Agent skill

Packslip

by jdx in jdx/packslip

Configure signed release manifests with packslip: add the jdx/packslip action or packslip create to a release workflow, declare completions, man pages, CLI specs, skills, and SBOMs as resources, and…

MITAuto-check passedSecurity

Install Packslip

skills CLI
$ npx skills add jdx/packslip --skill packslip -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install jdx/packslip packslip --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/jdx/packslip.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/packslip .claude/skills/packslip && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
packslip
GitHub stars
136
Token cost
~2.9k tokens
SKILL.md length
1,460 words
Files
1
Skills in repo
1
Repo updated
First seen
Licence
MIT

At a glance

Configure signed release manifests with packslip: add the jdx/packslip action or packslip create to a release workflow, declare completions, man pages, CLI specs, skills, and SBOMs as resources, and…

  • A repository has
  • SKILL.md covers Describe the release that was…, Declare completions, man…, Verify before publishing or… and References
  • Calls git; reaches github.com and token.actions.githubusercontent.com
  • Needs packslip.sigstore.json

What it does

Packslip is an agent skill from jdx/packslip. Configure signed release manifests with packslip: add the jdx/packslip action or packslip create to a release workflow, declare completions, man pages, CLI specs, skills, and SBOMs as resources, and verify bundles and downloaded artifacts. Use when a repository has or needs packslip.sigstore.json, a packslip release.toml, or the jdx/packslip action, or when packslip verification fails.

Its SKILL.md is about 2.9k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Security, covering Supply chain security. The repository describes itself as: A signed release manifest for vendor binaries. The licence is MIT.

When your agent uses it

  • A repository has
  • Needs packslip.sigstore.json
  • A packslip release.toml
  • The jdx/packslip action

Example prompts

  • “/packslip”

What it can do on your machine

Read from SKILL.md and the folder at commit 478b8c1. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • git

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • github.com
    • token.actions.githubusercontent.com

    Also links to:

    • packslip.dev

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Packslip loads about 2.9k tokens when it runs. Until then it costs about 100 tokens; SKILL.md has 1,460 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~100
When it runs · the whole SKILL.md, loaded when a task matches
~2.9k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from jdx/packslip at commit 478b8c1, republished under its MIT licence (© jdx). 1,460 words, ~2,938 tokens.

Download SKILL.mdSave it as .claude/skills/packslip/SKILL.md (or your agent's skills folder).
name
packslip
description
Configure signed release manifests with packslip: add the jdx/packslip action or `packslip create` to a release workflow, declare completions, man pages, CLI specs, skills, and SBOMs as resources, and verify bundles and downloaded artifacts. Use when a repository has or needs packslip.sigstore.json, a packslip release.toml, or the jdx/packslip action, or when packslip verification fails.

packslip

Work from the project's existing release workflow, artifact layout, and trust policy. Check packslip --version and the relevant subcommand's --help when flags differ from these examples.

Describe the release that was built

  • On GitHub Actions, add jdx/packslip@v1 after the steps that build the final files and create the release. By default it attests the matched files, signs the release manifest with the job's OIDC identity, verifies it, and uploads only the bundle to the release. Upload the artifacts and any asset: files yourself first. Without the action, packslip create writes the signed bundle and uploads nothing.

  • Pin the action to the full commit of its vX.Y.Z release. Its default CLI download is internally SHA-256 locked for every supported platform, then checked against the actual candidate build source and release-workflow provenance. The CLI/action tag still shares the final release commit. packslip-version explicitly overrides this internal lock (with a warning); set packslip-sha256 for a strict archive pin with that override. Checks run before extraction/execution. packslip-path supplies a local executable and bypasses archive/provenance checks. A source checkout without a release map requires one of these explicit trust overrides.

