Agent Skill trust card
Supply Chain Security
community · recorded version or snapshot 1.0.0
Harden software supply chain: Sigstore signing, SLSA provenance, reproducible builds, artifact attestations, and Cosign verification.
Metadata reviewed No listed warning
Source and identity
- Publisher
- community
- Namespace
- Not recorded
- Recorded version / snapshot
- 1.0.0
- License
- Not recorded
- Artifact SHA-256
- Not recorded — a source snapshot alone does not pin an artifact
- Canonical listing
- https://slsa.dev/
Declared access
Review every permission against your own environment and least-privilege policy.
No permissions were recorded. This does not prove the component requires none.
Required secrets
Generated examples use placeholders. Never paste real secrets into ToolDix.
No required secrets are declared in the current metadata.
Compatibility and connection
Clients
- Codex
- Claude
- Cursor
- OpenClaw
Runtimes
No runtime is recorded.
Transports
No transport is recorded.
Authentication
No authentication method is recorded.
Evidence
- Canonical source
canonical · observed Jul 15, 2026