Agent skill

Generate Slsa

by harness in harness/harness-skills

Add a SLSA Generation step (YAML type: provenance) to an existing Harness pipeline to generate SLSA provenance and optionally attest with Cosign (keyless, key-based, or Vault).

Apache-2.0Auto-check passedSecurity

Install Generate Slsa

skills CLI
$ npx skills add harness/harness-skills --skill generate-slsa -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install harness/harness-skills generate-slsa --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/harness/harness-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/generate-slsa .claude/skills/generate-slsa && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
generate-slsa
GitHub stars
115
Token cost
~3k tokens
SKILL.md length
1,009 words
Files
4 (incl. references)
Skills in repo
24
Repo updated
First seen
Licence
Apache-2.0

At a glance

Add a SLSA Generation step (YAML type: provenance) to an existing Harness pipeline to generate SLSA provenance and optionally attest with Cosign (keyless, key-based, or Vault).

  • Works in 12 steps: One question per turn — use AskQuestion… → Opening message — add SLSA Generation… → Progress breadcrumb — after pipeline fetch → …
  • Asked to generate SLSA
  • SKILL.md covers Interaction model (mandatory), Instructions, Examples and Performance Notes, plus 1 more section
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Generate Slsa is an agent skill from harness/harness-skills. Add a SLSA Generation step (YAML type: provenance) to an existing Harness pipeline to generate SLSA provenance and optionally attest with Cosign (keyless, key-based, or Vault). Supports container images (Docker, ECR, GCR, GAR, ACR, HAR) and Harness Local Stage artifacts. Place after image build/push; run sequentially after SBOM steps, not in parallel. Only works with existing pipelines. Use when asked to generate SLSA, add SLSA provenance, SLSA Generation step, attest SLSA, or configure SLSA Level 3 provenance in…

Its SKILL.md is about 3k tokens, which your agent loads only when the skill is triggered. The skill folder holds 4 other files, including reference files (for example `references/cd-containerized-step-group.md`, `references/interactive-wizard-flow.md` and `references/slsa-generation-step.md`). Compatibility notes: Requires Harness MCP v2 server (harness-mcp-v2)

It sits in Security, covering Supply chain security and Containers. It works with Docker. The repository describes itself as: A collection of structured AI agent skills that enable Claude Code, Cursor, GitHub Copilot, and other AI coding assistants to create, operate, debug, and govern Harness CI/CD… The licence is Apache-2.0.

When your agent uses it

  • Asked to generate SLSA
  • Add SLSA provenance
  • SLSA Generation step
  • Configure SLSA Level 3 provenance in a pipeline

Example prompts

  • “/generate-slsa”

Requirements

  • Docker
  • Compatibility (from SKILL.md): Requires Harness MCP v2 server (harness-mcp-v2)

Workflow steps

12 steps, taken from the first numbered list in SKILL.md.

  1. One question per turn — use AskQuestion when available; otherwise numbered options with (Recommended).
  2. Opening message — add SLSA Generation after image build/push; mention attestation options.
  3. Progress breadcrumb — after pipeline fetch
  4. Record answers — running summary; do not re-ask unless the user changes direction.
  5. Fetch before configure — harness_get before placement/source questions.
  6. Show pipeline structure — highlight build/push steps and existing provenance / SscaOrchestration steps (UI: SLSA Generation).
  7. Infer connector from build/push — skip connector question when unambiguous from YAML.
  8. Never guess image tags — always ask for image/repo in Phase 7.
  9. Confirm before write — summary + harness_update only after user confirms.
  10. Stop after update — after successful harness_update, provide a configuration summary and
  11. Phase 3 Placement is mandatory — always run Phase 2 then Phase 3, even with one CI stage or prior session context.
  12. Sequential with SBOM — if SscaOrchestration exists, place SLSA after it; never parallel (Cosign race).

What it can do on your machine

Read from SKILL.md and the folder at commit c25faee. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are yaml).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

  • Compatibility

    Requires Harness MCP v2 server (harness-mcp-v2)

    From compatibility in the SKILL.md frontmatter.

Context cost

Generate Slsa loads about 3k tokens when it runs, and up to ~6.5k if it reads all its reference files. Until then it costs about 178 tokens; SKILL.md has 1,009 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~178
When it runs · the whole SKILL.md, loaded when a task matches
~3k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~6.5k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from harness/harness-skills at commit c25faee, republished under its Apache-2.0 licence (© harness). 1,009 words, ~2,962 tokens.

