Research: agent-supply-chain

Cached research evidence for agent-supply-chain (not authority).

Back to catalog page

awesome-copilot skill covering AI/agent supply chain risks: dependency provenance, skill/plugin vetting, model provider trust, update channels.

Target agents: antigravity, claude-code, codex, crush, cursor, gemini-cli, github-copilot, grok, opencode.

trust_tier=needs-inspection; status=inspect-then-install; provenance=verified-install-command; GitHub curated; aligns with this repo mission; inspect for depth vs local policies.

Install: subset of github/awesome-copilot; status=inspect-then-install; selector=named; policy=Inspect source, hooks, scripts, credentials, and dedupe before install.

github/awesome-copilot (GitHub curated)

SBOM / supply chain skills; agent-governance; /review source related concepts.

> Evidence synthesized from public web sources (GitHub repos, official docs, skill registries); confidence reflects source reputation and public signals only. Not an endorsement.