← ClaudeAtlas

supply-chainlisted

Block typosquats, unpinned dependencies, floating GitHub Actions tags, `curl | bash` installs, unverified agent skills/MCP servers, and post-install scripts from unknown publishers before they reach a developer machine, a CI runner, or a production image. Require lockfile-based installs, SHA-pinned third-party actions, registry-namespace verification, and provenance checks (Sigstore, npm provenance, GitHub attestations) for any code that will run.
catpilotai/catpilot-ai-guardrails · ★ 2 · AI & Automation · score 78
Install: claude install-skill catpilotai/catpilot-ai-guardrails
## Baseline **Applies when:** Adding a dependency to a manifest or running an install command, referencing a third-party CI action, building a `Dockerfile`/compose that pulls images or binaries, piping `curl`/`wget` output into a shell, or installing an agent skill, MCP server, or IDE extension. **Always:** - Install from a lockfile (`npm ci`, `pip install --require-hashes`, `poetry install --no-update`, `bundle install --frozen`, `cargo build --locked`), never a bare install that re-resolves. - Pin third-party CI references (actions, orbs, plugins, reusable workflows) to a full commit SHA, not a mutable tag. - Before adding a dependency, verify its spelling against the canonical upstream name, its publisher/namespace, its provenance/attestation, and its download/maintenance history. - Replace `curl | bash`-style pipe-to-shell installs with download, hash-verify, inspect, then run; prefer the project's package-manager distribution. - Review a package's install/build-hook scripts before installing; refuse ones that download external artifacts or touch `~/.ssh`, `~/.aws`, or similar credential paths. - Vet any third-party agent skill, MCP server, or IDE extension as code: read the source, check the permission scope, and reject obfuscated or "ClickFix" install instructions. **Never:** - `npm install`/`yarn add`/`pip install <pkg>` (unpinned, no lockfile) in CI. - A GitHub Actions third-party reference pinned to a tag or branch (`@main`, `@v1`) instead of a commit SHA. - Silen