GitHub Actions Supply Chain Pinning
asyncapi/generator
A skill your agent uses when editing, adding, or reviewing any file under .github/workflows/, or when a CI step installs a CLI tool (npm i -g, npx, pipx, uses: /setup-).
Step-by-step cookbook for setting up cryptographically signed audit trails on Claude Code tool calls.
$ npx skills add wshobson/agents --skill signed-audit-trails-recipe -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install wshobson/agents signed-audit-trails-recipe --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/wshobson/agents.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/signed-audit-trails/skills/signed-audit-trails-recipe .claude/skills/signed-audit-trails-recipe && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "signed-audit-trails-recipe" agent skill from https://github.com/wshobson/agents/tree/main/plugins/signed-audit-trails/skills/signed-audit-trails-recipe into .claude/skills/signed-audit-trails-recipe/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "signed-audit-trails-recipe", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/wshobson/agents/tree/main/plugins/signed-audit-trails/skills/signed-audit-trails-recipeType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add wshobson/agents --skill signed-audit-trails-recipe -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install wshobson/agents signed-audit-trails-recipe --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/wshobson/agents.git skills-src && mkdir -p .agents/skills && cp -r skills-src/plugins/signed-audit-trails/skills/signed-audit-trails-recipe .agents/skills/signed-audit-trails-recipe && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "signed-audit-trails-recipe" agent skill from https://github.com/wshobson/agents/tree/main/plugins/signed-audit-trails/skills/signed-audit-trails-recipe into .agents/skills/signed-audit-trails-recipe/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "signed-audit-trails-recipe", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add wshobson/agents --skill signed-audit-trails-recipe -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install wshobson/agents signed-audit-trails-recipe --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/wshobson/agents.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/plugins/signed-audit-trails/skills/signed-audit-trails-recipe .cursor/skills/signed-audit-trails-recipe && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "signed-audit-trails-recipe" agent skill from https://github.com/wshobson/agents/tree/main/plugins/signed-audit-trails/skills/signed-audit-trails-recipe into .cursor/skills/signed-audit-trails-recipe/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "signed-audit-trails-recipe", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/wshobson/agents.git --path plugins/signed-audit-trails/skills/signed-audit-trails-recipe--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add wshobson/agents --skill signed-audit-trails-recipe -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install wshobson/agents signed-audit-trails-recipe --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/wshobson/agents.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/plugins/signed-audit-trails/skills/signed-audit-trails-recipe .gemini/skills/signed-audit-trails-recipe && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "signed-audit-trails-recipe" agent skill from https://github.com/wshobson/agents/tree/main/plugins/signed-audit-trails/skills/signed-audit-trails-recipe into .gemini/skills/signed-audit-trails-recipe/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "signed-audit-trails-recipe", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install wshobson/agents signed-audit-trails-recipeInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add wshobson/agents --skill signed-audit-trails-recipe -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/wshobson/agents.git skills-src && mkdir -p .github/skills && cp -r skills-src/plugins/signed-audit-trails/skills/signed-audit-trails-recipe .github/skills/signed-audit-trails-recipe && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "signed-audit-trails-recipe" agent skill from https://github.com/wshobson/agents/tree/main/plugins/signed-audit-trails/skills/signed-audit-trails-recipe into .github/skills/signed-audit-trails-recipe/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "signed-audit-trails-recipe", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add wshobson/agents --skill signed-audit-trails-recipe -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install wshobson/agents signed-audit-trails-recipe --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/wshobson/agents.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/plugins/signed-audit-trails/skills/signed-audit-trails-recipe .opencode/skills/signed-audit-trails-recipe && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "signed-audit-trails-recipe" agent skill from https://github.com/wshobson/agents/tree/main/plugins/signed-audit-trails/skills/signed-audit-trails-recipe into .opencode/skills/signed-audit-trails-recipe/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "signed-audit-trails-recipe", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
signed-audit-trails-recipeStep-by-step cookbook for setting up cryptographically signed audit trails on Claude Code tool calls.
Signed Audit Trails Recipe is an agent skill from wshobson/agents. Step-by-step cookbook for setting up cryptographically signed audit trails on Claude Code tool calls. Use when explaining, evaluating, or demonstrating the pattern before committing to the protect-mcp runtime hooks. Covers Cedar policy, Ed25519 receipts, offline verification, tamper detection, CI/CD integration, and SLSA composition.
