All skills
simota avatar

/chain

@35ffd55
by shingo imotasimota/agent-skills85 stars
15

Auditing skill/plugin/MCP supply chains and live package compromise: manifests, hidden injection, IoC scans, persistence-first eradication, and gated credential rotation. Not for app SAST (Sentinel).

Use this Skill: https://skilld.dev/gh/simota/agent-skills/chain

This session only. Nothing lands on disk.

referenceaudit-decision-matrix.md

≈487 tokens on demand. Your agent reads this file only when SKILL.md points to it.

Chain Audit Decision Matrix

Moved out of chain/SKILL.md so it loads when it is needed rather than on every invocation. The text is unchanged.


Audit Decision Matrix

Finding Severity Default action Escalate to
Unicode Tag codepoint in any file P0 REJECT + QUARANTINE triage
`curl ... bash, wget ... sh, eval $(...)` in bundled script P0
~/.ssh, ~/.aws, ~/.npmrc, ~/.netrc read without declaration P0 REJECT triage
settings.json mutation that changes permissions P0 REJECT + QUARANTINE triage
Project-local .claude/settings.json hooks parsed or executed before the trust prompt is answered P0 REJECT triage
Path containment checked before symlinks are resolved (validation sees the link, not its target) P0 REJECT triage
Frontmatter contains custom keys outside name / description P1 REJECT (forward-compat) maintainer
Bundled binary without provenance attestation P1 REJECT until provenance provided sentinel
Outbound HTTP to non-allowlisted host P1 REJECT until network allowlist updated maintainer
sha256 mismatch vs pinned manifest P1 BLOCK + investigate diff maintainer
MCP tool description changed since pin P1 BLOCK tool until reviewed maintainer
Capability declared in body but tool calls observed go beyond P2 FLAG + require capability update maintainer
External URL in SKILL.md resolves to executable content P2 FLAG + require static replacement maintainer
Bidi-override codepoint outside allowlisted i18n context P2 FLAG maintainer

Severity rules:

  • P0 always rejects and quarantines.
  • P1 rejects until remediated by maintainer.
  • P2 flags but may pass with explicit override and journaled rationale.

Source: SKILL.md on GitHub

1 alert13d3 checks · Risk CRITICAL
  • Gen Agent Trust Hub13d

    This skill is a security auditing tool designed to detect and eradicate supply chain malware. It contains examples of malicious code patterns and a database of known malware indicators (IoCs) for research and detection purposes. While the skill possesses broad command execution capabilities and processes untrusted third-party data, these are aligned with its primary purpose and are supported by explicit sandboxing and verification procedures. The findings flagged by scanners are documentation of threats, not the threats themselves.

  • Socket13d

    No alerts

  • Snyk13d

    Risk: LOW · No issues

Signed by skilld at 35ffd55. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 2 days ago.

Activeupdated 2 weeks ago

README badge

README badge for simota/agent-skills/chain