Skip to content

Marketplace

Everything your AI needs, in one place.

Ready-made agents, skills, personas, prompts, templates and tools. Each one is checked before it goes live, works with any model, and installs in a click. Rate what you use so the best rises to the top.

143.8K
listings
1
installs
0
reviews
38.7K
publishers
10 results
Skill

supply-chain-security-expert

Secure the path from dependency to deployed artefact: SBOMs, dependency scanning, build provenance, artefact signing and CI/CD integrity. Use when the user mentions supply chain security, SBOM, Cyclon

by personamanagmentlayerskills.sh
Not rated yet
Free
Skill

implementing-code-signing-for-artifacts

Implements code signing for build artifacts (binaries, packages, containers) using GPG, Sigstore, and platform-specific signing tools, establishing trust chains and verifying signatures in deployment

by mukul975skills.sh
Not rated yet
Free
Skill

implementing-image-provenance-verification-with-cosign

Signs and verifies container image provenance with Sigstore Cosign, covering key-based and keyless OIDC signing (Fulcio, Rekor transparency log), SLSA attestations, and enforcing signature verificatio

by mukul975skills.sh
Not rated yet
Free
Skill

implementing-sigstore-for-software-signing

Implements Sigstore-based software signing and verification using Cosign keyless signing, Rekor transparency log verification, and Fulcio certificate authority integration to establish cryptographic p

by mukul975skills.sh
Not rated yet
Free
Skill

implementing-supply-chain-security-with-in-toto

Implements supply chain integrity verification for container builds with the in-toto framework: generating signing keys, defining a supply chain layout, recording pipeline steps as signed link metadat

by mukul975skills.sh
Not rated yet
Free
Skill

verifying-build-provenance-with-slsa-sigstore

Verifies artifact signatures and SLSA provenance using Sigstore's cosign (verify, verify-attestation, verify-blob-attestation) and slsa-verifier (verify-artifact), enforcing keyless OIDC builder ident

by mukul975skills.sh
Not rated yet
Free
Skill

cosign

Expert guidance for Cosign, the Sigstore tool for signing, verifying, and attaching metadata to container images and other OCI artifacts. Helps developers implement supply chain security by signing im

by terminalskillsskills.sh
Not rated yet
Free
Skill

implementing-code-signing-for-artifacts

This skill covers implementing code signing for build artifacts to ensure integrity and authenticity throughout the software supply chain. It addresses signing binaries, packages, and containers using

by ghassan-gaidiGitHub
Not rated yet
Free
Skill

implementing-sigstore-for-software-signing

Implements Sigstore-based software signing and verification using Cosign keyless signing, Rekor transparency log verification, and Fulcio certificate authority integration to establish cryptographic p

by WorkNFlowGitHub
Not rated yet
Free
Skill

supply-chain-security

Use when designing a supply chain security program, implementing SLSA Levels 1-4, generating and signing SBOMs (SPDX/CycloneDX), configuring build provenance with Sigstore/cosign/in-toto, triaging dep

by zeroes-onesGitHub
Not rated yet
Free
1

Find

Search or browse by kind. Every card shows who made it, how many people installed it and what they think.

2

Install

One click. You get a manifest the router understands, plus copy-paste snippets for the CLI, Python and YAML.

3

Rate and publish

Leave a star rating after you have used it. Made something useful? Publish it - free listings go live immediately.

Prefer the terminal? osr stack apply registry://starter installs the starter template.