Bom Audit
cdxgen/cdxgen
Runs supply-chain risk analysis on CycloneDX BOMs with cdx-audit predictive auditing and cdxgen --bom-audit embedded rules, covering npm and PyPI package compromise posture, CI permission risk…
Inkline's platform & trust surface — the styleframe license boundary, supply-chain and secrets hygiene, npm distribution integrity, and the future Studio/commercial direction.
$ npx skills add inkline/inkline --skill platform-trust -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install inkline/inkline platform-trust --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/inkline/inkline.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/platform-trust .claude/skills/platform-trust && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "platform-trust" agent skill from https://github.com/inkline/inkline/tree/main/.claude/skills/platform-trust into .claude/skills/platform-trust/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "platform-trust", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/inkline/inkline/tree/main/.claude/skills/platform-trustType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add inkline/inkline --skill platform-trust -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install inkline/inkline platform-trust --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/inkline/inkline.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.claude/skills/platform-trust .agents/skills/platform-trust && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "platform-trust" agent skill from https://github.com/inkline/inkline/tree/main/.claude/skills/platform-trust into .agents/skills/platform-trust/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "platform-trust", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add inkline/inkline --skill platform-trust -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install inkline/inkline platform-trust --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/inkline/inkline.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.claude/skills/platform-trust .cursor/skills/platform-trust && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "platform-trust" agent skill from https://github.com/inkline/inkline/tree/main/.claude/skills/platform-trust into .cursor/skills/platform-trust/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "platform-trust", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/inkline/inkline.git --path .claude/skills/platform-trust--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add inkline/inkline --skill platform-trust -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install inkline/inkline platform-trust --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/inkline/inkline.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.claude/skills/platform-trust .gemini/skills/platform-trust && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "platform-trust" agent skill from https://github.com/inkline/inkline/tree/main/.claude/skills/platform-trust into .gemini/skills/platform-trust/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "platform-trust", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install inkline/inkline platform-trustInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add inkline/inkline --skill platform-trust -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/inkline/inkline.git skills-src && mkdir -p .github/skills && cp -r skills-src/.claude/skills/platform-trust .github/skills/platform-trust && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "platform-trust" agent skill from https://github.com/inkline/inkline/tree/main/.claude/skills/platform-trust into .github/skills/platform-trust/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "platform-trust", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add inkline/inkline --skill platform-trust -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install inkline/inkline platform-trust --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/inkline/inkline.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.claude/skills/platform-trust .opencode/skills/platform-trust && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "platform-trust" agent skill from https://github.com/inkline/inkline/tree/main/.claude/skills/platform-trust into .opencode/skills/platform-trust/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "platform-trust", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
platform-trustInkline's platform & trust surface — the styleframe license boundary, supply-chain and secrets hygiene, npm distribution integrity, and the future Studio/commercial direction.
Platform Trust is an agent skill from inkline/inkline. Inkline's platform & trust surface — the styleframe license boundary, supply-chain and secrets hygiene, npm distribution integrity, and the future Studio/commercial direction. Use for anything touching licenses, dependencies, tokens, or product surfaces.
Its SKILL.md is about 1.1k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Security, covering Supply chain security. It works with npm. The repository describes itself as: Inkline is the intuitive UI Components library that gives you a developer-friendly foundation for building high-quality, accessible, and customizable Vue.js 3 Design Systems.
5 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit f4da55a. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
pnpmFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use pnpm, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names these keys or tokens, usually read from environment variables:
STYLEFRAME_KEYNPM_TOKENCODECOV_TOKENFrom names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Platform Trust loads about 1.1k tokens when it runs. Until then it costs about 67 tokens; SKILL.md has 561 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
Without a licence we can't republish the file, so here is its outline and opening line. It has 561 words (~1,086 tokens).
“Inkline is MIT, free, and has no in-repo commercial layer today. The commercial gravity sits next door: styleframe (the styling engine Inkline consumes) has an MIT core + paid Pro layer, and the long-term product direction is Studio — the…”
Just SKILL.md in .claude/skills/platform-trust of inkline/inkline.
