agentsclimarketplace

Check artifact reputation

Skill gaelic-ghost/socket/skills/check-artifact-reputation

The Source for macOS Agent Workflows

Install
npx -y skills add gaelic-ghost/socket --skill check-artifact-reputation

Assembled from the repository path, not quoted from the project. Check it against their README if it does not work.

One thing to look at

  • 6 stars6 stars. Stars are a popularity signal and not a quality one, but at this level it is likely that nobody has read this closely except its author, and you would be relying on your own review.

What its author says it does

Copied from the file, not written here

Check local and external reputation for a suspicious artifact, signer, hash, URL, domain, certificate, package, or vendor. Use when provenance and threat-intelligence context could inform triage, while sample-upload privacy, stale intelligence, hash-only misses, false positives, and reputation-versus-behavior limits must remain explicit.

SKILL.md

2.0 KB, as published. Nobody here has run it

Check Artifact Reputation

Overview

Gather provenance and intelligence without treating popularity, valid signing, a clean lookup, or a vendor label as a safety verdict. Prefer local identity and vendor sources before sending data to third parties.

Read references/reputation-evidence.md for source ordering and interpretation.

Workflow

  1. Fix identity.

    • Record artifact hashes, signer/certificate, exact version, source URL, domain, resolved destinations, and acquisition time.
  2. Check local evidence.

    • Inspect quarantine/provenance, signature/notarization, known installation records, local security detections, and expected vendor distribution paths.
  3. Check authoritative sources.

    • Prefer vendor advisories, release checksums/signatures, certificate status, official repositories, and current platform security sources.
    • Date each lookup.
  4. Decide whether external intelligence is appropriate.

    • Explain whether the service receives only a hash/domain or may upload/retain the artifact.
    • Obtain explicit approval before sending private artifacts, URLs, customer data, or unknown binaries.
  5. Correlate results.

    • Record detection names, engines/sources, first/last seen, submission context, prevalence, relations, and conflicting classifications.
    • Distinguish “not present” from “known benign.”
  6. Feed behavior analysis.

    • Use reputation to prioritize static/dynamic checks, not replace them.

Output

Return identity, sources/date, privacy decision, reputation observations, conflicts, interpretation limits, confidence effect, and next behavioral check.

Keep looking

Skills are one crate of 328,083. Ordering is by how many stacks a row turns up in, so the top of any crate is what has actually been picked rather than what has the most stars.