本文へ移動
cccskills
無料GitHub で公開

supply-chain-security

Activate when reviewing or modifying dependency resolution, lockfile schema, package downloaders, signature/integrity checks, file integration cleanup, or anything that could expose APM to dependency confusion, typosquatting, malicious packages, or token leakage.

インストール方法を見る

含まれるファイル(1)

  • SKILL.md1.3 KB

SKILL.md(原文)

インストールする前に、エージェントに与えられる指示の中身を確認できます。

Supply Chain Security Skill

Supply chain security expert persona

When to activate

  • Changes under src/apm_cli/deps/ (resolver, lockfile, downloaders)
  • Changes to src/apm_cli/core/auth.py or token_manager.py
  • Changes to src/apm_cli/integration/cleanup.py (deletion chokepoint)
  • New file-write paths in any integrator
  • New PAT / credential handling in CI workflows
  • apm.lock schema changes
  • Any code that fetches, verifies, or executes content from a remote source

Key rules

  • All path construction routes through src/apm_cli/utils/path_security.py (no ad-hoc ".." in x).
  • All deletions of deployed files route through integration/cleanup.py:remove_stale_deployed_files() (3 safety gates).
  • All credential reads route through AuthResolver -- never raw os.getenv for token vars.
  • Fail closed: if integrity / signature cannot be verified, refuse rather than proceed.
  • Token values must never appear in user-facing strings.

レビュー

まだレビューはありません。使ってみた感想をお寄せください。

同じリポジトリのスキル

概要と使いどころ

Use this skill to run a four-panel adversarial advisory review on any pull request that touches the OpenAPM specification artifact (docs/src/content/docs/specs/openapm-*.md), its inline / sidecar JSON Schemas (docs/src/content/docs/specs/schemas/*.schema.json), or the conformance fixture seed (tests/fixtures/spec-conformance/**). The panel fans out to four spec-ecosystem reviewers (swagger-openapi-editor, oci-distribution-editor, pkgmgr-registry-contract-editor, w3c-tag-architect), each running in its own agent thread, and a spec-editor synthesizer that produces a fold-now / defer-v0.1.1 / defer-v0.2 / reject list plus a ship decision keyed off a 1..10 shocked_meter scale. The orchestrator is the sole writer to the PR: ONE consolidated comment, no verdict labels, no merge gating. The panel is advisory -- it surfaces findings, prioritizes folds, and renders a ship recommendation that the maintainer weighs.

日本語の概要は準備中です。原文の説明を表示しています。

microsoft/apm3,9972026年10月10日 更新

Activate for changes to project positioning, release communication, community-facing artifacts, or breaking-change decisions in microsoft/apm. Triggers on README, MANIFESTO, PRD, CHANGELOG, release workflows, and issue templates.

日本語の概要は準備中です。原文の説明を表示しています。

microsoft/apm3,9972026年10月10日 更新

apm-usage

無料

Activate when the user asks about APM (Agent Package Manager): installing, configuring, authoring, or troubleshooting AI-agent packages, dependencies, compilation, MCP servers, policy, or any `apm` CLI command.

日本語の概要は準備中です。原文の説明を表示しています。

microsoft/apm3,9972026年10月10日 更新

auth

無料

Activate when code touches token management, credential resolution, git auth flows, GITHUB_APM_PAT, ADO_APM_PAT, AuthResolver, HostInfo, AuthContext, or any remote host authentication -- even if 'auth' isn't mentioned explicitly.

日本語の概要は準備中です。原文の説明を表示しています。

microsoft/apm3,9972026年10月10日 更新

Use this skill to post or patch ONE GitHub comment for a microsoft/apm autopilot run. It owns public vs debug body assembly and the AI disclaimer footer. Never labels, assigns, requests reviewers, or merges. Autopilot skills that write comments must load this skill and must not call gh comment APIs themselves.

日本語の概要は準備中です。原文の説明を表示しています。

microsoft/apm3,9972026年10月10日 更新

Use this skill to queue maintainer-accepted microsoft/apm issues (`status/accepted`) and fan them out through an isolated pool (default 2) of autopilot-issue-delivery-worker sessions. Any accepted type is eligible. Advisory `triage/recommended` is not authorization. Does not triage. Does not review PRs. Works in a local session, Copilot App automation, Cloud Agent, Remote Agent, or Agentic Workflow.

日本語の概要は準備中です。原文の説明を表示しています。

microsoft/apm3,9972026年10月10日 更新

microsoft のスキルをすべて見る

このスキルの問題を報告する