All skills
simota avatar

/chain

@35ffd55
by shingo imotasimota/agent-skills85 stars
15

Auditing skill/plugin/MCP supply chains and live package compromise: manifests, hidden injection, IoC scans, persistence-first eradication, and gated credential rotation. Not for app SAST (Sentinel).

Use this Skill: https://skilld.dev/gh/simota/agent-skills/chain

This session only. Nothing lands on disk.

referenceautorun-schema.md

≈462 tokens on demand. Your agent reads this file only when SKILL.md points to it.

Chain — AUTORUN _STEP_COMPLETE Schema

When Chain receives _AGENT_CONTEXT, parse task_type (intake / audit / mcp / scan / recover / malware-scan / campaign-scan / lockfile / eradicate / rotate / harden / propagation), target (skill dir / plugin / MCP server / host / repo / image / runner), and Constraints. Execute the matching Recipe silently (no verbose progress narration).

_STEP_COMPLETE

_STEP_COMPLETE:
  Agent: Chain
  Status: SUCCESS | PARTIAL | BLOCKED | FAILED
  Output:
    deliverable: audit_report | malware_report | recovery_runbook | hardening_plan
    verdict: APPROVED | REJECTED | QUARANTINED | null
    target: "<skill-dir, MCP server, host, repo, image, or runner>"
    checklist_pass_rate: "<n>/<total>"
    findings:
      - severity: P0 | P1 | P2
        item: "<checklist item id>"
        rationale: "<one line>"
    manifest_path: "<.chain-manifest.json or null>"
    remediation_diff: "<path or inline or null>"
    infection:
      grade: CLEAN | SUSPECTED | CONFIRMED | ACTIVELY_BLEEDING | null
      findings:
        - ioc_family: "<campaign>"
          surface: persistence | droplet | lockfile | process | network | git-log
          evidence: "<path, package pin, command line, or log line>"
          sha256: "<file hash or null>"
          source: "<advisory URL + date>"
      eradication_status: not_started | in_progress | verified | blocked | null
      rotation_status: not_eligible | ready | issued | verified | null
  Validations:
    intake_checklist_version: "1"
    unicode_scan: "passed | failed"
    bundled_artifact_scan: "passed | failed"
    persistence_stopped_before_delete: true | false | n/a
    callback_probe_avoided: true | n/a
  Next: maintainer | triage | sentinel | gear | vigil | lore | DONE
  Reason: "<why this next step>"

Source: SKILL.md on GitHub

1 alert13d3 checks · Risk CRITICAL
  • Gen Agent Trust Hub13d

    This skill is a security auditing tool designed to detect and eradicate supply chain malware. It contains examples of malicious code patterns and a database of known malware indicators (IoCs) for research and detection purposes. While the skill possesses broad command execution capabilities and processes untrusted third-party data, these are aligned with its primary purpose and are supported by explicit sandboxing and verification procedures. The findings flagged by scanners are documentation of threats, not the threats themselves.

  • Socket13d

    No alerts

  • Snyk13d

    Risk: LOW · No issues

Signed by skilld at 35ffd55. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 3 days ago.

Activeupdated 2 weeks ago

README badge

README badge for simota/agent-skills/chain