Agent skill

Enforce Slsa

by harness in harness/harness-skills

Add an SLSA Verification (SlsaVerification) step to an existing Harness pipeline to verify SLSA provenance attestations and optionally enforce OPA policy sets on provenance data.

Apache-2.0Auto-check passedSecurity

Install Enforce Slsa

skills CLI
$ npx skills add harness/harness-skills --skill enforce-slsa -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install harness/harness-skills enforce-slsa --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/harness/harness-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/enforce-slsa .claude/skills/enforce-slsa && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
enforce-slsa
GitHub stars
115
Token cost
~3.2k tokens
SKILL.md length
1,085 words
Files
3 (incl. references)
Skills in repo
24
Repo updated
First seen
Licence
Apache-2.0

At a glance

Add an SLSA Verification (SlsaVerification) step to an existing Harness pipeline to verify SLSA provenance attestations and optionally enforce OPA policy sets on provenance data.

  • Works in 12 steps: One question per turn — use AskQuestion… → Opening message — add SLSA Verification;… → Progress breadcrumb — after pipeline fetch → …
  • Asked to verify SLSA
  • SKILL.md covers Interaction model (mandatory), Instructions, Examples and Performance Notes, plus 1 more section
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Enforce Slsa is an agent skill from harness/harness-skills. Add an SLSA Verification (SlsaVerification) step to an existing Harness pipeline to verify SLSA provenance attestations and optionally enforce OPA policy sets on provenance data. Supports CI and CD (Deployment) including CI-only pipelines — append a Deploy stage via Phase 3b when verifying before deploy. Supports Docker, ECR, GCR, GAR, ACR, HAR, and Local artifacts. Only works with existing pipelines. Use when asked to verify SLSA, enforce SLSA policies, add SLSA verification step, validate SLSA attestation, or…

Its SKILL.md is about 3.2k tokens, which your agent loads only when the skill is triggered. The skill folder holds 3 other files, including reference files (for example `references/interactive-wizard-flow.md` and `references/slsa-verification-step.md`). Compatibility notes: Requires Harness MCP v2 server (harness-mcp-v2)

It sits in Security, covering Supply chain security. It works with Docker. The repository describes itself as: A collection of structured AI agent skills that enable Claude Code, Cursor, GitHub Copilot, and other AI coding assistants to create, operate, debug, and govern Harness CI/CD… The licence is Apache-2.0.

When your agent uses it

  • Asked to verify SLSA
  • Enforce SLSA policies
  • Add SLSA verification step
  • Validate SLSA attestation

Example prompts

  • “/enforce-slsa”

Requirements

  • Docker
  • Compatibility (from SKILL.md): Requires Harness MCP v2 server (harness-mcp-v2)

Workflow steps

12 steps, taken from the first numbered list in SKILL.md.

  1. One question per turn — use AskQuestion when available; otherwise numbered options with (Recommended).
  2. Opening message — add SLSA Verification; mention generation + optional policy prerequisites.
  3. Progress breadcrumb — after pipeline fetch
  4. Record answers — running summary; do not re-ask unless the user changes direction.
  5. Fetch before configure — harness_get before placement/source questions.
  6. Show pipeline structure — highlight provenance (SLSA Generation) and connectors.
  7. Infer source from generation — when one provenance step exists (or identifier: slsageneration), reuse its source (map repo → image_path…
  8. Never guess image tags — default from generation step; ask if ambiguous.
  9. Confirm before write — summary + harness_update only after user confirms.
  10. Stop after update — after successful harness_update, provide a configuration summary and
  11. CD on CI-only pipeline — do not reject CD verify; run Phase 3b to add Deploy stage + containerized group.
  12. Verify method must match generation — keyless ↔ keyless, keybased ↔ public key from same key pair.

What it can do on your machine

Read from SKILL.md and the folder at commit c25faee. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are yaml).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

  • Compatibility

    Requires Harness MCP v2 server (harness-mcp-v2)

    From compatibility in the SKILL.md frontmatter.

Context cost

Enforce Slsa loads about 3.2k tokens when it runs, and up to ~5.8k if it reads all its reference files. Until then it costs about 179 tokens; SKILL.md has 1,085 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~179
When it runs · the whole SKILL.md, loaded when a task matches
~3.2k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~5.8k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from harness/harness-skills at commit c25faee, republished under its Apache-2.0 licence (© harness). 1,085 words, ~3,155 tokens.

