supply-chainlisted
Install: claude install-skill catpilotai/catpilot-ai-guardrails
## Baseline
**Applies when:** Adding a dependency to a manifest or running an install command, referencing a third-party CI action, building a `Dockerfile`/compose that pulls images or binaries, piping `curl`/`wget` output into a shell, or installing an agent skill, MCP server, or IDE extension.
**Always:**
- Install from a lockfile (`npm ci`, `pip install --require-hashes`, `poetry install --no-update`, `bundle install --frozen`, `cargo build --locked`), never a bare install that re-resolves.
- Pin third-party CI references (actions, orbs, plugins, reusable workflows) to a full commit SHA, not a mutable tag.
- Before adding a dependency, verify its spelling against the canonical upstream name, its publisher/namespace, its provenance/attestation, and its download/maintenance history.
- Replace `curl | bash`-style pipe-to-shell installs with download, hash-verify, inspect, then run; prefer the project's package-manager distribution.
- Review a package's install/build-hook scripts before installing; refuse ones that download external artifacts or touch `~/.ssh`, `~/.aws`, or similar credential paths.
- Vet any third-party agent skill, MCP server, or IDE extension as code: read the source, check the permission scope, and reject obfuscated or "ClickFix" install instructions.
**Never:**
- `npm install`/`yarn add`/`pip install <pkg>` (unpinned, no lockfile) in CI.
- A GitHub Actions third-party reference pinned to a tag or branch (`@main`, `@v1`) instead of a commit SHA.
- Silen