agent-supply-chain

by github 38k MIT Updated Aug 18, 2026
agent-supply-chain skill by github
agent-supply-chain — Integrations skill by github

agent-supply-chain is an open-source integrations skill for Claude Code and compatible agents, published by github. Its author describes it as: “Verify supply chain integrity for AI agent plugins, tools, and dependencies. Use this skill when: - Generating SHA-256 integrity manifests for agent plugins or tool packages - Verifying that installed plugins match th…”. The project has 38k stars on GitHub and is available under the MIT license. Add it to your setup with `git clone https://github.com/github/awesome-copilot ~/.claude/skills/agent-supply-chain`.

What agent-supply-chain does

Generate and verify integrity manifests for AI agent plugins and tools. Detect tampering, enforce version pinning, and establish supply chain provenance.

Installation

Add agent-supply-chain to your agent with:

git clone https://github.com/github/awesome-copilot ~/.claude/skills/agent-supply-chain

Always review a skill's source before installing it. This command comes from the skill's public repository; the linked repo is the source of truth for exact setup steps.

What's inside

The SKILL.md for agent-supply-chain is organised into these sections:

  • Overview
  • When to Use
  • Pattern 1: Generate Integrity Manifest
  • Pattern 2: Verify Integrity
  • Pattern 3: Dependency Version Audit
  • Pattern 4: Promotion Gate
  • CI Integration
  • Best Practices
  • Related Resources

When to use it

Reach for agent-supply-chain when you want integrations help from your agent without writing the same instructions every session. Load the skill and the agent picks it up automatically for relevant tasks.

Strengths

  • Clear MIT license — safe to read and adapt
  • Ships in github/awesome-copilot, an established project with 37,982 GitHub stars
  • Actively maintained (recent commits)

Topics

agent-skillsagentsaiawesomecustom-agentsgithub-copilothacktoberfestprompt-engineering

Frequently asked questions

What does agent-supply-chain do?
Verify supply chain integrity for AI agent plugins, tools, and dependencies. Use this skill when: - Generating SHA-256 integrity manifests for agent plugins or tool packages - Verifying that installed plugins match their published manifests - Detecting tampered, modified, or untracked files in agent tool directories - Auditing dependency pinning and version policies for agent components - Building provenance chains for agent plugin promotion (dev → staging → production) - Any request like "verify plugin integrity", "generate manifest", "check supply chain", or "sign this plugin"
How do I install agent-supply-chain?
Run git clone https://github.com/github/awesome-copilot ~/.claude/skills/agent-supply-chain in your agent, then reload your skills. Review the source at https://github.com/github/awesome-copilot before installing.
Is agent-supply-chain free to use?
Yes. agent-supply-chain is free and open source under the MIT license, so you can read, run, and adapt it within that license's terms.
Where does agent-supply-chain come from?
agent-supply-chain ships inside github/awesome-copilot, a repository that contains 41 catalogued skills in total. The repository's 37,982 GitHub stars apply to that whole collection, not to this skill on its own.

Related skills

More Integrations →

Create or register a canvas extension in the awesome-copilot repository. Use when asked to scaffold a new canvas extension, create its plugin.json, add a reusable extension to one or more plugins, or migrate extension metadata. Extensions are reusable source under extensions/; shippable plugin manifests belong under plugins/.

38k github MIT

Run the AgentRC readiness assessment on the current repository and produce a static HTML dashboard at reports/index.html. Wraps `npx github:microsoft/agentrc readiness` and hands off rendering to the @ai-readiness-reporter custom agent. Supports policies (--policy) for org-specific scoring. Use when asked to assess, audit, or score the AI readiness of a repo.

38k github MIT

Generate tailored AI agent instruction files via AgentRC instructions command. Produces .github/copilot-instructions.md (default, recommended for Copilot in VS Code) plus optional per-area .instructions.md files with applyTo globs for monorepos. Use after running /acreadiness-assess to close gaps in the AI Tooling pillar.

38k github MIT

Help the user pick, write, or apply an AgentRC policy. Policies customise readiness scoring by disabling irrelevant checks, overriding impact/level, setting pass-rate thresholds, or chaining org baselines with team overrides. Use when the user asks about strict mode, AI-only scoring, custom weights, CI gating, or wants org-wide standardisation.

38k github MIT