Download SKILL.mdSave it as .claude/skills/enforce-slsa/SKILL.md (or your agent's skills folder). This skill also uses 2 other files; get the full folder from GitHub.
name
enforce-slsa
description
Add an SLSA Verification (SlsaVerification) step to an existing Harness pipeline to verify SLSA provenance attestations and optionally enforce OPA policy sets on provenance data. Supports CI and CD (Deployment) including CI-only pipelines — append a Deploy stage via Phase 3b when verifying before deploy. Supports Docker, ECR, GCR, GAR, ACR, HAR, and Local artifacts. Only works with existing pipelines. Use when asked to verify SLSA, enforce SLSA policies, add SLSA verification step, validate SLSA attestation, or gate deploy on SLSA provenance. Trigger phrases: enforce SLSA, SLSA verification, verify SLSA, SLSA policy enforcement, SlsaVerification, verify SLSA attestation, add SLSA verify step.
compatibility
Requires Harness MCP v2 server (harness-mcp-v2)
metadata.author
Harness
metadata.version
1.0.0
metadata.mcp-server
harness-mcp-v2
license
Apache-2.0

Enforce SLSA

Add an SLSA Verification (SlsaVerification) step to an existing Harness pipeline. The step verifies SLSA provenance attestations (when enabled) and optionally evaluates OPA policy sets against provenance data.

This skill only works with existing pipelines — do not create standalone verification-only pipelines.

Prerequisites: SLSA provenance must already exist for the artifact (typically from a provenance step via /generate-slsa — UI label SLSA Generation). Optional policy sets for provenance enforcement (/create-policy, harness_list policy_set).

Supported stages: CI, CD (Deployment), and Security. CD requires a containerized step group. Unlike SBOM enforcement, CI and CD both use SlsaVerification (no separate CD step type).

Guide the user through a step-by-step interactive wizard (same UX as /generate-slsa):

  • Wizard: references/interactive-wizard-flow.md
  • UI ↔ YAML: references/slsa-verification-step.md
  • CD containerized step groups: skills/generate-slsa/references/cd-containerized-step-group.md

Interaction model (mandatory)

  1. One question per turn — use AskQuestion when available; otherwise numbered options with (Recommended).
  2. Opening message — add SLSA Verification; mention generation + optional policy prerequisites.
  3. Progress breadcrumb — after pipeline fetch: Pipeline · Placement · Source · Details · Verify · Policy · Submit
  4. Record answers — running summary; do not re-ask unless the user changes direction.
  5. Fetch before configure — harness_get before placement/source questions.
  6. Show pipeline structure — highlight provenance (SLSA Generation) and connectors.
  7. Infer source from generation — when one provenance step exists (or identifier: slsageneration), reuse its source (map repo → image_path, lowercase → PascalCase types).
  8. Never guess image tags — default from generation step; ask if ambiguous.
  9. Confirm before write — summary + harness_update only after user confirms.
  10. Stop after update — after successful harness_update, provide a configuration summary and point the user to /run-pipeline to execute. Do not call harness_execute, poll executions, or run harness_diagnose in this skill (same pattern as /configure-repo-scan).
  11. CD on CI-only pipeline — do not reject CD verify; run Phase 3b to add Deploy stage + containerized group.
  12. Verify method must match generation — keyless ↔ keyless, keybased ↔ public key from same key pair.

Full phase prompts: references/interactive-wizard-flow.md.


Instructions

Wizard phases
PhaseBreadcrumbAction
0PipelineAskQuestion: pipeline URL ready?
1PipelineCollect URL → harness_get
2PipelineDisplay structure; note missing provenance (SLSA Generation) step
3PlacementAskQuestion: after generation, CD before deploy, etc.
3bPlacement (CD)Service, env, infra, step group if new Deploy stage
4SourceInfer from generation or pick registry tile
5SourceRegistry provider (Third-Party only)
6DetailsConnector (skip if obvious)
7DetailsImage / image_path (default from generation)
8VerifyAskQuestion: verify attestation method
9PolicyAskQuestion: policy set(s) or skip
10SubmitAskQuestion: confirm pipeline update

After Phase 10 confirm → insert step, harness_update, then provide summary (do not run the pipeline).

Supported stage types
Stage typeStep typePlacement notes
CISlsaVerificationAfter provenance / slsageneration in the same stage
DeploymentSlsaVerificationContainerized step group; before deploy
SecuritySlsaVerificationAfter generation when artifact is in registry
CD edge case

If no Deployment stage and user chose CD verify:

No CD Deploy stage yet. We can add a Deployment stage with a containerized step group and place SLSA Verification before deploy.

Run Phase 3b (service, environment, infrastructure, stepGroupInfra) — mirror /generate-slsa Phase 3b. Use skills/generate-slsa/references/cd-containerized-step-group.md with SlsaVerification.

