Sbom Supply Chain
sickn33/agentic-awesome-skills
Generate, sign, and verify SBOMs and provenance attestations to secure the software supply chain.
Run OpenLoomi one-time setup — auto-chains install → set Codex provider → launch → wait API → mint guest session token → ready in one call.
$ npx skills add melandlabs/openloomi --skill openloomi-setup -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install melandlabs/openloomi openloomi-setup --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/melandlabs/openloomi.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/codex/skills/openloomi-setup .claude/skills/openloomi-setup && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "openloomi-setup" agent skill from https://github.com/melandlabs/openloomi/tree/main/plugins/codex/skills/openloomi-setup into .claude/skills/openloomi-setup/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "openloomi-setup", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/melandlabs/openloomi/tree/main/plugins/codex/skills/openloomi-setupType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add melandlabs/openloomi --skill openloomi-setup -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install melandlabs/openloomi openloomi-setup --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/melandlabs/openloomi.git skills-src && mkdir -p .agents/skills && cp -r skills-src/plugins/codex/skills/openloomi-setup .agents/skills/openloomi-setup && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "openloomi-setup" agent skill from https://github.com/melandlabs/openloomi/tree/main/plugins/codex/skills/openloomi-setup into .agents/skills/openloomi-setup/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "openloomi-setup", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add melandlabs/openloomi --skill openloomi-setup -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install melandlabs/openloomi openloomi-setup --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/melandlabs/openloomi.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/plugins/codex/skills/openloomi-setup .cursor/skills/openloomi-setup && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "openloomi-setup" agent skill from https://github.com/melandlabs/openloomi/tree/main/plugins/codex/skills/openloomi-setup into .cursor/skills/openloomi-setup/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "openloomi-setup", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/melandlabs/openloomi.git --path plugins/codex/skills/openloomi-setup--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add melandlabs/openloomi --skill openloomi-setup -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install melandlabs/openloomi openloomi-setup --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/melandlabs/openloomi.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/plugins/codex/skills/openloomi-setup .gemini/skills/openloomi-setup && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "openloomi-setup" agent skill from https://github.com/melandlabs/openloomi/tree/main/plugins/codex/skills/openloomi-setup into .gemini/skills/openloomi-setup/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "openloomi-setup", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install melandlabs/openloomi openloomi-setupInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add melandlabs/openloomi --skill openloomi-setup -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/melandlabs/openloomi.git skills-src && mkdir -p .github/skills && cp -r skills-src/plugins/codex/skills/openloomi-setup .github/skills/openloomi-setup && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "openloomi-setup" agent skill from https://github.com/melandlabs/openloomi/tree/main/plugins/codex/skills/openloomi-setup into .github/skills/openloomi-setup/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "openloomi-setup", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add melandlabs/openloomi --skill openloomi-setup -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install melandlabs/openloomi openloomi-setup --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/melandlabs/openloomi.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/plugins/codex/skills/openloomi-setup .opencode/skills/openloomi-setup && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "openloomi-setup" agent skill from https://github.com/melandlabs/openloomi/tree/main/plugins/codex/skills/openloomi-setup into .opencode/skills/openloomi-setup/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "openloomi-setup", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
openloomi-setupRun OpenLoomi one-time setup — auto-chains install → set Codex provider → launch → wait API → mint guest session token → ready in one call.
Openloomi Setup is an agent skill from melandlabs/openloomi. Run OpenLoomi one-time setup — auto-chains install → set Codex provider → launch → wait API → mint guest session token → ready in one call. Mirrors Claude's /openloomi:setup. Triggers: setup openloomi, install openloomi, install and run, 一键装好并跑起来, fix openloomi, finalize openloomi, installrequired, awaitinguseraction, sessioninitializationrequired, aiproviderrequired, installfailed, apinotready, what now, what next, first time, what can i do.