Download SKILL.mdSave it as .claude/skills/generate-slsa/SKILL.md (or your agent's skills folder). This skill also uses 3 other files; get the full folder from GitHub.
name
generate-slsa
description
Add a SLSA Generation step (YAML type: provenance) to an existing Harness pipeline to generate SLSA provenance and optionally attest with Cosign (keyless, key-based, or Vault). Supports container images (Docker, ECR, GCR, GAR, ACR, HAR) and Harness Local Stage artifacts. Place after image build/push; run sequentially after SBOM steps, not in parallel. Only works with existing pipelines. Use when asked to generate SLSA, add SLSA provenance, SLSA Generation step, attest SLSA, or configure SLSA Level 3 provenance in a pipeline. Trigger phrases: generate SLSA, SLSA generation, add SLSA step, SLSA provenance, attest SLSA, SlsaGeneration, provenance step, SLSA attestation, add provenance step.
compatibility
Requires Harness MCP v2 server (harness-mcp-v2)
metadata.author
Harness
metadata.version
1.0.0
metadata.mcp-server
harness-mcp-v2
license
Apache-2.0

Generate SLSA

Add a SLSA Generation step to an existing Harness pipeline to generate SLSA provenance and optionally attest/sign the .att file in the container registry. Pipeline YAML uses type: provenance (UI label: SLSA Generation; do not use SlsaGeneration — API rejects it).

This skill only works with existing pipelines — do not create standalone SLSA-only pipelines.

Prerequisites: Image must be built and pushed (or available in registry) before SLSA runs. Key-based attestation requires Cosign key pair secrets (/create-secret). Harness Cloud builds enable SLSA Level 3 provenance when using hosted infrastructure.

Guide the user through a step-by-step interactive wizard (same UX as /configure-repo-scan):

  • Wizard: references/interactive-wizard-flow.md
  • UI ↔ YAML: references/slsa-generation-step.md
  • CD containerized step groups: references/cd-containerized-step-group.md

Interaction model (mandatory)

  1. One question per turn — use AskQuestion when available; otherwise numbered options with (Recommended).
  2. Opening message — add SLSA Generation after image build/push; mention attestation options.
  3. Progress breadcrumb — after pipeline fetch: Pipeline · Placement · Source · Details · Attestation · Submit
  4. Record answers — running summary; do not re-ask unless the user changes direction.
  5. Fetch before configure — harness_get before placement/source questions.
  6. Show pipeline structure — highlight build/push steps and existing provenance / SscaOrchestration steps (UI: SLSA Generation).
  7. Infer connector from build/push — skip connector question when unambiguous from YAML.
  8. Never guess image tags — always ask for image/repo in Phase 7.
  9. Confirm before write — summary + harness_update only after user confirms.
  10. Stop after update — after successful harness_update, provide a configuration summary and point the user to /run-pipeline to execute. Do not call harness_execute, poll executions, or run harness_diagnose in this skill (same pattern as /configure-repo-scan).
  11. Phase 3 Placement is mandatory — always run Phase 2 then Phase 3, even with one CI stage or prior session context.
  12. Sequential with SBOM — if SscaOrchestration exists, place SLSA after it; never parallel (Cosign race).
  13. CD path — Deploy stage steps go inside containerized stepGroup only — see CD reference.

Full phase prompts: references/interactive-wizard-flow.md.


Instructions

Wizard phases
PhaseBreadcrumbAction
0PipelineAskQuestion: pipeline URL ready?
1PipelineCollect URL → harness_get
2PipelineDisplay structure; note build/push + SBOM steps
3PlacementMandatory AskQuestion: stage + position (after build/push recommended)
3bPlacement (CD)Service, env, infra, step group if new Deploy stage
4SourceAskQuestion: Third-Party, HAR, or Local
5SourceAskQuestion: registry provider (Third-Party only)
6DetailsConnector (skip if obvious)
7DetailsImage/repo; optional digest expression
8AttestationAskQuestion: keyless, keybased, vault, or none
9SubmitAskQuestion: confirm pipeline update

After Phase 9 confirm → generate YAML, insert step, harness_update, then provide summary (do not run the pipeline).

Supported stage types
Stage typePlacement notes
CIRecommended — immediately after BuildAndPush* or image push Run step
DeploymentContainerized step group only; before deploy — uncommon for generation
SecurityEnd of stage when scanning pre-built registry images
After the wizard — backend steps
Extract connectors from pipeline YAML

From BuildAndPushDockerRegistry, BuildAndPushECR, Run, Plugin, SscaOrchestration, provenance (SLSA Generation), or SscaArtifactSigning steps — reuse connectorRef / connector.