After the wizard — backend steps
Check prerequisites
  1. SLSA generation — pipeline contains type: provenance (SLSA Generation) or user confirms provenance exists.
  2. Policy sets (optional) — harness_list(resource_type="policy_set"). If user wants policy enforcement and none exist, direct to /create-policy before continuing.
Extract context from pipeline YAML

From provenance step (if present — also match identifier: slsageneration), copy and transform:

GenerationVerification
source.type: dockersource.type: Docker
source.spec.reposource.spec.image_path
source.spec.connectorsource.spec.connector
spec.attestationmatching verify_attestation (private → public key for keybased)
Generate SLSA verification step YAML

CI / Security — Docker Registry, keyless verify:

yaml
- step:
    identifier: slsaverification
    name: SLSA Verification
    type: SlsaVerification
    spec:
      source:
        type: Docker
        spec:
          connector: lavakush07
          image_path: lavakush07/easy-buggy-app:blog
      verify_attestation:
        type: keyless
        spec:
          oidcProvider: harness
    timeout: 15m

Key-based verify (generation used keybased + private key):

yaml
      verify_attestation:
        type: keybased
        spec:
          publicKey: account.cosign_public_key

If API validation rejects flat keyless / keybased, retry with nested cosign wrapper — see references/slsa-verification-step.md.

Policy enforcement (Advanced tab — step-level enforce):

yaml
    enforce:
      policySets:
        - slsa_provenance_rules

No attestation verify (policy-only): omit verify_attestation.

CD Deploy — same step type inside containerized stepGroup; use <+artifact.image> for image_path when verifying service artifacts.

Full provider mapping: references/slsa-verification-step.md.

Show full SKILL.md (444 more words)Show less
Insert step into pipeline YAML
  • Insert at Phase 3 placement — after slsageneration when possible.
  • Do not modify unrelated steps.
  • Step identifier: slsaverification (use slsaverification_cd in CD when CI already has one).
  • CD: inside containerized step group only.
Update pipeline via MCP
harness_update
  resource_type: pipeline
  resource_id: <pipeline_identifier>
  org_id: <organization>
  project_id: <project>
  body: { yamlPipeline: "<updated pipeline YAML>" }

On validation errors, check PascalCase source.type, image_path vs repo, and verify_attestation shape (prefer flat keyless; fallback nested cosign).

Provide summary

Report the results to the user (same pattern as /configure-repo-scan — do not execute the pipeline):

## SLSA Verification Configured

**Pipeline:** <pipeline_name>
**Step:** SLSA Verification (SlsaVerification)
**Location:** Stage "<stage_name>", <position>
**Source:** Docker — <connector> — <image_path>
**Verify attestation:** Keyless (Harness OIDC) — or as configured
**Policy sets:** <list or none>

**Pipeline URL:** https://app.harness.io/ng/account/<account_id>/module/ci/orgs/<org_id>/projects/<project_id>/pipelines/<pipeline_id>/pipeline-studio/

**Note:** Review the SLSA Verification step in Pipeline Studio to adjust Advanced settings.

### Next Steps
1. Run the pipeline via `/run-pipeline` to verify SLSA verification executes successfully
2. If the run fails, diagnose with `/debug-pipeline`
3. View verification outcome on the execution **Supply Chain** tab
4. If **Failed** due to policy deny, tune policies via `/create-policy`
5. Add generation with `/generate-slsa` if provenance was missing
6. Automate with `/create-trigger`

CD pipelines: note in the summary if runtime inputs (service artifact, environment, infrastructure) will be required at run time — the user provides those via /run-pipeline or Harness UI Run.


Examples

Verify after SLSA Generation
/enforce-slsa
Add SLSA verification after slsa-generation — keyless verify, policy set slsa_prod_rules
CD before deploy
/enforce-slsa
Verify SLSA in deploy stage before K8s rolling deploy for easy-buggy-app:blog
Key-based verify (matches keybased generation)
/enforce-slsa
Verify SLSA with public key account.cosign_public_key — same image as generation step

Performance Notes

  • Only existing pipelines (may append Deploy stage).
  • Wizard UX mandatory — one question per turn.
  • Reuse generation source — scan for type: provenance or identifier: slsageneration; map repo → image_path, lowercase → PascalCase types.
  • Verification source.type is PascalCase (Docker) — generation uses lowercase (docker).
  • verify_attestation is snake_case (not verifyAttestation). Prefer flat type: keyless + oidcProvider (same shape as generation attestation).
  • Policy sets on step enforce.policySets — not spec.policy like SBOM enforcement.
  • List policy_set via MCP — do not invent identifiers.
  • CD: containerized step group only; see skills/generate-slsa/references/cd-containerized-step-group.md.
  • Do not execute pipelines in this skill — use /run-pipeline after configuration (same as /configure-repo-scan).
  • Pair with /generate-slsa (generate) and /create-policy (OPA rules).