  • Prefer two jobs, so the signing job cannot change the release. Run the action with upload: false in a job with these permissions:

    yaml
    permissions:
      contents: read       # Download release assets; cannot change the release.
      id-token: write      # Sign with the workflow's OIDC identity.
      attestations: write  # Attest the files (the default attest: true).

    Upload the file at the action's bundle output with actions/upload-artifact, and attach it to the release from a second job that has contents: write. A contents: read token cannot see a draft release, so the action's download input cannot fetch its files. If the release stays a draft until the bundle is attached, download the build's files with actions/download-artifact and give their paths to the action's artifacts input instead. If the action instead runs as one step in an existing release job, it uploads the bundle itself, and that job needs contents: write in addition to the two write permissions above. See Publish with GitHub Actions for both layouts.

  • By default the action uses the triggering tag as tag, that tag without a leading v as version, and github.sha as commit. When the job does not run on the release tag, as in a manual dispatch from a branch, pass tag and the tag's full commit SHA as commit. Pass version explicitly when the tag without a leading v is not semver, such as mytool-v1.2.3 or v4.1; the action does not normalize tags.

  • Sign every release of a project from the same workflow file in the project's own repository. A consumer treats a release signed from a different workflow file as a new signer and refuses it until a person approves it, so run backfills from that file too. If releases must come from several workflow files of the repository, sign them with packslip create --no-pin-workflow. The action has no input for it (GitHub only warns about an input the action does not define and runs the step without it), so run packslip create in those jobs instead. Declare it from the first release: a consumer that accepted a release without it refuses the first one with it until a person approves it, and consumers that predate the field ignore it and still ask. See Workflow pinning.

  • Select only installable binaries or archives as artifacts. Declare companion files as resources. Inspect archive contents before setting paths: --bin mytool discovers the executable within an archive, while --bin mytool=bin/tool uses an explicit path from the true archive root.

  • Inspect inferred OS, architecture, libc, and format with packslip show. With packslip create, fix ambiguous metadata with an explicit artifact argument, such as dist/mytool.tar.gz:linux/x86_64/gnu, or PATH:any for a file that runs on every platform, or with a TOML manifest. The action's artifacts input takes only file paths and globs: set platforms in release.toml (the manifest input), and use the variants and formats inputs for those fields. Absent platform fields mean unrestricted, not unknown.

  • Leave the main build of each platform (OS, architecture, and libc) without a variant, and give every other distinct build of that platform its own variant, whatever its format; consumers select only artifacts without a variant unless a user asks for one. Artifacts that differ only in format must contain the same build, because consumers pick among them by format preference.

  • Do not list shared libraries; packslip create reads them from the executables it can open. Declare commands the program needs on PATH with --require bin:NAME[@MIN] (the action's require input), and put glibc_min or os_min on the artifact's requires in release.toml. See Host requirements.

Use CLI flags for shared metadata and a TOML manifest for per-artifact layouts, requirements, or resource scope. See Artifact configuration for release.toml examples, path rules, and every key.

Show full SKILL.md (690 more words)Show less

Declare completions, man pages, CLI specs, skills, and SBOMs

Each resource has exactly one source:

SourceUse it forWhat fixes the content to this release
archiveFiles already inside each applicable binary archiveArtifact digest
assetA separately uploaded file or skill archiveIts signed digest
repoA tracked directory such as skills/mytoolsource.repo and source.commit
execContent that must be generated by an installed executableThe verified executable; consumer execution policy still applies

For example, add these to the action's resources input:

yaml
resources: |
  cli-spec/usage/mytool=asset:dist/mytool.usage.kdl
  skill/mytool=repo:skills/mytool
  sbom/cyclonedx=asset:dist/mytool.cdx.json

The mytool qualifier binds the CLI specification to that executable, including in releases containing several commands. An SBOM names its format (sbom/cyclonedx or sbom/spdx) and cannot come from exec.