Open the folder on GitHubat commit f4da55a
Platform Trust next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Platform Trust this skillinkline/inkline | 1.5k | — | ~1.1k | Automated safety check: Pass | None | |
| Bom Auditcdxgen/cdxgen | 1.1k | — | ~2.4k | Automated safety check: Pass | Apache-2.0 | |
| Vex Authoringrelizaio/rearm | 127 | — | ~2.9k | Automated safety check: Pass | AGPL-3.0 | |
| Dependency Update Auditbacknotprop/plannotator | 9.2k | — | ~1.8k | Automated safety check: Pass | Apache-2.0 | |
| Supply Chain Risk Auditortrailofbits/skills | 7.4k | — | ~1.7k | Automated safety check: Notes | CC-BY-SA-4.0 | |
| Corpus Sweepnubjs/nub | 4.4k | — | ~2.4k | Automated safety check: Pass | MIT |
cdxgen/cdxgen
Runs supply-chain risk analysis on CycloneDX BOMs with cdx-audit predictive auditing and cdxgen --bom-audit embedded rules, covering npm and PyPI package compromise posture, CI permission risk…
relizaio/rearm
Author CycloneDX-VEX or OpenVEX documents that import cleanly into ReARM.
backnotprop/plannotator
Audits outdated npm and Bun packages for supply chain integrity before bumping them, deferring risky ones and logging every decision.
trailofbits/skills
Audits a project's dependencies for supply-chain risk: version-matched advisories for direct dependencies and the full lockfile tree, abandoned or archived upstreams, npm publisher concentration…
nubjs/nub
Run a large sharded measurement sweep over npm packages (the build-jail catalog probe, or any harness that installs thousands of package-versions and records a verdict per run).
briiirussell/cybersecurity-skills
Audit project dependencies, frameworks, languages, and dev tools for known vulnerabilities, CVEs, and security anti-patterns.
inkline/inkline
Repro-first QA for Inkline — minimal .ink.tsx reproductions, the visual-parity and cross-target harnesses, fuzz targets, and how to audit teammates' claims.
inkline/inkline
How Inkline measures itself — compile performance, output size and quality vs hand-written components and Mitosis, fairness rules, and reporting format.
inkline/inkline
The Inkline compiler's end-to-end pipeline — parse → IR → analyze → per-target codegen → print — including the IR contracts, reactivity tracking, target rewrite rules, plugin hooks, the two compile…
inkline/inkline
How Inkline components are built and kept consistent — the headless/styled split, family anatomy, prop/axis conventions, recipe consumption, the current 5-family catalog and its gap list.
inkline/inkline
Author a pull request in the Guild's standard shape — a fixed Summary / Changes / Verification / Notes skeleton that mirrors the review-gate, plus the hard anti-leak rule that no agent @mention or…
inkline/inkline
How design tokens and recipes flow from styleframe into Inkline — the presets, the two faces of virtual:styleframe, recipe class contracts, theming, and the rules for custom CSS in components.
Works with
Categories
Inkline's platform & trust surface — the styleframe license boundary, supply-chain and secrets hygiene, npm distribution integrity, and the future Studio/commercial direction. Platform Trust is an agent skill from inkline/inkline. Inkline's platform & trust surface — the styleframe license boundary, supply-chain and secrets hygiene, npm distribution integrity, and the future Studio/commercial direction.
Platform Trust fits situations like: anything touching licenses; product surfaces.
Run `npx skills add inkline/inkline --skill platform-trust -a claude-code`. Or copy the skill folder (.claude/skills/platform-trust in inkline/inkline) into .claude/skills/platform-trust in your project. Claude Code loads it when a task matches its description.
Run `npx skills add inkline/inkline --skill platform-trust -a codex`. Or copy the skill folder (.claude/skills/platform-trust in inkline/inkline) into .agents/skills/platform-trust in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add inkline/inkline --skill platform-trust -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/platform-trust, .gemini/skills/platform-trust, .github/skills/platform-trust and .opencode/skills/platform-trust in your project.
Going by SKILL.md and its folder, Platform Trust needs the command-line tools its instructions call (pnpm) and credentials named STYLEFRAME_KEY, NPM_TOKEN and CODECOV_TOKEN. Our summary lists: A credential in STYLEFRAME_KEY; A credential in NPM_TOKEN.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
No licence was found for Platform Trust or its repository. Without one, default copyright applies: ask the author before reusing or redistributing it.
About 1.1k tokens (SKILL.md is roughly 4.3k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Platform Trust: Bom Audit (cdxgen/cdxgen, 1.1k stars), Vex Authoring (relizaio/rearm, 127 stars), Dependency Update Audit (backnotprop/plannotator, 9.2k stars) and Supply Chain Risk Auditor (trailofbits/skills, 7.4k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
inkline (a GitHub organization) maintains it in inkline/inkline, which has 1,469 GitHub stars. The repository holds 23 skills in this directory. The repository was last updated on September 11, 2026.
Source: inkline/inkline on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.