Its SKILL.md is about 5.1k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
The repository describes itself as: OpenLoomi is an open-source AI coworker. It connects your work tools, understands what you’re working on, and tells you what needs your attention, why it matters, and what to do… The licence is Apache-2.0.
5 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 2aca101. It shows what the files ask for, not the result of running them.
Pre-approves these tools, so the agent can use them without asking each time:
Bash(node $SKILL_DIR/../../scripts/loomi-bridge.mjs setup *)From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
nodecurlFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use curl, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Openloomi Setup loads about 5.1k tokens when it runs. Until then it costs about 119 tokens; SKILL.md has 1,996 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from melandlabs/openloomi at commit 2aca101, republished under its Apache-2.0 licence (© melandlabs). 1,996 words, ~5,110 tokens.
.claude/skills/openloomi-setup/SKILL.md (or your agent's skills folder).The bridge now exposes a single end-to-end wizard: setup --yes. One
invocation walks the full Codex state machine:
install OpenLoomi.app from the official GitHub release
→ set OPENLOOMI_AGENT_PROVIDER=codex in the GUI launchd / environment.d
(auto-restarts the desktop if it was already running)
→ launch the desktop app (`open -a <desktopMarker>` / platform equivalent)
→ wait for the local HTTP API to come up on http://localhost:3414
→ mint a guest bearer (one-tap sign-in) into ~/.openloomi/token
→ { ready: true }Each transition is automatic. Do not ask the user to click anything in the GUI. The bridge only surfaces a stop condition when the next step truly requires human action — e.g. AI provider not configured, or the native Codex runtime isn't reachable.
This wizard is the Codex-side equivalent of Claude's /openloomi:setup.
Both plugins speak the same bridge commands, the same flag names, and the
same stop-condition vocabulary so an install step that works on one works
on the other.
Make sure the Codex sandbox is set to a mode that allows the wizard
to actually run. setup needs to write to /Applications (macOS) or
~/.config/environment.d/ (Linux), install/launch the desktop helper,
and reach http://localhost:3414. workspace-write is the minimum
that usually works; danger-full-access is the safe choice for the
first run. If you do not have approval, ask the user before invoking
the bridge.
If the bridge returns setup: install_attempted (only happens on the
very first invocation when --yes is required), this is informational
— --yes is already passed through and the wizard proceeds.
Run:
node "$SKILL_DIR/../../scripts/loomi-bridge.mjs" setup --yes [--max-wait <ms>] [--api-timeout <ms>] [--install-timeout <ms>] [--launch-timeout <ms>] [--permission-timeout <ms>] [--bin-path <path>]Read the JSON. The bridge writes an audit trail of what it did into
steps[]. Surface that to the user so they can see which transitions
fired (status_check → install → runtime_env_write →
quit_for_env_reload (only when needed) → launch → wait_api →
guest_login).
If setup: ready → done.
If setup: awaiting_user_action → the chain hit a step that genuinely
needs the user (e.g. nextAction: install_openloomi because --yes
wasn't passed, nextAction: configure_ai_provider because no AI
provider is configured, or nextAction: open_openloomi because the
desktop process won't auto-launch). Explain what the user needs to do
and stop — do not auto-retry.
If setup: api_not_ready → show the bridge's hints[] and the
pre-built resumeCommand. Re-running the wizard is always safe; the
state machine is idempotent. Re-approval may be needed to leave the
sandbox.
All flags are also accepted by the bridge directly. Names + defaults are
identical to Claude's /openloomi:setup so the two plugins speak the same
dial language.
