Create or register a canvas extension in the awesome-copilot repository. Use when asked to scaffold a new canvas extension, create its plugin.json, add a reusable extension to one or more plugins, or migrate extension metadata. Extensions are reusable source under extensions/; shippable plugin manifests belong under plugins/.
agent-supply-chain
agent-supply-chain is an open-source integrations skill for Claude Code and compatible agents, published by github. Its author describes it as: “Verify supply chain integrity for AI agent plugins, tools, and dependencies. Use this skill when: - Generating SHA-256 integrity manifests for agent plugins or tool packages - Verifying that installed plugins match th…”. The project has 38k stars on GitHub and is available under the MIT license. Add it to your setup with `git clone https://github.com/github/awesome-copilot ~/.claude/skills/agent-supply-chain`.
What agent-supply-chain does
Generate and verify integrity manifests for AI agent plugins and tools. Detect tampering, enforce version pinning, and establish supply chain provenance.
Installation
Add agent-supply-chain to your agent with:
git clone https://github.com/github/awesome-copilot ~/.claude/skills/agent-supply-chain Always review a skill's source before installing it. This command comes from the skill's public repository; the linked repo is the source of truth for exact setup steps.
What's inside
The SKILL.md for agent-supply-chain is organised into these sections:
- Overview
- When to Use
- Pattern 1: Generate Integrity Manifest
- Pattern 2: Verify Integrity
- Pattern 3: Dependency Version Audit
- Pattern 4: Promotion Gate
- CI Integration
- Best Practices
- Related Resources
When to use it
Reach for agent-supply-chain when you want integrations help from your agent without writing the same instructions every session. Load the skill and the agent picks it up automatically for relevant tasks.
Strengths
- Clear MIT license — safe to read and adapt
- Ships in github/awesome-copilot, an established project with 37,982 GitHub stars
- Actively maintained (recent commits)
Topics
Frequently asked questions
- What does agent-supply-chain do?
- Verify supply chain integrity for AI agent plugins, tools, and dependencies. Use this skill when: - Generating SHA-256 integrity manifests for agent plugins or tool packages - Verifying that installed plugins match their published manifests - Detecting tampered, modified, or untracked files in agent tool directories - Auditing dependency pinning and version policies for agent components - Building provenance chains for agent plugin promotion (dev → staging → production) - Any request like "verify plugin integrity", "generate manifest", "check supply chain", or "sign this plugin"
- How do I install agent-supply-chain?
- Run git clone https://github.com/github/awesome-copilot ~/.claude/skills/agent-supply-chain in your agent, then reload your skills. Review the source at https://github.com/github/awesome-copilot before installing.
- Is agent-supply-chain free to use?
- Yes. agent-supply-chain is free and open source under the MIT license, so you can read, run, and adapt it within that license's terms.
- Where does agent-supply-chain come from?
- agent-supply-chain ships inside github/awesome-copilot, a repository that contains 41 catalogued skills in total. The repository's 37,982 GitHub stars apply to that whole collection, not to this skill on its own.
Related skills
More Integrations →Run the AgentRC readiness assessment on the current repository and produce a static HTML dashboard at reports/index.html. Wraps `npx github:microsoft/agentrc readiness` and hands off rendering to the @ai-readiness-reporter custom agent. Supports policies (--policy) for org-specific scoring. Use when asked to assess, audit, or score the AI readiness of a repo.
Generate tailored AI agent instruction files via AgentRC instructions command. Produces .github/copilot-instructions.md (default, recommended for Copilot in VS Code) plus optional per-area .instructions.md files with applyTo globs for monorepos. Use after running /acreadiness-assess to close gaps in the AI Tooling pillar.
Help the user pick, write, or apply an AgentRC policy. Policies customise readiness scoring by disabling irrelevant checks, overriding impact/level, setting pass-rate thresholds, or chaining org baselines with team overrides. Use when the user asks about strict mode, AI-only scoring, custom weights, CI gating, or wants org-wide standardisation.
Add educational comments to the file specified, or prompt asking for file to comment if one is not provided.