Troubleshooting

No SLSA Generation Step
  • Add /generate-slsa first with attestation enabled (type: provenance in YAML).
  • Verification needs .att in registry or provenance in SCS Artifacts.
  • Scan for provenance steps — not SlsaGeneration (API uses provenance).
Attestation Verification Failed
  • Verify method must match generation (keyless vs keybased).
  • Keybased: use public key secret (generation uses private key).
  • Keyless non-harness: configure Connector for Keyless Signing.
Wrong Image / No Provenance
  • Use same image_path as generation repo field.
  • Symptom: verify passes wrong artifact — image mismatch.
Policy Evaluation Failed
  • Review policy set Rego rules; check Supply Chain tab for violations.
  • Confirm policy set identifier (not display name) in enforce.policySets.
YAML Validation Errors
  • source.type must be PascalCase for verification (Docker, not docker).
  • Docker source uses image_path, not repo.
  • verify_attestation: use flat type: keyless + spec.oidcProvider: harness — not nested cosign unless API rejects flat shape.
  • DUPLICATE_IDENTIFIER — rename slsaverification.
CD Step Errors
  • Place inside stepGroup with stepGroupInfra — not top-level execution.steps.
  • See skills/generate-slsa/references/cd-containerized-step-group.md.
User Chose CD on CI-Only Pipeline
  • Expected — run Phase 3b; do not force CI-only unless user changes direction.
Pipeline Run Failed
  • Use /run-pipeline to execute and /debug-pipeline to diagnose failures
  • Confirm verify method matches generation attestation; check public key for keybased
  • Missing runtime inputs: provide branch/tag or deploy inputs via /run-pipeline or Harness UI Run
MCP Errors
  • CONNECTOR_NOT_FOUND — verify connector in Project Settings.
  • ACCESS_DENIED — PAT needs pipeline edit and policy read permissions.

© harness, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 2 other files (references) in skills/enforce-slsa of harness/harness-skills.

  • SKILL.md
  • references/interactive-wizard-flow.md
  • references/slsa-verification-step.md

Open the folder on GitHubat commit c25faee

Compare with similar skills

Enforce Slsa next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Enforce Slsa compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Enforce Slsa this skillharness/harness-skills115—~3.2kAutomated safety check: PassApache-2.0
Warp Vulnerability Triagewarpdotdev/warp65k1 repos~2.1kAutomated safety check: PassAGPL-3.0
Container Scanning with GrypeAgentSecOps/SecOpsAgentKit2201 repos~2.5kAutomated safety check: PassCustom licence
Container Securityhardw00t/ai-security-arsenal104—~2.8kAutomated safety check: PassNone
Sca TrivyAgentSecOps/SecOpsAgentKit2202 repos~3.7kAutomated safety check: PassCustom licence
Container Security Hardeningsickn33/agentic-awesome-skills47k1 repos~1kAutomated safety check: NotesMIT

Similar skills

  • Gathers security findings from Dependabot, GCP container scanning, Docker Scout and Linear security issues, then triages and remediates them across Warp's repos and images.

    65k GitHub starsUsed in 1 repo~2.1k tokens
    SecurityAuto-check passed
  • Container Scanning with Grype

    AgentSecOps/SecOpsAgentKit

    Scans container images, filesystems and SBOMs with Grype for known vulnerabilities, ranks them by CVSS, EPSS and CISA KEV, and wires scans into CI/CD thresholds.

    220 GitHub starsUsed in 1 repo~2.5k tokens
    SecurityAuto-check passed
  • Container Security

    hardw00t/ai-security-arsenal

    Container and Kubernetes security assessment — image vulnerability scanning, SBOM diff analysis, K8s cluster auditing, RBAC privilege mapping, NetworkPolicy review, container escape testing, and…

    104 GitHub stars~2.8k tokensUpdated 5 mo ago
    SecurityAuto-check passed
  • Sca Trivy

    AgentSecOps/SecOpsAgentKit

    Software Composition Analysis (SCA) and container vulnerability scanning using Aqua Trivy for identifying CVE vulnerabilities in dependencies, container images, IaC misconfigurations, and license…

    220 GitHub starsUsed in 2 repos~3.7k tokens
    SecurityAuto-check passed
  • Container Security Hardening

    sickn33/agentic-awesome-skills

    Harden Docker/container images and runtime deployments with secure base images, non-root users, CVE scanning, SBOM/signing, seccomp/AppArmor, and Kubernetes pod security controls.

