Skip to content
Back to skills

Quickstart

CSecurity

Use this skill when the user wants to manage software supply chain attestations — sign artifacts, record build provenance, verify SLSA compliance, or integrate attestation into CI/CD pipelines.

  • 54 stars
  • 0 votes
  • 0 copies
  • 0 views
  • Added September 6, 2026
devopsbashdockergitci/cd

Works with

  • cli

Security analysis

C71/100
  • criticalPipes output to a shell interpreter
  • mediumUses curl or wget to download content
  • criticalDownloads and executes remote scripts — classic supply chain attack

Pro shows the line behind each finding and how to fix it

Scanned September 6, 2026

npx -y skills add javimosch/supercli --skill quickstart --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Quickstart?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Quickstart
[![Security: C — Skills Directory](https://www.skillsdirectory.com/api/skills/javimosch-quickstart-5a158e72/badge)](https://www.skillsdirectory.com/skills/javimosch-quickstart-5a158e72)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: chainloop
description: Use this skill when the user wants to manage software supply chain attestations — sign artifacts, record build provenance, verify SLSA compliance, or integrate attestation into CI/CD pipelines.
---

# chainloop Plugin

Software supply chain attestation and metadata framework. Record artifact integrity, build provenance, and compliance evidence for SLSA and related standards.

## Installation

```bash
curl -sSL https://raw.githubusercontent.com/chainloop-dev/chainloop/main/install.sh | sh
```

## Basic Usage

```bash
# Check CLI version
chainloop version

# Authenticate with a Chainloop server
chainloop auth login

# Initialize an attestation for a workflow
chainloop attestation init

# Add an artifact to the current attestation
chainloop attestation add --name my-artifact --value ./dist/app.tar.gz

# Push/finalize the attestation
chainloop attestation push
```

## Common Patterns

```bash
# List available workflows
chainloop workflow list

# Run attestation in CI (non-interactive)
chainloop attestation init --workflow my-workflow
chainloop attestation add --name binary --value ./build/output
chainloop attestation push --yes

# Verify an attestation
chainloop attestation verify --digest sha256:abc123...
```

## Usage Examples

- "Create a supply chain attestation for this build artifact"
- "Sign and record provenance for a Docker image in CI"
- "Verify the attestation on a released binary"

## SuperCLI

```bash
sc chainloop _ _ version
sc chainloop _ _ attestation init
sc plugins learn chainloop
```

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…