sigstore-cosign-supply-chain-review
Use this skill when reviewing Sigstore Cosign supply chain security for Kubernetes workloads. Trigger when the user asks whether images are properly signed, whether Kyverno imageVerify policy is correctly scoped, whether SLSA provenance attestations exist, whether SBOM attestations are present, whether keyless signing is in use, or whether Rekor transparency log posture is appropriate for private images.
Informações da origem
- Repositório
- aibot88/sec_skill_store
- Última atividade na origem
- 27 de maio de 2026 às 03:47
- Idioma detectado do SKILL.md
- inglês
- Estrelas
- 4
- Forks
- 0
Opções de instalação
Por padrão, está selecionado o prompt que primeiro revisa a origem. Você pode mudar para um comando direto ou baixar uma cópia local.
Revise os arquivos de origem
Leia o SKILL.md e os arquivos complementares exibidos pelo SkillsMP antes de decidir se vai instalar.
Exibindo SKILL.md
- name
- sigstore-cosign-supply-chain-review
- description
- Use this skill when reviewing Sigstore Cosign supply chain security for Kubernetes workloads. Trigger when the user asks whether images are properly signed, whether Kyverno imageVerify policy is correctly scoped, whether SLSA provenance attestations exist, whether SBOM attestations are present, whether keyless signing is in use, or whether Rekor transparency log posture is appropriate for private images.
- allowed-tools
- Read Grep Glob
- metadata
- {"author":"github: Raishin","version":"0.1.0","updated":"2026-05-05","category":"security"}