Implementing Supply Chain Security With In Toto

mukul975/implementing-supply-chain-security-with-in-toto · Agent Skill (multi-file)

by mukul975 · bundle

Published · Last updated


Verify container image integrity across CI/CD pipelines using the in-toto framework to generate and check cryptographically signed attestations.

SKILL.md

Files

This skill is a package of 8 files. Install with the command above, or download the folder.

Related

  1. Detecting Supply Chain Attacks In CI CD · mukul975 bundle
    Scans GitHub Actions workflows and CI/CD pipeline configurations for supply chain attack vectors including unpinned actions, script injection via expressions, dependency confusion, and secrets exposure.
    24.6k
    repo stars
  2. Implementing Code Signing For Artifacts · mukul975 bundle
    Sign build artifacts (binaries, packages, containers) with GPG, Sigstore, and platform-specific tools to ensure integrity and authenticity throughout the software supply chain.
    24.6k
    repo stars
  3. Implementing Image Provenance Verification With Cosign · mukul975 bundle
    Sign and verify container image provenance using Sigstore Cosign with keyless OIDC-based signing, attestations, and Kubernetes admission enforcement.
    24.6k
    repo stars
  4. Securing Helm Chart Deployments · mukul975 bundle
    Secure Helm chart deployments by validating chart integrity, scanning templates for misconfigurations, and enforcing security contexts in Kubernetes releases.
    24.6k
    repo stars
  5. Securing Github Actions Workflows · mukul975 bundle
    Hardens GitHub Actions workflows against supply chain attacks, credential theft, and privilege escalation by pinning actions to SHA digests, minimizing GITHUB_TOKEN permissions, preventing script injection, and implementing workflow change controls.
    24.6k
    repo stars
  6. Agentic Actions Auditor · trailofbits bundle
    Audits GitHub Actions workflows for security vulnerabilities in AI agent integrations, detecting attack vectors where attacker-controlled input reaches AI agents in CI/CD pipelines.
    6k
    repo stars

Frequently asked questions

How do I install the Implementing Supply Chain Security With In Toto skill?

Run npx skillmds add mukul975/implementing-supply-chain-security-with-in-toto in your terminal (requires Node.js), paste this page's agent-chat prompt into Claude, Cursor, or any MCP-connected agent, or download the SKILL.md file and copy it into your agent's skills directory.

What does the Implementing Supply Chain Security With In Toto skill do?

Verify container image integrity across CI/CD pipelines using the in-toto framework to generate and check cryptographically signed attestations. It is listed under DevOps & Infra, Security, CI/CD, Secure Coding on SkillMD.

Is Implementing Supply Chain Security With In Toto safe to use?

SkillMD's automated safety review verdict for this skill is CAUTION. Independent scanners report: SkillSpector: PASS, Skill Scanner: PASS. Capability flags: executes scripts, makes network calls. SkillMD never runs a skill's scripts for you; review the SKILL.md before installing.

Which AI agents work with Implementing Supply Chain Security With In Toto?

This skill is tagged as working with Claude Code, Claude.ai, OpenAI Codex. SKILL.md is an open format, so most agents that read a skills directory can load it too.

Is Implementing Supply Chain Security With In Toto free to use?

Yes. Installing skills from SkillMD is free. This skill is licensed under Apache-2.

Who published Implementing Supply Chain Security With In Toto?

mukul975 (@mukul975) published this skill. Their other Agent Skills are listed on their SkillMD profile.