ai-supply-chain-securitylisted
Install: claude install-skill sebastienrousseau/agtmls
# AI Supply Chain Security
Use this skill to audit agentic supply-chain risk before shipping an AI-enabled repository or skill pack.
## Workflow
1. Identify generated artifacts, skills, prompts, tools, MCP servers, and provider adapters.
2. Check provenance: source commit, generator script, checksum, license, and owner.
3. Check package risk: dependency confusion, typosquatting, unsigned artifacts, unpinned install commands, and shell-pipe installers.
4. Check agent risk: prompt injection, MCP tool poisoning, unreviewed network access, file-write authority, and secret handling.
5. Require release evidence: `SBOM.spdx.json`, `provenance.json`, `SHA256SUMS`, and green `agtmls.py check`.
6. Report blocking issues before publishing or installing globally.
## Evidence
Record reviewed files, commands run, and residual risks in the evidence log when available.