| Flag | Default | Meaning |
|---|---|---|
--yes | off | Pre-approve install. Without it, the bridge stops at INSTALL_CONFIRMATION_REQUIRED because Codex can't presume consent. With it, the chain runs end-to-end. |
--max-wait | 120000 | Global cap (ms) across the wait stages. Defaults to 120 s to absorb the first-run install + TCC prompts. |
--api-timeout | 120000 | Per-stage budget for "waiting for local API". Independent of --max-wait. |
--install-timeout | 300000 | Per-stage budget for "installing OpenLoomi". Covers download + copy on a 50 Mbps link. |
--launch-timeout | 10000 | Per-stage budget for open -a <bundle> (and platform equivalents). Almost never actually hit; included for parity with the Claude side. |
--permission-timeout | 60000 | Extra grace wait after --api-timeout when the desktop process is up but the API never woke up — only fires when the bridge can confirm the process is alive. |
--bin-path | auto | Explicit path to the OpenLoomi desktop bundle (e.g. /Applications/OpenLoomi.app). Mirrors Claude's flag and overrides the usual discovery order. |
While the wizard is inside a long stage, the bridge writes a throttled 1 Hz line to stderr so the user can see progress:
· installing OpenLoomi (12s / max 5m) …
· waiting for local API (4s / max 2m) …
· waiting on macOS permission prompt (3s / max 1m) …Stdout is reserved for the final JSON result — do not mix it.
api_not_ready payloadWhen --api-timeout (+ --permission-timeout grace) elapses, the wizard
returns an actionable JSON payload you can use to drive chat-side
guidance. The original setup: "api_not_ready" shape is preserved for
backwards compatibility; new fields are added alongside it.
| Field | Type | Meaning |
|---|---|---|
ok | bool | Always false for this stop condition. |
setup | string | Always "api_not_ready" here. |
code | string | Stable machine code: "API_NOT_READY" or "PERMISSION_PROMPT_LIKELY" (when desktop process is up but API is not). |
stage | string | Always "wait_api". Reserved for future per-stage error codes. |
elapsedMs | number | Wall-clock time since setup --yes started. |
effectiveBudgetMs | number | Total wait budget actually granted (api + permission grace). |
canResume | bool | Always true. Re-running the wizard is the supported "keep waiting" action. |
resumeCommand | string | A pre-built command the user can paste — already uses a sensible raised --max-wait. |
hints | string[] | 1–3 hints, safe to print verbatim. Includes the macOS TCC prompt hint on Darwin. |
overCap | bool | true if the elapsed time exceeded the global --max-wait cap (informational). |
steps | Step[] | The existing audit trail. |
wait | object | The raw waitForApi payload (code, elapsedMs, attempted, lastError, optional graceWait). |
status | object | The latest setup-status snapshot. |
setup | When it fires |
|---|---|
ready | All transitions completed. The desktop app is running, the API is reachable, the guest session token is minted, and the native Codex provider is the active agent. Surface mode, version, and executionProviderSource from status. |
awaiting_user_action | A transition that needs the user ran without a programmatic path. Most commonly: nextAction: install_openloomi because --yes wasn't passed, nextAction: configure_ai_provider because no provider is configured, nextAction: open_openloomi because the desktop process didn't wake, or nextAction: inspect_codex_runtime because the native Codex agent is not active. Walk the user through what they need to do and stop. |
install_attempted | (Informational.) The first setup invocation in a fresh environment must install before it can confirm READY. --yes already authorised the install; treat this as a normal await. |
install_failed | The platform install script exited non-zero (or hit --install-timeout). Show install.code / install.message. |
runtime_env_failed | The set-codex-runtime-env step failed (rare; usually a TCC prompt on macOS, or a write-permission error on Linux). Follow runtimeEnv.message. |
quit_for_env_reload_failed | The desktop app was running, the env var was written, but quitDesktopApp couldn't bring it down (TCC prompt blocking the kill). The only stop condition that truly needs the user to Quit+Reopen by hand. Surface quit.message. |
launch_failed | open -a <desktopMarker> (or platform equivalent) returned a non-zero exit. On macOS this almost never happens for a signed .app; if it does, fall back to manual launch instructions. |
api_not_ready | The desktop app was launched but the local HTTP API didn't respond within --api-timeout. The bridge only adds --permission-timeout grace when it can confirm the desktop process is alive. code distinguishes network/slow (API_NOT_READY) vs TCC prompt (PERMISSION_PROMPT_LIKELY); hints[] and resumeCommand are pre-built; canResume: true makes re-running the wizard the recommended action. |
guest_login_failed | API is up but the one-tap guest login was rejected by /api/auth/guest. Show session.code / session.error. The user can sign in via the GUI and re-run setup. |
step_limit_reached | Hit the internal step ceiling without reaching READY (default 8 transitions). Almost certainly a state-machine bug; show steps[]. |
The bridge's stdout output is authoritative. Never invoke the platform
install script (setup.{macos,linux,windows}.*) directly — only the
bridge may run it, and only after explicit user consent (which is what
--yes records).