Its SKILL.md is about 2.5k tokens, which your agent loads only when the skill is triggered. The skill folder holds 5 other files, including reference files (for example `references/cedar-policy.md`, `references/ci-cd.md` and `references/hook-wiring.md`).
It sits in DevOps & Cloud, covering Supply chain security and CI/CD. It works with Model Context Protocol. The repository describes itself as: Multi-harness agentic plugin marketplace for Claude Code, Codex, Cursor, OpenCode, GitHub Copilot, Google Antigravity, and Pi. The licence is MIT.
6 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 46891e7. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
npxnpmpython3nodeFrom the folder's file list and the shell code blocks in SKILL.md.
Hosts in commands or code, which the agent is likely to contact:
veritasacta.comAlso links to:
github.comdatatracker.ietf.orgnpmjs.comrefs.arewm.compypi.orgdocs.cedarpolicy.comFrom URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Signed Audit Trails Recipe loads about 2.5k tokens when it runs, and up to ~4.7k if it reads all its reference files. Until then it costs about 91 tokens; SKILL.md has 1,003 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from wshobson/agents at commit 46891e7, republished under its MIT licence (© wshobson). 1,003 words, ~2,518 tokens.
.claude/skills/signed-audit-trails-recipe/SKILL.md (or your agent's skills folder). This skill also uses 4 other files; get the full folder from GitHub.Cookbook-style walkthrough for cryptographically signed receipts on every
Claude Code tool call. This is the teaching skill. For the runtime
implementation, install the protect-mcp plugin.
Every tool call (Bash, Edit, Write, WebFetch) is:
An auditor, regulator, or counterparty can verify every receipt later (Step 5). No network call, no vendor lookup, no trust in the operator.
Install the protect-mcp plugin with /plugin install protect-mcp. Its hooks
run evaluate.sh before each tool call and sign.sh after it. Both scripts
read the hook event from stdin, because Claude Code sets no TOOL_NAME or
TOOL_INPUT variables. See
references/hook-wiring.md for the hook
configuration and what each script passes to protect-mcp.
protect-mcp 0.7.4 does not create the signing key, and without a key the
receipts are unsigned. Create ./protect-mcp.key once. The command never
replaces an existing key:
if [ ! -e ./protect-mcp.key ]; then
d=$(mktemp -d) && npx protect-mcp@0.7.4 init --dir "$d" && mv "$d/keys/gateway.json" ./protect-mcp.key
fiGive auditors the publicKey value from that file. Do not commit the file,
because it also holds the private key.
Add the private key and receipt directory to .gitignore:
echo "/protect-mcp.key" >> .gitignore
echo "/receipts/" >> .gitignoreCreate ./protect.cedar from the example in
references/cedar-policy.md. It allows read-only
tools and a short list of Bash commands, denies shell chaining and destructive
commands, and limits writes to the project with .. segments denied.
Start Claude Code. Every tool call goes through both hooks:
You: Please read the README and summarize it.
Claude: I will read README.md.
[PreToolUse: Read ./README.md -> allow]
[Tool: Read executes]
[PostToolUse: receipt rcpt-a8f3c9d2 signed to ./receipts/]
... summary of README ...A session of 20 tool calls appends 20 receipts to ./receipts/receipts.jsonl.
protect-mcp 0.7.4 appends each receipt as one line of
./receipts/receipts.jsonl. Print the newest one:
tail -n 1 ./receipts/receipts.jsonl | python3 -m json.toolThe receipt is a signed v2 envelope that names the tool, and it holds no
public key. See references/receipt-format.md
for a sample and the signed fields.
Pass the publicKey value from ./protect-mcp.key to the verifier:
PUB=$(node -p 'JSON.parse(require("fs").readFileSync("./protect-mcp.key")).publicKey')
npx @veritasacta/verify@0.9.2 --replay-chain ./receipts/receipts.jsonl --key "$PUB"Exit codes:
| Code | Meaning |
|---|---|
0 | Every receipt verified |
1 | A receipt failed verification (tampered, wrong key, or malformed line) |
2 | The receipts file could not be read |
Change the newest receipt's decision from allow to deny:
python3 -c "
import json
path = './receipts/receipts.jsonl'
lines = open(path).read().splitlines()
r = json.loads(lines[-1])
r['payload']['decision'] = 'deny'
lines[-1] = json.dumps(r)
open(path, 'w').write('\n'.join(lines) + '\n')
"
npx @veritasacta/verify@0.9.2 --replay-chain ./receipts/receipts.jsonl --key "$PUB"The verifier exits with code 1 and reports which line failed. The
Ed25519 signature no longer matches the JCS-canonical bytes of the
tampered payload.
