Agent skill

Platform Trust

by inkline in inkline/inkline

Inkline's platform & trust surface — the styleframe license boundary, supply-chain and secrets hygiene, npm distribution integrity, and the future Studio/commercial direction.

No licenceAuto-check passedSecurity

Install Platform Trust

skills CLI
$ npx skills add inkline/inkline --skill platform-trust -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install inkline/inkline platform-trust --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/inkline/inkline.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/platform-trust .claude/skills/platform-trust && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
platform-trust
GitHub stars
1.5k
Token cost
~1.1k tokens
SKILL.md length
561 words
Files
1
Skills in repo
23
Repo updated
First seen
Licence
None found

At a glance

Inkline's platform & trust surface — the styleframe license boundary, supply-chain and secrets hygiene, npm distribution integrity, and the future Studio/commercial direction.

  • Works in 5 steps: Never weaken the license/watermark… → Never commit/log secrets or keys; env… → Anything touching money, entitlements,… → …
  • Anything touching licenses
  • SKILL.md covers The lay of the land…, Surface 1 — the styleframe…, Surface 2 — supply chain &… and Surface 3 — the product…, plus 1 more section
  • Calls pnpm; needs STYLEFRAME_KEY and NPM_TOKEN

What it does

Platform Trust is an agent skill from inkline/inkline. Inkline's platform & trust surface — the styleframe license boundary, supply-chain and secrets hygiene, npm distribution integrity, and the future Studio/commercial direction. Use for anything touching licenses, dependencies, tokens, or product surfaces.

Its SKILL.md is about 1.1k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Security, covering Supply chain security. It works with npm. The repository describes itself as: Inkline is the intuitive UI Components library that gives you a developer-friendly foundation for building high-quality, accessible, and customizable Vue.js 3 Design Systems.

When your agent uses it

  • Anything touching licenses
  • Product surfaces

Example prompts

  • “/platform-trust”

Requirements

  • A credential in STYLEFRAME_KEY
  • A credential in NPM_TOKEN

Workflow steps

5 steps, taken from the first numbered list in SKILL.md.

  1. Never weaken the license/watermark boundary (Surface 1) — and never make it more hostile either.
  2. Never commit/log secrets or keys; env only.
  3. Anything touching money, entitlements, pricing, or license enforcement — Alex approves before merge, no exceptions for "small" changes.
  4. Production infrastructure (when it exists) is not a sandbox: schema/config changes are proposed in the issue, Alex approves, applied via…
  5. Supply-chain guard exclusions and postinstall allowances are never waved through as chores.

What it can do on your machine

Read from SKILL.md and the folder at commit f4da55a. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • pnpm

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use pnpm, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • STYLEFRAME_KEY
    • NPM_TOKEN
    • CODECOV_TOKEN

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Platform Trust loads about 1.1k tokens when it runs. Until then it costs about 67 tokens; SKILL.md has 561 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~67
When it runs · the whole SKILL.md, loaded when a task matches
~1.1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

Without a licence we can't republish the file, so here is its outline and opening line. It has 561 words (~1,086 tokens).

“Inkline is MIT, free, and has no in-repo commercial layer today. The commercial gravity sits next door: styleframe (the styling engine Inkline consumes) has an MIT core + paid Pro layer, and the long-term product direction is Studio — the…”

— opening of SKILL.md by inkline
name
platform-trust

Read the full SKILL.md on GitHub

Files

Just SKILL.md in .claude/skills/platform-trust of inkline/inkline.

Open the folder on GitHubat commit f4da55a

Compare with similar skills

Platform Trust next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Platform Trust compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Platform Trust this skillinkline/inkline1.5k—~1.1kAutomated safety check: PassNone
Bom Auditcdxgen/cdxgen1.1k—~2.4kAutomated safety check: PassApache-2.0
Vex Authoringrelizaio/rearm127—~2.9kAutomated safety check: PassAGPL-3.0
Dependency Update Auditbacknotprop/plannotator9.2k—~1.8kAutomated safety check: PassApache-2.0
Supply Chain Risk Auditortrailofbits/skills7.4k—~1.7kAutomated safety check: NotesCC-BY-SA-4.0
Corpus Sweepnubjs/nub4.4k—~2.4kAutomated safety check: PassMIT

Similar skills

  • Bom Audit

    cdxgen/cdxgen

    Runs supply-chain risk analysis on CycloneDX BOMs with cdx-audit predictive auditing and cdxgen --bom-audit embedded rules, covering npm and PyPI package compromise posture, CI permission risk…

    1.1k GitHub stars~2.4k tokensUpdated today
    SecurityAuto-check passed
  • Vex Authoring

    relizaio/rearm

    Author CycloneDX-VEX or OpenVEX documents that import cleanly into ReARM.

    127 GitHub stars~2.9k tokensUpdated today
    SecurityAuto-check passed
  • Dependency Update Audit

    backnotprop/plannotator

    Audits outdated npm and Bun packages for supply chain integrity before bumping them, deferring risky ones and logging every decision.

