All skills
simota avatar

/chain

@35ffd55
by shingo imotasimota/agent-skills85 stars
15

Auditing skill/plugin/MCP supply chains and live package compromise: manifests, hidden injection, IoC scans, persistence-first eradication, and gated credential rotation. Not for app SAST (Sentinel).

Use this Skill: https://skilld.dev/gh/simota/agent-skills/chain

This session only. Nothing lands on disk.

referencesupply-chain-malware-handoffs.md

≈1.5k tokens on demand. Your agent reads this file only when SKILL.md points to it.

Supply-Chain Malware Handoffs

Purpose: Canonical handoff payloads for Chain's live supply-chain malware recipes. Read when: A lockfile, IDE hook, runtime, git-history, CI, or maintainer-publish finding must move between Chain and a domain owner.

All payloads follow _common/HANDOFF.md. Emit one target per handoff, reference concrete evidence, defang attacker URLs, and never include credential values.

Inbound

USER_TO_CHAIN_MALWARE_REQUEST

from: User
to: Chain
intent: malware-scan | campaign-scan | lockfile | eradicate | rotate | harden | propagation
context:
  os: macOS | Linux | Windows | WSL | container | CI
  suspect_window: "<UTC range>"
  suspect_campaign: "<campaign or unknown>"
  scope: ["<repo path, host scope, image, or runner>"]
  prior_actions: "<actions already taken>"
constraints:
  read_only_until_confirm: true
  may_quarantine: false

SENTINEL_TO_CHAIN_MALWARE_REQUEST

from: Sentinel
to: Chain
trigger: malicious_pin | slopsquat_candidate | install_script_anomaly
context:
  package: "<name@version>"
  lockfile_path: "<path>"
  advisory: "<CVE, GHSA, or source URL>"
  confidence: HIGH | MEDIUM | LOW
ask:
  - Confirm live-environment persistence, droplet, and process evidence
  - Return infection grade and evidence chain

BUILDER_OR_TRAIL_TO_CHAIN_MALWARE_REQUEST

from: Builder | Trail
to: Chain
trigger: lockfile_diff | optional_dependency | install_script | suspicious_commit | force_pushed_tag
context:
  ref_or_commit: "<sha>"
  changed_files: ["<path>"]
  author: "<if relevant>"
ask:
  - Cross-check exact evidence against the campaign IoC database
  - Block merge only on an evidence-backed malicious match

TRIAGE_TO_CHAIN_MALWARE_REQUEST

from: Triage
to: Chain
trigger: supply_chain_incident
context:
  incident_id: "<id>"
  severity: SEV1 | SEV2
  affected_targets: ["<host, runner, repo, or image>"]
constraints:
  approved_actions: ["<pre-authorized persistence-stop action>"]
  blocked_actions: ["credential revocation", "production infrastructure changes"]
ask:
  - Run a full IoC scan and classify the infection
  - Stop IoC-matched persistence if actively bleeding and authorized
  - Return evidence chain, eradication gate, and rotation eligibility

Outbound

CHAIN_TO_TRIAGE_MALWARE_INCIDENT

from: Chain
to: Triage
trigger: CONFIRMED | ACTIVELY_BLEEDING
context:
  campaign: "<name>"
  grade: CONFIRMED | ACTIVELY_BLEEDING
  evidence:
    persistence: [{path: "<path>", sha256: "<hash>", status: stopped | running}]
    lockfile_pins: [{package: "<name@version>", path: "<lockfile>"}]
    passive_exfil_traces: [{host: "<defanged host>", evidence: "<log line>"}]
  quarantine_path: "/tmp/chain-malware-quarantine-<utc>/"
  eradication_status: in_progress | verified_clean | blocked
  rotation_status: not_eligible | ready | issued
  retaliation_risk: "<why rotation remains gated>"

CHAIN_TO_SENTINEL_MALICIOUS_PIN

from: Chain
to: Sentinel
trigger: confirmed_malicious_version_pin
context:
  package: "<name@version>"
  lockfiles: ["<path>"]
  clean_version: "<name@version>"
  campaign: "<name>"
ask:
  - Find the pin across the organization
  - Propose an upgrade and rollback plan
  - Add a slopsquat rule if applicable

CHAIN_TO_GEAR_MALWARE_HARDENING

from: Chain
to: Gear
trigger: verified_clean_rebuild
context:
  affected_surfaces: [npm_runtime, github_actions, container_image, dependency_bot]
  controls:
    - "ignore-scripts=true"
    - "minimum release age of at least 7 days"
    - "full-SHA GitHub Action pinning"
    - "OIDC instead of long-lived tokens"
    - "registry proxy and provenance checks"
ask:
  - Rebuild runners and images from a clean base
  - Apply controls and return verification evidence

CHAIN_TO_VIGIL_MALWARE_RULES

from: Chain
to: Vigil
trigger: new_source_cited_ioc
context:
  campaign: "<name>"
  signatures:
    - type: filename | sha256 | process_cmdline | network_endpoint | git_pattern
      value: "<exact or defanged value>"
      source: "<advisory URL + date>"
ask:
  - Author and test Sigma or YARA coverage
  - Map the evidence to current MITRE ATT&CK techniques

CHAIN_TO_LORE_MALWARE_PATTERN

from: Chain
to: Lore
trigger: repeated_campaign_pattern | novel_persistence | eradication_order_lesson
context:
  pattern_summary: "<short, non-sensitive summary>"
  recurrence_count: <n>
  affected_agents: [Sentinel, Chain, Vigil, Triage, Gear]
ask:
  - Curate the reusable pattern without raw credentials or confidential payloads

Handoff Hygiene

  • One target per handoff; do not combine Triage, Sentinel, Gear, and Vigil requests.
  • Include exact paths, hashes, timestamps, package pins, and source citations.
  • Defang attacker URLs (https to hxxps, .com to [.]com) and use passive evidence only.
  • Preserve persistence stopped before revoke and verify-clean before rotation as explicit gates.
  • A confirmed IDE-hook compromise remains within Chain: quarantine only after approval, then rerun intake and regenerate .chain-manifest.json on the cleaned directory.

Overlap Boundaries

Partner Chain supplies Partner owns
Triage IoC grade, evidence, eradication and rotation gates Incident command, severity, communications, disclosure
Sentinel Confirmed malicious pin and campaign evidence Org-wide dependency remediation, SAST, slopsquat rules
Gear Clean-rebuild and hardening specification CI/CD, runner, image, and dependency-policy implementation
Vigil Source-cited detection primitives Sigma/YARA authoring, ATT&CK mapping, detection validation
Trail Campaign cross-check for suspicious commits Git archaeology and public-ref cleanup analysis
Lore Reusable non-sensitive campaign pattern Ecosystem memory and propagation

Source: SKILL.md on GitHub

1 alert13d3 checks · Risk CRITICAL
  • Gen Agent Trust Hub13d

    This skill is a security auditing tool designed to detect and eradicate supply chain malware. It contains examples of malicious code patterns and a database of known malware indicators (IoCs) for research and detection purposes. While the skill possesses broad command execution capabilities and processes untrusted third-party data, these are aligned with its primary purpose and are supported by explicit sandboxing and verification procedures. The findings flagged by scanners are documentation of threats, not the threats themselves.

  • Socket13d

    No alerts

  • Snyk13d

    Risk: LOW · No issues

Signed by skilld at 35ffd55. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 3 days ago.

Activeupdated 2 weeks ago

README badge

README badge for simota/agent-skills/chain