Skip to content

skill: package SocketDev/skills into dockyard #476

@JAORMX

Description

@JAORMX

Package agent skills from SocketDev/skills into the Dockyard registry.

Source

Rationale

Socket.dev is a first-party supply-chain security vendor. Their skills pack covers dependency scanning, inspection, and remediation workflows — strong overlap with Dockyard's supply-chain-risk-auditor (Trail of Bits).

Candidate skills

  • skills/socket-scan — dependency scanning via Socket CLI (SBOM, reachability, license compliance)
  • skills/socket-inspect — package inspection
  • skills/socket-fix/socket-dep-cleanup
  • skills/socket-fix/socket-dep-patch
  • skills/socket-fix/socket-dep-replace
  • skills/socket-fix/socket-dep-upgrade

Exact paths to confirm at packaging time.

Acceptance criteria

  • One spec.yaml per selected skill under skills/<name>/
  • spec.ref pinned to an audited upstream commit SHA
  • task validate-skill passes for each
  • task scan-skill findings triaged
  • Single PR grouping all SocketDev skills (branch skills/socketdev)

Part of the vendor-by-vendor sweep following #466 (Trail of Bits).

Metadata

Metadata

Assignees

No one assigned

    Labels

    skillsSkill packaging, vendor skill imports

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions