Supply Chain Security
MVP available
Supply Chain Security inspects supported agent components at an exact repository commit. It reports findings through a GitHub check so reviewers can see risk in the pull request workflow.
What it protects
Section titled “What it protects”The first release inspects:
SKILL.mdinstruction files; and- known MCP configuration files.
The product is designed to cover more component types over time, including plugins and packages. The current scan scope is always shown with the result.
What a result contains
Section titled “What a result contains”Each result records:
- the exact commit that was inspected;
- the scanner and ruleset versions;
- the policy used for the decision;
- scan completeness and file counts;
- duration; and
- normalized findings with file and line evidence where available.
Scanner errors are reported as failures. They are not treated as clean scans.
How it fits your workflow
Section titled “How it fits your workflow”The GitHub App responds to check events, queues a scan, reads a bounded archive for the requested commit, and publishes the outcome as a GitHub check. Repository code, scripts, hooks, package managers, and builds are never run during scanning.
Read How scanning works for the scan lifecycle and security boundaries.