Restore the field and verification passes again.
Two invariants make receipts verifiable offline across any conformant implementation:
protect-mcp 0.7.4 receipts carry no link to the previous receipt, so a deleted receipt goes undetected.
For the formal wire format see draft-farley-acta-signed-receipts.
The receipt format has four independent implementations today:
| Implementation | Language | Use case |
|---|---|---|
| protect-mcp | TypeScript | Claude Code, Cursor, MCP hosts |
| protect-mcp-adk | Python | Google Agent Development Kit |
| sb-runtime | Rust | OS-level sandbox (Landlock + seccomp) |
| APS governance hook | Python | CrewAI, LangChain |
A receipt produced by any of them verifies against
@veritasacta/verify.
The auditor does not need to trust the operator's tooling choice: the format
is the contract.
Verify receipts in CI so a tampered receipt fails the build.
references/ci-cd.md has a GitHub Actions workflow
that runs on pushes to the default branch. It installs the signing key from a
branch-limited environment, runs the agent, verifies the receipts, and uploads
them. It does not run on pull requests, because that would hand the key to
unreviewed code.
When Claude Code builds and releases software (running npm install,
npm build, npm publish as tool calls), the receipt chain is the
per-step build log. SLSA Provenance v1 has an extension point for this: the
byproducts field can reference the receipt chain alongside the build
attestation.
The agent-commit build type documents the pattern using the ResourceDescriptor shape:
{
"name": "decision-receipts",
"digest": { "sha256": "..." },
"uri": "oci://registry/org/build-xyz/receipts:sha256-...",
"annotations": {
"predicateType": "https://veritasacta.com/attestation/decision-receipt/v0.1",
"signerRole": "supervisor-hook"
}
}The SLSA provenance is signed by the builder identity; the receipt attestation is signed by the supervisor-hook identity. Two trust domains, cross-referenced at the byproduct layer. See slsa-framework/slsa#1594 for the composition discussion.
Private key in version control. The generated ./protect-mcp.key must
not be committed. The examples above add it to .gitignore. If a key is
accidentally committed, rotate it immediately. Move the key and
./receipts/receipts.jsonl to an archive, then run the Step 1 command again.
Verify the archived receipts with the old public key.
Hook payload on stdin. Claude Code sets no $TOOL_NAME or $TOOL_INPUT
variables. A hook command that passes --tool "$TOOL_NAME" sends an empty
tool name, so the policy denies every call. Read the payload from stdin as the
plugin scripts do.
Receipts directory in CI. If Claude Code runs in CI, upload receipts as an artifact at the end of the job or the receipts are lost at job end.
Policy is missing. When ./protect.cedar does not exist, evaluate.sh
prints a warning to stderr and allows the call. No call is gated until you
create the policy in Step 2.
protect-mcp — the runtime hook implementation
(use this plugin in production)review-agent-governance — require
human approval before review-surface actions; composes with protect-mcpdraft-farley-acta-signed-receipts — IETF draft, receipt wire formatexamples/protect-mcp-governed/)© wshobson, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 4 other files (references) in plugins/signed-audit-trails/skills/signed-audit-trails-recipe of wshobson/agents.
Open the folder on GitHubat commit 46891e7
Signed Audit Trails Recipe next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Signed Audit Trails Recipe this skillwshobson/agents | 40k | — | ~2.5k | Automated safety check: Pass | MIT | |
| GitHub Actions Supply Chain Pinningasyncapi/generator | 1.1k | — | ~1.9k | Automated safety check: Pass | Apache-2.0 | |
| Vibe CI Supply Chainmistralai/mistral-vibe | 5.1k | — | ~1k | Automated safety check: Pass | Apache-2.0 | |
| CI/CD Pipeline Principlesirahardianto/awesome-agv | 156 | — | ~2.7k | Automated safety check: Notes | MIT | |
| Atmos CIcloudposse/atmos | 1.4k | — | ~4.7k | Automated safety check: Pass | Apache-2.0 | |
| Detecting Supply Chain Attacks In CI CDmukul975/Anthropic-Cybersecurity-Skills | 34k | — | ~655 | Automated safety check: Pass | Apache-2.0 |
asyncapi/generator
A skill your agent uses when editing, adding, or reviewing any file under .github/workflows/, or when a CI step installs a CLI tool (npm i -g, npx, pipx, uses: /setup-).
