Research: agent-supply-chain
Cached research evidence for agent-supply-chain (not authority).
Purpose
Section titled “Purpose”awesome-copilot skill covering AI/agent supply chain risks: dependency provenance, skill/plugin vetting, model provider trust, update channels.
Harness Coverage
Section titled “Harness Coverage”Target agents: antigravity, claude-code, codex, crush, cursor, gemini-cli, github-copilot, grok, opencode.
Trust And Risks
Section titled “Trust And Risks”trust_tier=needs-inspection; status=inspect-then-install; provenance=verified-install-command; GitHub curated; aligns with this repo mission; inspect for depth vs local policies.
Install Prerequisites
Section titled “Install Prerequisites”Install: subset of github/awesome-copilot; status=inspect-then-install; selector=named; policy=Inspect source, hooks, scripts, credentials, and dedupe before install.
Upstream Maintainer
Section titled “Upstream Maintainer”github/awesome-copilot (GitHub curated)
Comparable Alternatives
Section titled “Comparable Alternatives”SBOM / supply chain skills; agent-governance; /review source related concepts.
> Evidence synthesized from public web sources (GitHub repos, official docs, skill registries); confidence reflects source reputation and public signals only. Not an endorsement.
