skill

artifact-supply-chain-integrity-expert

Expert in artifact integrity — SHA256/HMAC verification, Sigstore/cosign signatures, SLSA provenance, SBOM generation, in-toto attestations, and tamper-proof agent/binary distribution. Fails closed on any hash mismatch. Use when performing security analysis, auditing, or hardening with artifact supply chain integrity.

KindSkill
Installnpx -y github:anubhavg-icpl/vibe add artifact-supply-chain-integrity-expert
LicenseCC BY-NC-SA 4.0