    47k GitHub starsUsed in 1 repo~1k tokens
    SecurityAuto-check: notes
  • Container Sbom

    cdxgen/cdxgen

    Generates CycloneDX BOMs for container images, OCI archives, mounted root filesystems, Electron ASAR archives, caxa executables, binaries, and Kubernetes or Dockerfile manifests using OWASP cdxgen…

    1.1k GitHub stars~1.5k tokensUpdated yesterday
    DevOps & CloudAuto-check passed

More from harness/harness-skills

All 24 skills in this repo
  • Audit Report

    harness/harness-skills

    Generate audit reports and compliance trails using Harness audit trail data via MCP v2 tools.

    115 GitHub stars~1.3k tokensUpdated 2 days ago
    Auto-check passed
  • Chaos Dr Test

    harness/harness-skills

    A skill your agent uses when working with Chaos Engineering steps inside a Harness pipeline.

    115 GitHub stars~2.6k tokensUpdated 2 days ago
    Auto-check passed
  • Chaos Experiment

    harness/harness-skills

    A skill your agent uses when the user asks to create, edit, update, design, or configure a Harness Chaos Experiment — including faults, probes, actions, experiment YAML, fault injection, pod-delete…

    115 GitHub stars~1.6k tokensUpdated 2 days ago
    Auto-check passed
  • Cleanup Feature Flags

    harness/harness-skills

    Remove a launched Harness FME feature flag from application code, keeping the treatment FME serves today, and open a pull request.

    115 GitHub stars~2.4k tokensUpdated 2 days ago
    Auto-check passed
  • Configure Repo Scan

    harness/harness-skills

    Configure code scanning in Harness pipelines using STO security scanners.

    115 GitHub stars~2.2k tokensUpdated 2 days ago
    Auto-check passed
  • Create Agent Template

    harness/harness-skills

    Generate Harness Agent Template files for AI-powered automation agents.

    115 GitHub stars~2.2k tokensUpdated 2 days ago
    Auto-check passed

Works with

Questions about Enforce Slsa

What does Enforce Slsa do?

Add an SLSA Verification (SlsaVerification) step to an existing Harness pipeline to verify SLSA provenance attestations and optionally enforce OPA policy sets on provenance data. Enforce Slsa is an agent skill from harness/harness-skills. Add an SLSA Verification (SlsaVerification) step to an existing Harness pipeline to verify SLSA provenance attestations and optionally enforce OPA policy sets on provenance data.

When should I use Enforce Slsa?

Enforce Slsa fits situations like: asked to verify SLSA; enforce SLSA policies; add SLSA verification step; validate SLSA attestation.

How do I install Enforce Slsa in Claude Code?

Run `npx skills add harness/harness-skills --skill enforce-slsa -a claude-code`. Or copy the skill folder (skills/enforce-slsa in harness/harness-skills) into .claude/skills/enforce-slsa in your project. Claude Code loads it when a task matches its description.

How do I install Enforce Slsa in Codex?

Run `npx skills add harness/harness-skills --skill enforce-slsa -a codex`. Or copy the skill folder (skills/enforce-slsa in harness/harness-skills) into .agents/skills/enforce-slsa in your project. Codex loads it when a task matches its description.

Can I use Enforce Slsa in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add harness/harness-skills --skill enforce-slsa -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/enforce-slsa, .gemini/skills/enforce-slsa, .github/skills/enforce-slsa and .opencode/skills/enforce-slsa in your project.

What does Enforce Slsa need to run?

SKILL.md names no scripts, command-line tools or credentials: Enforce Slsa is instructions for the agent only. Our summary lists: Docker. Compatibility (from SKILL.md): Requires Harness MCP v2 server (harness-mcp-v2).

Does Enforce Slsa access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Enforce Slsa safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Enforce Slsa use?

Enforce Slsa is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Enforce Slsa use?

About 3.2k tokens (SKILL.md is roughly 13k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 2.6k tokens, read only when the agent opens those files.

What are the alternatives to Enforce Slsa?

Skills that share tags, products or a category with Enforce Slsa: Warp Vulnerability Triage (warpdotdev/warp, 65k stars), Container Scanning with Grype (AgentSecOps/SecOpsAgentKit, 220 stars), Container Security (hardw00t/ai-security-arsenal, 104 stars) and Sca Trivy (AgentSecOps/SecOpsAgentKit, 220 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Enforce Slsa?

harness (a GitHub organization) maintains it in harness/harness-skills, which has 115 GitHub stars. The repository holds 24 skills in this directory. The repository was last updated on October 6, 2026.

Source: harness/harness-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.