At the recorded release commit, the skill directory must contain SKILL.md and every file it links by relative path. A separate skill asset is an archive with SKILL.md at its root or under one top-level directory. An asset: value is a local path that packslip create reads. Upload the same file to the URL the bundle records (url-base plus the file name), because the action uploads only the bundle.

With packslip create, a repo resource also needs --source-repo and --commit, or repo and commit in a [source] table in release.toml; the action passes both flags. An exec command must start with one of the release's bin names.

Scope resources when archives have different layouts. On the command line or in the action's resources input, put @ and the platform after the kind and any qualifier: man@linux=archive:share/man/man1/mytool.1 or completion/zsh@darwin=archive:share/zsh/site-functions/_mytool. Scope to one exact artifact with artifact = "FILENAME" in a TOML [[resource]]. Do not declare a universal archive path that exists on only one target. Prefer static files for skills so installation does not require running the tool.

packslip create checks executable paths inside readable archives, but not archive: or repo: resource paths. List each archive (tar -tzf, unzip -l) to confirm every archive: path on every target it applies to. Confirm a repo: directory at the release commit with git cat-file -e COMMIT:skills/mytool/SKILL.md.

See Resources for the kind and qualifier grammar and for how consumers choose among entries.

Verify before publishing or consuming

packslip show BUNDLE decodes metadata; it does not verify trust. Verify the expected signer and downloaded artifacts together, for example:

sh
packslip verify packslip.sigstore.json \
  --identity-prefix 'https://github.com/owner/mytool/.github/workflows/release.yml@' \
  --issuer https://token.actions.githubusercontent.com \
  --artifact dist/mytool-linux-x64.tar.gz

Replace the identity with the project's actual trusted workflow. A repository prefix such as https://github.com/owner/mytool/ accepts any workflow of the repository; the workflow-file prefix above is narrower. Repeat --artifact for additional local files. Also compare the verified statement's project and version with the requested release; packslip verify does not enforce that match. For key-signed releases, use the vendor's trusted public key with --pubkey; do not obtain a new trust anchor from the same untrusted download just to make verification pass.

After the first keyless release, packslip pin packslip.sigstore.json prints the repository's signer fingerprint (ps1_ and 26 characters). Run it on a release you trust, because it names whichever repository signed the bundle. Publish the fingerprint in the install instructions so users can verify with --pin instead of trusting the first release they see. A fingerprint mismatch means another repository signed the release; never replace the pin to make verification pass. A key-signed project publishes its public key instead.

For local packaging checks, create a temporary key with packslip keygen, sign with packslip create --key ... --no-log, and verify with packslip verify --pubkey ... --allow-unlogged. Keep this explicit offline exception in the test; do not add it to production verification to work around a failure.

When verification fails, compare the expected identity, source commit, subject file name and digest with the actual release. Preserve the failure until its cause is understood. When only a resource is missing, inspect its selected source and path before changing signing or trust settings.

References

© jdx, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/packslip of jdx/packslip.

Open the folder on GitHubat commit 478b8c1

Compare with similar skills

Packslip next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Packslip compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Packslip this skilljdx/packslip136—~2.9kAutomated safety check: PassMIT
Skill Scannergetsentry/skills1k4 repos~2.5kAutomated safety check: WarnApache-2.0
Serenity Aleabitoreddityan-labs/serenity-aleabitoreddit4811 repos~3.3kAutomated safety check: PassNone
Eu CraSushegaad/Claude-Skills-Governance-Risk-and-Compliance9431 repos~4kAutomated safety check: PassMIT
Kesekit Checkcdppcorp/KESE-KIT361—~1.3kAutomated safety check: PassMIT
Bom Auditcdxgen/cdxgen1.1k—~2.4kAutomated safety check: PassApache-2.0

Similar skills

  • Skill Scanner

    getsentry/skills

    Official

    Scan agent skills for security issues. An agent skill from getsentry/skills.

