All skills
simota avatar

/chain

@35ffd55
by shingo imotasimota/agent-skills85 stars
15

Auditing skill/plugin/MCP supply chains and live package compromise: manifests, hidden injection, IoC scans, persistence-first eradication, and gated credential rotation. Not for app SAST (Sentinel).

Use this Skill: https://skilld.dev/gh/simota/agent-skills/chain

This session only. Nothing lands on disk.

referencerecipes-index.md

≈569 tokens on demand. Your agent reads this file only when SKILL.md points to it.

Chain Recipe Registry

The full Recipe table for chain. chain/SKILL.md carries only the dispatch allowlist; this file holds what is needed to execute a Recipe — activation condition and the files to read first.

Read this when a subcommand matched and you need its row, or when scanning what Recipes exist at all.


Recipe Subcommand Default? When to Use Read First
Skill Intake Audit intake ✓ New third-party skill or plugin requires intake gate reference/intake-checklist.md
Drift Detection audit Verify pinned sha256 against current files; detect silent updates _common/SECURITY.md
MCP Server Pinning mcp First install or session-start re-verification of MCP tool descriptions _common/SECURITY.md
Unicode Scan scan Standalone scan for Unicode Tag, bidi, or zero-width injection reference/unicode-tag-scan.md
Recovery / Quarantine recover Confirmed-compromised skill must be quarantined and remediation diff produced reference/intake-checklist.md
Live Malware Scan malware-scan Full campaign IoC sweep across live environment surfaces reference/supply-chain-malware-scan-procedures.md, reference/supply-chain-malware-ioc-database.md
Campaign Scan campaign-scan Narrow scan for a named npm/PyPI campaign reference/supply-chain-malware-ioc-database.md
Lockfile Pin Check lockfile Fast, read-only pre-merge check for known-bad versions and resolved URLs reference/supply-chain-malware-ioc-database.md
Eradication Runbook eradicate Persistence-first removal for a recent CONFIRMED finding reference/supply-chain-malware-eradication.md
Rotation Runbook rotate Dependency-ordered credential rotation after verify-clean reference/supply-chain-malware-eradication.md
Supply-Chain Hardening harden Lifecycle-script, cooldown, provenance, registry, and Actions controls reference/supply-chain-malware-scan-procedures.md
Propagation Audit propagation Unauthorized maintainer publishes, OIDC exchange, and provenance review from a clean session reference/supply-chain-malware-scan-procedures.md

Source: SKILL.md on GitHub

1 alert13d3 checks · Risk CRITICAL
  • Gen Agent Trust Hub13d

    This skill is a security auditing tool designed to detect and eradicate supply chain malware. It contains examples of malicious code patterns and a database of known malware indicators (IoCs) for research and detection purposes. While the skill possesses broad command execution capabilities and processes untrusted third-party data, these are aligned with its primary purpose and are supported by explicit sandboxing and verification procedures. The findings flagged by scanners are documentation of threats, not the threats themselves.

  • Socket13d

    No alerts

  • Snyk13d

    Risk: LOW · No issues

Signed by skilld at 35ffd55. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 3 days ago.

Activeupdated 2 weeks ago

README badge

README badge for simota/agent-skills/chain