Skip to content

Supply Chain Security

MVP available

Supply Chain Security inspects supported agent components at an exact repository commit. It reports findings through a GitHub check so reviewers can see risk in the pull request workflow.

The first release inspects:

  • SKILL.md instruction files; and
  • known MCP configuration files.

The product is designed to cover more component types over time, including plugins and packages. The current scan scope is always shown with the result.

Each result records:

  • the exact commit that was inspected;
  • the scanner and ruleset versions;
  • the policy used for the decision;
  • scan completeness and file counts;
  • duration; and
  • normalized findings with file and line evidence where available.

Scanner errors are reported as failures. They are not treated as clean scans.

The GitHub App responds to check events, queues a scan, reads a bounded archive for the requested commit, and publishes the outcome as a GitHub check. Repository code, scripts, hooks, package managers, and builds are never run during scanning.

Read How scanning works for the scan lifecycle and security boundaries.