    1k GitHub starsUsed in 4 repos~2.5k tokens
    SecurityAuto-check: warnings
  • Serenity Aleabitoreddit

    yan-labs/serenity-aleabitoreddit

    Apply trader Serenity's (@aleabitoreddit) AI/semiconductor supply-chain analytical lens to US-stock ideas and market judgment.

    481 GitHub starsUsed in 1 repo~3.3k tokens
    SecurityAuto-check passed
  • Eu Cra

    Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

    Expert EU Cyber Resilience Act (CRA) advisor for Regulation (EU) 2024/2847 — mandatory cybersecurity and vulnerability handling requirements for all products with digital elements (PDEs) sold in the…

    943 GitHub starsUsed in 1 repo~4k tokens
    SecurityAuto-check passed
  • Kesekit Check

    cdppcorp/KESE-KIT

    Run a pre-deployment security compliance checklist based on KISA guidelines.

    361 GitHub stars~1.3k tokensUpdated 6 mo ago
    SecurityAuto-check passed
  • Bom Audit

    cdxgen/cdxgen

    Runs supply-chain risk analysis on CycloneDX BOMs with cdx-audit predictive auditing and cdxgen --bom-audit embedded rules, covering npm and PyPI package compromise posture, CI permission risk…

    1.1k GitHub stars~2.4k tokensUpdated yesterday
    SecurityAuto-check passed
  • Vex Authoring

    relizaio/rearm

    Author CycloneDX-VEX or OpenVEX documents that import cleanly into ReARM.

    127 GitHub stars~2.9k tokensUpdated yesterday
    SecurityAuto-check passed

Categories

Questions about Packslip

What does Packslip do?

Configure signed release manifests with packslip: add the jdx/packslip action or packslip create to a release workflow, declare completions, man pages, CLI specs, skills, and SBOMs as resources, and…. Packslip is an agent skill from jdx/packslip. Configure signed release manifests with packslip: add the jdx/packslip action or packslip create to a release workflow, declare completions, man pages, CLI specs, skills, and SBOMs as resources, and verify bundles and downloaded artifacts.

When should I use Packslip?

Packslip fits situations like: A repository has; needs packslip.sigstore.json; A packslip release.toml; the jdx/packslip action.

How do I install Packslip in Claude Code?

Run `npx skills add jdx/packslip --skill packslip -a claude-code`. Or copy the skill folder (skills/packslip in jdx/packslip) into .claude/skills/packslip in your project. Claude Code loads it when a task matches its description.

How do I install Packslip in Codex?

Run `npx skills add jdx/packslip --skill packslip -a codex`. Or copy the skill folder (skills/packslip in jdx/packslip) into .agents/skills/packslip in your project. Codex loads it when a task matches its description.

Can I use Packslip in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add jdx/packslip --skill packslip -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/packslip, .gemini/skills/packslip, .github/skills/packslip and .opencode/skills/packslip in your project.

What does Packslip need to run?

Going by SKILL.md and its folder, Packslip needs the command-line tools its instructions call (git).

Does Packslip access the network?

SKILL.md names 3 domains. In commands or code: github.com and token.actions.githubusercontent.com; the agent is likely to contact these when it follows the instructions. As links in the text: packslip.dev. This is read from the text; nothing was executed.

Is Packslip safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Packslip use?

Packslip is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Packslip use?

About 2.9k tokens (SKILL.md is roughly 12k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Packslip?

Skills that share tags, products or a category with Packslip: Skill Scanner (getsentry/skills, 1k stars), Serenity Aleabitoreddit (yan-labs/serenity-aleabitoreddit, 481 stars), Eu Cra (Sushegaad/Claude-Skills-Governance-Risk-and-Compliance, 943 stars) and Kesekit Check (cdppcorp/KESE-KIT, 361 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Packslip?

jdx (a GitHub user) maintains it in jdx/packslip, which has 136 GitHub stars. The repository was last updated on October 9, 2026.

Source: jdx/packslip on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.