Before any launch, the bridge writes OPENLOOMI_AGENT_PROVIDER=codex so
the freshly-started desktop server picks up the Codex runtime. On macOS
this is done via launchctl setenv plus a LaunchAgent so the variable
survives reboot; on Linux the bridge edits ~/.config/environment.d/; on
Windows the user must set the variable manually. codex-runtime-info
always reports the current effective value.
ready walkthroughWhen setup: ready fires, the wizard is done. Print the canonical
post-setup hand-off so the user knows what they just installed and what
to try next. The bridge JSON above is for machines; this section is the
human-facing surface and supersedes the earlier "do not improvise" rule
with a richer, scripted intro + tour. Print all four parts on the very
first setup: ready emission. On later re-runs you may abbreviate to
the audit table plus "where to go next" line, but never skip the intro.
OpenLoomi is your open-source, local-first AI partner, built to protect your attention. It runs as a desktop app on your Mac, connects to the tools you authorise (Gmail, Slack, GitHub, Google Calendar, Notion, Linear, etc. via Composio, plus native bots for Telegram / WhatsApp / iMessage / Feishu / DingTalk / QQ / WeChat), watches the signals that come in, and surfaces daily decisions as cards on the desktop pet (Loomi the fox). You tap Approve and the action runs through the same connector — the result is written back into Memory so the next judgement is sharper. Nothing leaves your machine unless you opt in to a Connector.
| Surface | Where |
|---|---|
| Desktop app | /Applications/OpenLoomi.app |
| Local HTTP API | http://localhost:3414 (fallback 3515) |
| Guest bearer token | ~/.openloomi/token (base64-encoded JWT) |
| Codex runtime env | OPENLOOMI_AGENT_PROVIDER=codex (LaunchAgent, survives reboot) |
| Memory files | ~/.openloomi/data/memory/{people,projects,notes,strategy,chats,channels}/ |
| Knowledge Base | GET /api/rag/documents |
| Audit log | GET /api/audit/... |
| Pet widget | Watcher polls ~/.openloomi/loop/decisions.json every 2s |
After setup: ready, suggest this exact sequence. Each step is a
single shell call plus a one-line description of what the user will
see. Skip steps the user has already done — but always emit step 1
(health check) so the user knows what "still ready" looks like.
| # | What | Command | What you'll see |
|---|---|---|---|
| 1 | Health check | node "$PLUGIN/scripts/loomi-bridge.mjs" setup-status | Same audit table you just got. Confirms Codex runtime is still the active default agent. |
| 2 | Pet reacts | node "$PLUGIN/scripts/loomi-bridge.mjs" pet happy | Loomi the fox flips to the happy sprite. Try thinking, working, juggling to see the rest of the 9-state set. |
| 3 | Connect a tool | Native: node "$PLUGIN/skills/openloomi-connectors/scripts/openloomi-connectors.cjs" connect telegram or OAuth: composio link gmail | A QR scan or browser OAuth opens; once you approve, the account shows in list-accounts. |
| 4 | Run one Loop tick | TOKEN=$(cat ~/.openloomi/token | base64 -d); curl -X POST http://localhost:3414/api/loop/tick -H "Authorization: Bearer $TOKEN" | Loop pulls signals, classifies them, and enqueues decisions. Then GET /api/loop/decisions?status=pending to see the cards. Approve with POST /api/loop/action/schedule. |
| 5 | Seed Memory | node "$PLUGIN/skills/openloomi-memory/scripts/openloomi-memory.cjs" add-memory "About me: ..." --file=tour/about-me.md | A tour-owned .md shows up in ~/.openloomi/data/memory/tour/. Future Loop ticks have grounding context without overwriting user memory. |
Optional extensions after step 4 (skip if the user is new):
PUT /api/loop/channels with toolkit + toolSlug).PUT /api/loop/classifier-rules).DecisionType icon + label
(PUT /api/loop/types).If the user asks for a hands-on walkthrough rather than just a
recommendation, hand off to the openloomi-tour skill — it runs the
same five steps with live probes and stops between each one for the
user to react.