mistralai/mistral-vibe
Git workflow, CI/GitHub Actions, and supply-chain pinning rules for Mistral Vibe.
irahardianto/awesome-agv
Rules for designing CI/CD pipelines in layers: universal lint, test and scan stages, container builds with SBOM attestation, and GitOps for orchestrated deployments.
cloudposse/atmos
Atmos CI: Native CI with GitHub Actions containers, native outputs, SBOM workflow-artifact publication, collapsible log groups, affected/all matrix workflows, OIDC profiles, toolchain-aware jobs…
mukul975/Anthropic-Cybersecurity-Skills
Scans GitHub Actions workflows and CI/CD pipeline configurations for supply chain attack vectors including unpinned actions, script injection via expressions, dependency confusion, and secrets…
davila7/claude-code-templates
Detect and remediate software supply chain attacks in npm, PyPI, crates.io, GitHub Actions, and CI/CD pipelines by scanning for known compromised packages, malicious versions, filesystem IOCs, C2…
wshobson/agents
Cuts cloud spend across AWS, Azure, GCP and OCI with cost tagging, rightsizing, commitment and spot pricing models, and architecture changes.
wshobson/agents
Covers building subscription billing: billing cycles, subscription states, invoice generation, proration, tax handling and dunning for failed payments.
wshobson/agents
Profiles slow Python code with cProfile and memory profilers, then applies targeted fixes for CPU, memory, I/O and query bottlenecks.
wshobson/agents
Writes unit tests for shell scripts with Bats: error-condition tests, fixtures and mocks, cross-shell checks, parallel runs, helper files and CI integration.
wshobson/agents
Implement distributed tracing with Jaeger and Tempo to track requests across microservices and identify performance bottlenecks.
wshobson/agents
Reference for designing and tuning production LLM prompts: few-shot examples, chain-of-thought, structured outputs, templates and system prompts.
Works with
Categories
Step-by-step cookbook for setting up cryptographically signed audit trails on Claude Code tool calls. Signed Audit Trails Recipe is an agent skill from wshobson/agents. Step-by-step cookbook for setting up cryptographically signed audit trails on Claude Code tool calls.
Signed Audit Trails Recipe fits situations like: demonstrating the pattern before committing to the protect-mcp runtime hooks; tasks that involve Supply chain security; tasks that involve CI/CD.
Run `npx skills add wshobson/agents --skill signed-audit-trails-recipe -a claude-code`. Or copy the skill folder (plugins/signed-audit-trails/skills/signed-audit-trails-recipe in wshobson/agents) into .claude/skills/signed-audit-trails-recipe in your project. Claude Code loads it when a task matches its description.
Run `npx skills add wshobson/agents --skill signed-audit-trails-recipe -a codex`. Or copy the skill folder (plugins/signed-audit-trails/skills/signed-audit-trails-recipe in wshobson/agents) into .agents/skills/signed-audit-trails-recipe in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add wshobson/agents --skill signed-audit-trails-recipe -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/signed-audit-trails-recipe, .gemini/skills/signed-audit-trails-recipe, .github/skills/signed-audit-trails-recipe and .opencode/skills/signed-audit-trails-recipe in your project.
Going by SKILL.md and its folder, Signed Audit Trails Recipe needs the command-line tools its instructions call (npx, npm, python3 and node). Our summary lists: Python 3; Node.js.
SKILL.md names 7 domains. In commands or code: veritasacta.com; the agent is likely to contact it when it follows the instructions. As links in the text: github.com, datatracker.ietf.org, npmjs.com, refs.arewm.com, pypi.org and docs.cedarpolicy.com. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Signed Audit Trails Recipe is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 2.5k tokens (SKILL.md is roughly 10k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 2.2k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Signed Audit Trails Recipe: GitHub Actions Supply Chain Pinning (asyncapi/generator, 1.1k stars), Vibe CI Supply Chain (mistralai/mistral-vibe, 5.1k stars), CI/CD Pipeline Principles (irahardianto/awesome-agv, 156 stars) and Atmos CI (cloudposse/atmos, 1.4k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
wshobson (a GitHub user) maintains it in wshobson/agents, which has 40,314 GitHub stars. The repository holds 142 skills in this directory. The repository was last updated on October 5, 2026.
Source: wshobson/agents on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.