AgentStack
Browse Sign in
Browse Why AgentStack Sell Docs
Sign in
SKILL verified Apache-2.0 Self-run

Manage Supply Chain

skill-harness-harness-skills-manage-supply-chain · by harness

>-

No reviews yet
0 installs
26 views
0.0% view→install

Install

$ agentstack add skill-harness-harness-skills-manage-supply-chain

✓ scanned · ✓ verified, works with Claude Code, Cursor, and more.

Security review

✓ Passed

No issues found. Passed automated security review. · v0.1.0 How review works →

  • Prompt-injection patterns
  • Secret / credential exfiltration
  • Dangerous shell & filesystem operations
  • Untrusted network calls
  • Known-malicious package signatures

What it can access

  • Network access No
  • Filesystem access No
  • Shell / process execution No
  • Environment & secrets No
  • Dynamic code execution No

From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.

View the full security report →

Verified badge

Passed review? Show it. Paste this badge into your README, it links to the public security report.

AgentStack Verified badge Links to your public security report.
[![AgentStack Verified](https://agentstack.voostack.com/badges/verified.svg)](https://agentstack.voostack.com/security/report/skill-harness-harness-skills-manage-supply-chain)

Reliability & compatibility

Security review passed
0 installs to date
no reviews yet
3mo ago

Declared compatibility

Claude CodeClaude Desktop

Compatibility is declared by the source manifest. End-to-end runtime verification is coming, see below.

Preview Execution monitoring

We're building live execution health for every listing: tool-call success rate, median latency, uptime, and last-checked timestamps, measured, not self-reported. It isn't live yet, so we don't show numbers we can't stand behind.

How agent discovery & health will work →
Are you the author of Manage Supply Chain? Claim this listing to set pricing, connect Stripe payouts, and keep 70% of every sale.
Sign up to claim

About

Manage Supply Chain

Configure SBOM generation, artifact signing, supply chain policy enforcement, and SLSA provenance tracking in Harness SSCA.

Instructions

Step 1: Establish Scope

Confirm the user's org, project, service, and build tool.

Call MCP tool: harness_list
Parameters:
  resource_type: "project"
  org_id: ""

Step 2: Identify the SSCA Task

Determine which workflow the user needs:

  1. SBOM Generation -- Automated SBOM creation on every build with signing and attestation
  2. Supply Chain Policy Enforcement -- OPA policies for artifact provenance, signing, and compliance

Step 3: Configure SBOM Generation

Gather from the user:

  • Service name, build tool, and language
  • Pipeline to attach SBOM generation to
  • SBOM format: CycloneDX 1.5 (JSON) or SPDX 2.3 (JSON)
  • SBOM scope: direct dependencies, transitive, or full (OS + language + transitive)
  • Signing key provider: Cosign keyless (Sigstore), Cosign with KMS, AWS KMS, GCP KMS

Configure SBOM generation in the CI pipeline:

  • Trigger on every successful build or container push
  • Generate SBOM in the selected format
  • Sign SBOM with the configured key provider
  • Attach as OCI artifact alongside the container image
  • Require valid signature verification before deployment to protected environments

Supply Chain Risk Analysis:

  • Flag dependencies with known CVEs above CVSS threshold (default 7.0)
  • Detect license conflicts (e.g., GPL-3.0, AGPL-3.0)
  • Flag dependencies outdated by more than N months
  • Flag dependencies from untrusted registries

Compliance Mapping:

  • Target SLSA level (Level 1, 2, or 3)
  • Map to compliance frameworks: NIST SSDF, EO 14028, SOC2

Step 4: Configure Supply Chain Policy Enforcement

Gather enforcement points from the user (build, push, deploy, or all stages).

Define OPA policies:

  1. Artifact Provenance -- Require all container images to have valid Cosign signatures
  2. SLSA Level -- Enforce minimum SLSA level for production deployments
  3. SBOM Requirements -- Block deployment if SBOM is missing or unsigned
  4. Dependency Restrictions -- Block artifacts with banned licenses or known malicious packages
  5. Registry Allowlist -- Only allow artifacts from approved registries
Call MCP tool: harness_create
Parameters:
  resource_type: "policy"
  org_id: ""
  project_id: ""
  body:
    name: "supply-chain-enforcement"
    identifier: "supply_chain_enforcement"
    rego: |
      package harness.supply_chain

      deny[msg] {
        not input.artifact.signed
        msg := "Artifact must be signed with Cosign before deployment"
      }

      deny[msg] {
        not input.artifact.sbom_attached
        msg := "SBOM must be generated and attached to artifact"
      }

Step 5: Set Up SBOM Storage and Dashboards

Configure SBOM storage:

  • Store in Harness AR alongside the image, or in S3/GCS/Dependency-Track
  • Set retention period (default 365 days)

Enable the SSCA portal dashboard for:

  • Real-time component inventory across all services
  • Vulnerability trends over time
  • License compliance status
  • SLSA level tracking per service

Examples

  • "Generate SBOMs for our payment-service builds" -- Configure CycloneDX SBOM generation with Cosign signing in the CI pipeline
  • "Enforce artifact signing for production deployments" -- Create OPA policy requiring valid Cosign signatures
  • "Set up SLSA Level 2 compliance tracking" -- Configure provenance tracking and SBOM attestation
  • "Block deployments with GPL-3.0 dependencies" -- Create supply chain policy with license restrictions
  • "Track our software supply chain risk" -- Enable SSCA dashboard with CVE, license, and staleness analysis

Performance Notes

  • SBOM generation adds 10-30 seconds to the build depending on dependency count -- acceptable for most pipelines.
  • Cosign keyless signing (Sigstore) is simpler to set up than KMS-backed keys but requires internet access.
  • SLSA Level 3 requires hermetic builds -- this may require significant pipeline restructuring.
  • SBOM storage costs are minimal (JSON files) but retention policies prevent unbounded growth.

Troubleshooting

SBOM Generation Failing

  • Verify the build tool is supported by the SBOM generator (Syft, Trivy, cdxgen)
  • Check that the container image is accessible at the point SBOM generation runs
  • For monorepos, ensure the SBOM scope is set to the correct subdirectory

Cosign Signing Errors

  • For keyless: verify the OIDC provider (Sigstore/Fulcio) is reachable
  • For KMS: verify the service account has signing permissions on the key
  • Check that the Cosign binary version is compatible with the image format

Policy Blocking Deployments

  • Check which specific policy rule is triggering the deny
  • Use the exemption workflow for known false positives
  • Verify the policy is evaluating the correct input fields from the pipeline

Source & license

This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.

  • Author: harness
  • Source: harness/harness-skills
  • License: Apache-2.0
  • Homepage: https://developer.harness.io/docs/platform/harness-ai/harness-skills/

Install and usage instructions live in the source repository linked above.

Reviews

No reviews yet, be the first.

Versions

  • v0.1.0 Imported from the upstream source.