Generate SLSA step YAML

Use only wizard answers. Default attestation: keyless Harness OIDC when user chose defaults.

Docker Registry — matches reference UI (key-based attestation):

yaml
- step:
    identifier: slsageneration
    name: slsa-generation
    type: provenance
    spec:
      source:
        type: docker
        spec:
          connector: lavakush07
          repo: lavakush07/easy-buggy-app:blog
      attestation:
        type: keybased
        spec:
          privateKey: account.cosign_private_key
          password: account.cosign_password
    timeout: 15m

Keyless attestation (default for “use defaults”):

yaml
      attestation:
        type: keyless
        spec:
          oidcProvider: harness

With digest from Build and Push:

yaml
      source:
        type: docker
        spec:
          connector: <docker_registry_connector>
          repo: <org>/<repo>:<tag>
          digest: <+pipeline.stages.<stage>.spec.execution.steps.<build_step>.output.outputVariables.digest>

Amazon ECR:

yaml
      source:
        type: ecr
        spec:
          connector: <registry_connector>
          image: <repo/name>
          region: <aws_region>
          account: <aws_account_id>

Google GCR / GAR / Azure ACR / HAR / Local: see references/slsa-generation-step.md.

No attestation: omit attestation block.

Insert step into pipeline YAML
  • Insert at Phase 3 placement — after build/push (or after generate_sbom when both exist).
  • Do not modify unrelated steps, variables, or failure strategies.
  • Step identifier: slsageneration (suffix _cd in CD when CI already has one).
  • CD: inside containerized stepGroup.steps only.
Update pipeline via MCP
harness_update
  resource_type: pipeline
  resource_id: <pipeline_identifier>
  org_id: <organization>
  project_id: <project>
  body: { yamlPipeline: "<updated pipeline YAML>" }

On validation errors, read the API message, fix fields (often repo vs image, attestation spec), retry.

Show full SKILL.md (417 more words)Show less
Provide summary

Report the results to the user (same pattern as /configure-repo-scan — do not execute the pipeline):

## SLSA Generation Configured

**Pipeline:** <pipeline_name>
**Step:** SLSA Generation (`provenance`)
**Location:** Stage "<stage_name>", <position>
**Source:** docker — <connector> — <repo/image>
**Attestation:** Key-based (account.cosign_private_key) — or as configured

**Pipeline URL:** https://app.harness.io/ng/account/<account_id>/module/ci/orgs/<org_id>/projects/<project_id>/pipelines/<pipeline_id>/pipeline-studio/

**Note:** Review the SLSA Generation step in Pipeline Studio to adjust Advanced settings.

**Provenance:** After a successful run, view on the Supply Chain tab and in SCS Artifacts.

### Next Steps
1. Run the pipeline via `/run-pipeline` to verify the SLSA Generation step executes successfully
2. If the run fails, diagnose with `/debug-pipeline`
3. Add SLSA verification with `/enforce-slsa`
4. Pair with `SscaOrchestration` (Generate SBOM) — run SBOM then SLSA sequentially
5. Automate with `/create-trigger`

CD pipelines: note in the summary if runtime inputs (service artifact, environment, infrastructure) will be required at run time — the user provides those via /run-pipeline or Harness UI Run.


Examples

After Docker build/push — key-based attestation (reference UI)
/generate-slsa
Add SLSA Generation to my CI pipeline after docker push — lavakush07/easy-buggy-app:blog, key-based attest with account cosign secrets
Keyless defaults on Harness Cloud
/generate-slsa
Use defaults — keyless Harness OIDC after Build_and_Push step
With digest expression
/generate-slsa
Generate SLSA for image from Build_and_Push digest output — keyless attest
Placement must be explicit
/generate-slsa
add slsa to the pipeline

Agent must still run Phase 2 + Phase 3 — do not assume stage or skip placement.


Performance Notes

  • Only existing pipelines — do not create standalone SLSA pipelines (may append Deploy stage for CD).
  • Wizard UX is mandatory — one question per turn; see references/interactive-wizard-flow.md.
  • Placement after build/push — SLSA needs a published image (tag or digest).
  • Sequential with SBOM — never parallel SBOM + SLSA attestation (Cosign registry race).
  • YAML step type is provenance — not SlsaGeneration (API enum rejects SlsaGeneration).
  • Docker UI Image field → YAML source.spec.repo (not image; SBOM SscaOrchestration uses image for docker).
  • Key-based attestation — private key + password must be Harness file secrets (/create-secret).
  • CD generation is rare — prefer CI generation + CD /enforce-slsa; see CD reference.
  • Do not execute pipelines in this skill — use /run-pipeline after configuration (same as /configure-repo-scan).
  • Do not use for dashboard-only SSCA config — use /manage-supply-chain instead.