End with this closed list so the user doesn't have to memorise URLs.
| Want to… | Run |
|---|---|
| See health | setup-status |
| Flip the pet | pet <state> |
| Re-confirm Codex runtime | codex-runtime-info |
| List connectors | openloomi-connectors list-accounts |
| Search memory | openloomi-memory search-all "<query>" |
| Run a Loop tick | POST /api/loop/tick |
| See pending decisions | GET /api/loop/decisions?status=pending |
| Approve a decision | POST /api/loop/action/schedule {decision_id, action:"run"} |
| Archive old data | archive |
Finish with: "Run openloomi-tour from this Codex session for a
guided walkthrough, or pick a number above and I'll run that step for
you."
api_not_readyWhen the wizard times out waiting for the API, the recommended chat-side flow is:
hints[] verbatim. Each is safe-to-print.canResume: true (always the case for api_not_ready), suggest
the user simply re-runs the wizard. The state machine is idempotent —
already-completed steps (e.g. install, env write) will be skipped
immediately, and the wizard will land back inside wait_api.resumeCommand (e.g. node <plugin>/scripts/loomi-bridge.mjs setup --yes --max-wait 180000) rather than asking them to invent the flag.| Follow-up | Bridge command | When to suggest |
|---|---|---|
| Status snapshot | setup-status | User asks "is everything wired up?" — read-only snapshot. |
| Pet state | pet happy / pet normal / etc. | User asks about the Pet widget or wants to flip its state manually. |
| Code runtime env | codex-runtime-info | User asks whether the desktop app is wired to Codex. |
| Install-only | install-openloomi --confirm | User asks to install without launching (rare; mostly CI / VDI). |
The setup wizard must be run outside the Codex sandbox (or with
danger-full-access) — it needs to write to system application
directories (/Applications on macOS, ~/.config/environment.d/ on
Linux), launch a signed GUI helper, and reach the local HTTP API at
http://localhost:3414. None of those survive read-only or default
workspace-write mode in a fresh environment. If you are still inside a
sandbox when the user asks for setup, request approval and re-run
outside the sandbox before invoking the bridge. The bridge surfaces a
sandbox-y reason in awaiting_user_action, launch_failed, or
api_not_ready; the hints[] payload calls out the next concrete step
(approve the request and retry).
© melandlabs, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in plugins/codex/skills/openloomi-setup of melandlabs/openloomi.
Open the folder on GitHubat commit 2aca101
Openloomi Setup next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Openloomi Setup this skillmelandlabs/openloomi | 1k | — | ~5.1k | Automated safety check: Pass | Apache-2.0 | |
| Sbom Supply Chainsickn33/agentic-awesome-skills | 47k | 2 repos | ~3.4k | Automated safety check: Pass | MIT | |
| Agent Supply Chaingithub/awesome-copilot | 40k | 1 repos | ~2.7k | Automated safety check: Pass | MIT | |
| Supply Chain Securityzhaoxuya520/reverse-skill | 40k | 4 repos | ~953 | Automated safety check: Warn | MIT | |
| Canonical Chainthedaviddias/Front-End-Checklist | 74k | — | ~417 | Automated safety check: Pass | MIT | |
| Implementing Supply Chain Security With In Totomukul975/Anthropic-Cybersecurity-Skills | 34k | — | ~2.5k | Automated safety check: Pass | Apache-2.0 |
sickn33/agentic-awesome-skills
Generate, sign, and verify SBOMs and provenance attestations to secure the software supply chain.