    9.2k GitHub stars~1.8k tokensUpdated today
    SecurityAuto-check passed
  • Supply Chain Risk Auditor

    trailofbits/skills

    Official

    Audits a project's dependencies for supply-chain risk: version-matched advisories for direct dependencies and the full lockfile tree, abandoned or archived upstreams, npm publisher concentration…

    7.4k GitHub stars~1.7k tokensUpdated yesterday
    SecurityAuto-check: notes
  • Corpus Sweep

    nubjs/nub

    Run a large sharded measurement sweep over npm packages (the build-jail catalog probe, or any harness that installs thousands of package-versions and records a verdict per run).

    4.4k GitHub stars~2.4k tokensUpdated today
    SecurityAuto-check passed
  • Dependency Audit

    briiirussell/cybersecurity-skills

    Audit project dependencies, frameworks, languages, and dev tools for known vulnerabilities, CVEs, and security anti-patterns.

    413 GitHub stars~3.2k tokensUpdated 4 mo ago
    SecurityAuto-check: warnings

More from inkline/inkline

All 23 skills in this repo
  • Adversarial QA

    inkline/inkline

    Repro-first QA for Inkline — minimal .ink.tsx reproductions, the visual-parity and cross-target harnesses, fuzz targets, and how to audit teammates' claims.

    1.5k GitHub stars~1.2k tokensUpdated 27 days ago
    Auto-check passed
  • Benchmark Protocol

    inkline/inkline

    How Inkline measures itself — compile performance, output size and quality vs hand-written components and Mitosis, fairness rules, and reporting format.

    1.5k GitHub stars~955 tokensUpdated 27 days ago
    Auto-check passed
  • The Inkline compiler's end-to-end pipeline — parse → IR → analyze → per-target codegen → print — including the IR contracts, reactivity tracking, target rewrite rules, plugin hooks, the two compile…

    1.5k GitHub stars~1.9k tokensUpdated 27 days ago
    Auto-check passed
  • Component Catalog

    inkline/inkline

    How Inkline components are built and kept consistent — the headless/styled split, family anatomy, prop/axis conventions, recipe consumption, the current 5-family catalog and its gap list.

    1.5k GitHub stars~1.4k tokensUpdated 27 days ago
    Auto-check passed
  • Create PR

    inkline/inkline

    Author a pull request in the Guild's standard shape — a fixed Summary / Changes / Verification / Notes skeleton that mirrors the review-gate, plus the hard anti-leak rule that no agent @mention or…

    1.5k GitHub stars~1.7k tokensUpdated 27 days ago
    Auto-check passed
  • How design tokens and recipes flow from styleframe into Inkline — the presets, the two faces of virtual:styleframe, recipe class contracts, theming, and the rules for custom CSS in components.

    1.5k GitHub stars~1.2k tokensUpdated 27 days ago
    Auto-check passed

Works with

Categories

Questions about Platform Trust

What does Platform Trust do?

Inkline's platform & trust surface — the styleframe license boundary, supply-chain and secrets hygiene, npm distribution integrity, and the future Studio/commercial direction. Platform Trust is an agent skill from inkline/inkline. Inkline's platform & trust surface — the styleframe license boundary, supply-chain and secrets hygiene, npm distribution integrity, and the future Studio/commercial direction.

When should I use Platform Trust?

Platform Trust fits situations like: anything touching licenses; product surfaces.

How do I install Platform Trust in Claude Code?

Run `npx skills add inkline/inkline --skill platform-trust -a claude-code`. Or copy the skill folder (.claude/skills/platform-trust in inkline/inkline) into .claude/skills/platform-trust in your project. Claude Code loads it when a task matches its description.

How do I install Platform Trust in Codex?

Run `npx skills add inkline/inkline --skill platform-trust -a codex`. Or copy the skill folder (.claude/skills/platform-trust in inkline/inkline) into .agents/skills/platform-trust in your project. Codex loads it when a task matches its description.

Can I use Platform Trust in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add inkline/inkline --skill platform-trust -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/platform-trust, .gemini/skills/platform-trust, .github/skills/platform-trust and .opencode/skills/platform-trust in your project.

What does Platform Trust need to run?

Going by SKILL.md and its folder, Platform Trust needs the command-line tools its instructions call (pnpm) and credentials named STYLEFRAME_KEY, NPM_TOKEN and CODECOV_TOKEN. Our summary lists: A credential in STYLEFRAME_KEY; A credential in NPM_TOKEN.

Does Platform Trust access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Platform Trust safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Platform Trust use?

No licence was found for Platform Trust or its repository. Without one, default copyright applies: ask the author before reusing or redistributing it.

How many tokens does Platform Trust use?

About 1.1k tokens (SKILL.md is roughly 4.3k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Platform Trust?

Skills that share tags, products or a category with Platform Trust: Bom Audit (cdxgen/cdxgen, 1.1k stars), Vex Authoring (relizaio/rearm, 127 stars), Dependency Update Audit (backnotprop/plannotator, 9.2k stars) and Supply Chain Risk Auditor (trailofbits/skills, 7.4k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Platform Trust?

inkline (a GitHub organization) maintains it in inkline/inkline, which has 1,469 GitHub stars. The repository holds 23 skills in this directory. The repository was last updated on September 11, 2026.

Source: inkline/inkline on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.