Troubleshooting

Pipeline Not Found
  • Verify org/project; harness_list (resource_type: pipeline).
Connector Not Found
  • Search build/push steps for connectorRef; harness_search for Docker registry connectors.
Image Not Found / Invalid Reference
  • Use single repo string — e.g. lavakush07/easy-buggy-app:blog.
  • Symptom: provenance generation fails — confirm image exists at run time.
Attestation Failed (Key-based)
  • Verify file secrets exist and Cosign key is ecdsa-p256.
  • Password secret must match the key pair generation password.
  • JFrog registries need extra connector permissions for .att upload.
Attestation Failed (Keyless)
  • Requires Harness CI execution context; configure Connector for Keyless Signing for non-harness OIDC.
SBOM + SLSA Race
  • Symptom: only one .att in registry — steps ran in parallel.
  • Fix: reorder — SBOM then SLSA sequentially in the same stage.
CD Validation Errors
  • provenance (SLSA Generation) in Deploy stages must be inside stepGroup with stepGroupInfra.
  • See references/cd-containerized-step-group.md.
YAML Rejects SlsaGeneration Step Type
  • Symptom: does not have a value in the enumeration for SlsaGeneration.
  • Fix: use type: provenance — validate with harness_schema(resource_type="pipeline", path="steps").
Skipped Placement
  • Re-run wizard from Phase 2; ask stage + position explicitly.
Pipeline Run Failed
  • Use /run-pipeline to execute and /debug-pipeline to diagnose failures
  • Verify image exists in registry and Cosign secrets are valid file secrets
  • CD: provide service/env/infra inputs via /run-pipeline or Harness UI Run — do not guess runtime inputs
MCP Errors
  • CONNECTOR_NOT_FOUND — verify connector identifier.
  • ACCESS_DENIED — PAT needs pipeline edit permission.

© harness, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 3 other files (references) in skills/generate-slsa of harness/harness-skills.

  • SKILL.md
  • references/cd-containerized-step-group.md
  • references/interactive-wizard-flow.md
  • references/slsa-generation-step.md

Open the folder on GitHubat commit c25faee

Compare with similar skills

Generate Slsa next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Generate Slsa compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Generate Slsa this skillharness/harness-skills115—~3kAutomated safety check: PassApache-2.0
Warp Vulnerability Triagewarpdotdev/warp65k1 repos~2.1kAutomated safety check: PassAGPL-3.0
Container Scanning with GrypeAgentSecOps/SecOpsAgentKit2201 repos~2.5kAutomated safety check: PassCustom licence
Container Securityhardw00t/ai-security-arsenal104—~2.8kAutomated safety check: PassNone
Sca TrivyAgentSecOps/SecOpsAgentKit2202 repos~3.7kAutomated safety check: PassCustom licence
Container Security Hardeningsickn33/agentic-awesome-skills47k1 repos~1kAutomated safety check: NotesMIT

Similar skills

  • Gathers security findings from Dependabot, GCP container scanning, Docker Scout and Linear security issues, then triages and remediates them across Warp's repos and images.

    65k GitHub starsUsed in 1 repo~2.1k tokens
    SecurityAuto-check passed
  • Container Scanning with Grype

    AgentSecOps/SecOpsAgentKit

    Scans container images, filesystems and SBOMs with Grype for known vulnerabilities, ranks them by CVSS, EPSS and CISA KEV, and wires scans into CI/CD thresholds.

    220 GitHub starsUsed in 1 repo~2.5k tokens
    SecurityAuto-check passed
  • Container Security

    hardw00t/ai-security-arsenal

    Container and Kubernetes security assessment — image vulnerability scanning, SBOM diff analysis, K8s cluster auditing, RBAC privilege mapping, NetworkPolicy review, container escape testing, and…

    104 GitHub stars~2.8k tokensUpdated 5 mo ago
    SecurityAuto-check passed
  • Sca Trivy

    AgentSecOps/SecOpsAgentKit

    Software Composition Analysis (SCA) and container vulnerability scanning using Aqua Trivy for identifying CVE vulnerabilities in dependencies, container images, IaC misconfigurations, and license…

    220 GitHub starsUsed in 2 repos~3.7k tokens
    SecurityAuto-check passed
  • Container Security Hardening

    sickn33/agentic-awesome-skills

    Harden Docker/container images and runtime deployments with secure base images, non-root users, CVE scanning, SBOM/signing, seccomp/AppArmor, and Kubernetes pod security controls.

    47k GitHub starsUsed in 1 repo~1k tokens
    SecurityAuto-check: notes
  • Container Sbom

    cdxgen/cdxgen

    Generates CycloneDX BOMs for container images, OCI archives, mounted root filesystems, Electron ASAR archives, caxa executables, binaries, and Kubernetes or Dockerfile manifests using OWASP cdxgen…

    1.1k GitHub stars~1.5k tokensUpdated today
    DevOps & CloudAuto-check passed

More from harness/harness-skills

All 24 skills in this repo
  • Audit Report

    harness/harness-skills

    Generate audit reports and compliance trails using Harness audit trail data via MCP v2 tools.

    115 GitHub stars~1.3k tokensUpdated yesterday
    Auto-check passed
  • Chaos Dr Test

    harness/harness-skills

    A skill your agent uses when working with Chaos Engineering steps inside a Harness pipeline.

    115 GitHub stars~2.6k tokensUpdated yesterday
    Auto-check passed
  • Chaos Experiment

    harness/harness-skills

    A skill your agent uses when the user asks to create, edit, update, design, or configure a Harness Chaos Experiment — including faults, probes, actions, experiment YAML, fault injection, pod-delete…

    115 GitHub stars~1.6k tokensUpdated yesterday
    Auto-check passed
  • Cleanup Feature Flags

    harness/harness-skills

    Remove a launched Harness FME feature flag from application code, keeping the treatment FME serves today, and open a pull request.

    115 GitHub stars~2.4k tokensUpdated yesterday
    Auto-check passed
  • Configure Repo Scan

    harness/harness-skills

    Configure code scanning in Harness pipelines using STO security scanners.

    115 GitHub stars~2.2k tokensUpdated yesterday
    Auto-check passed
  • Create Agent Template

    harness/harness-skills

    Generate Harness Agent Template files for AI-powered automation agents.

    115 GitHub stars~2.2k tokensUpdated yesterday
    Auto-check passed

Works with

Categories

Questions about Generate Slsa

What does Generate Slsa do?

Add a SLSA Generation step (YAML type: provenance) to an existing Harness pipeline to generate SLSA provenance and optionally attest with Cosign (keyless, key-based, or Vault). Generate Slsa is an agent skill from harness/harness-skills. Add a SLSA Generation step (YAML type: provenance) to an existing Harness pipeline to generate SLSA provenance and optionally attest with Cosign (keyless, key-based, or Vault).

When should I use Generate Slsa?

Generate Slsa fits situations like: asked to generate SLSA; add SLSA provenance; SLSA Generation step; configure SLSA Level 3 provenance in a pipeline.

How do I install Generate Slsa in Claude Code?

Run `npx skills add harness/harness-skills --skill generate-slsa -a claude-code`. Or copy the skill folder (skills/generate-slsa in harness/harness-skills) into .claude/skills/generate-slsa in your project. Claude Code loads it when a task matches its description.

How do I install Generate Slsa in Codex?

Run `npx skills add harness/harness-skills --skill generate-slsa -a codex`. Or copy the skill folder (skills/generate-slsa in harness/harness-skills) into .agents/skills/generate-slsa in your project. Codex loads it when a task matches its description.

Can I use Generate Slsa in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add harness/harness-skills --skill generate-slsa -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/generate-slsa, .gemini/skills/generate-slsa, .github/skills/generate-slsa and .opencode/skills/generate-slsa in your project.

What does Generate Slsa need to run?

SKILL.md names no scripts, command-line tools or credentials: Generate Slsa is instructions for the agent only. Our summary lists: Docker. Compatibility (from SKILL.md): Requires Harness MCP v2 server (harness-mcp-v2).

Does Generate Slsa access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Generate Slsa safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Generate Slsa use?

Generate Slsa is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Generate Slsa use?

About 3k tokens (SKILL.md is roughly 12k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 3.6k tokens, read only when the agent opens those files.

What are the alternatives to Generate Slsa?

Skills that share tags, products or a category with Generate Slsa: Warp Vulnerability Triage (warpdotdev/warp, 65k stars), Container Scanning with Grype (AgentSecOps/SecOpsAgentKit, 220 stars), Container Security (hardw00t/ai-security-arsenal, 104 stars) and Sca Trivy (AgentSecOps/SecOpsAgentKit, 220 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Generate Slsa?

harness (a GitHub organization) maintains it in harness/harness-skills, which has 115 GitHub stars. The repository holds 24 skills in this directory. The repository was last updated on October 6, 2026.

Source: harness/harness-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.