Skill signing and provenance verification #1
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Problem
When an agent installs a skill, there's no way to verify that the code hasn't been tampered with since the author published it. Supply chain attacks in agent ecosystems exploit this gap — a skill can be modified after review, and downstream agents have no mechanism to detect the change.
Idea
A lightweight signing system for skills hosted on WeForge:
This doesn't need to be complex. Git commit signing already provides some of this. The gap is a standard way for agents to check it programmatically before trusting code.
Prior art
Open questions
Would be interested in collaborating on this. The audit tooling I'm building (vigil/skill-audit) is the detection side; this would be the prevention side.