github/awesome-copilot
Verify supply chain integrity for AI agent plugins, tools, and dependencies.
zhaoxuya520/reverse-skill
A skill your agent uses for software supply-chain security assessment covering SBOM, SCA, CI/CD pipelines, container images, build integrity, dependency provenance, and vulnerability reachability.
thedaviddias/Front-End-Checklist
A skill your agent uses when auditing metadata, crawlability, structured data, or indexability related to Avoid redirect chains on canonical URLs.
mukul975/Anthropic-Cybersecurity-Skills
Implements supply chain integrity verification for container builds with the in-toto framework: generating signing keys, defining a supply chain layout, recording pipeline steps as signed link…
davila7/claude-code-templates
Detect and remediate software supply chain attacks in npm, PyPI, crates.io, GitHub Actions, and CI/CD pipelines by scanning for known compromised packages, malicious versions, filesystem IOCs, C2…
melandlabs/openloomi
openloomi Connectors tools - manage the native 7 messaging integrations and pair with the composio skill for the 1000+ apps OAuth layer (Slack, Discord, X, Gmail, Outlook, Google…
melandlabs/openloomi
Create an end-to-end Continual Learning Bench task. An agent skill from melandlabs/openloomi.
melandlabs/openloomi
openloomi Memory tools - search and manage the holistic context (people, projects, decisions, knowledge base, chat insights).
melandlabs/openloomi
OpenLoomi first-use setup and readiness guidance for skill-only agent runtimes.
melandlabs/openloomi
Discover and install skills from the open agent skills ecosystem.
melandlabs/openloomi
OpenLoomi runtime integration for Claude Code. An agent skill from melandlabs/openloomi.
Run OpenLoomi one-time setup — auto-chains install → set Codex provider → launch → wait API → mint guest session token → ready in one call. Openloomi Setup is an agent skill from melandlabs/openloomi. Run OpenLoomi one-time setup — auto-chains install → set Codex provider → launch → wait API → mint guest session token → ready in one call.
Run `npx skills add melandlabs/openloomi --skill openloomi-setup -a claude-code`. Or copy the skill folder (plugins/codex/skills/openloomi-setup in melandlabs/openloomi) into .claude/skills/openloomi-setup in your project. Claude Code loads it when a task matches its description.
Run `npx skills add melandlabs/openloomi --skill openloomi-setup -a codex`. Or copy the skill folder (plugins/codex/skills/openloomi-setup in melandlabs/openloomi) into .agents/skills/openloomi-setup in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add melandlabs/openloomi --skill openloomi-setup -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/openloomi-setup, .gemini/skills/openloomi-setup, .github/skills/openloomi-setup and .opencode/skills/openloomi-setup in your project.
Going by SKILL.md and its folder, Openloomi Setup needs the command-line tools its instructions call (node and curl). Its frontmatter pre-approves these tools: Bash(node $SKILL_DIR/../../scripts/loomi-bridge.mjs setup *).
SKILL.md contains no URLs. Its commands use curl, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Openloomi Setup is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 5.1k tokens (SKILL.md is roughly 20k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Openloomi Setup: Sbom Supply Chain (sickn33/agentic-awesome-skills, 47k stars), Agent Supply Chain (github/awesome-copilot, 40k stars), Supply Chain Security (zhaoxuya520/reverse-skill, 40k stars) and Canonical Chain (thedaviddias/Front-End-Checklist, 74k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
melandlabs (a GitHub organization) maintains it in melandlabs/openloomi, which has 1,037 GitHub stars. The repository holds 23 skills in this directory. The repository was last updated on September 24, 2026.
Source: melandlabs/openloomi on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.