Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add Zfinix/aster --skill supply-chain-safetygit clone --depth 1 https://github.com/Zfinix/asterWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/zfinix/aster/supply-chain-safety)<a href="https://agentmods.dev/skills/zfinix/aster/supply-chain-safety"><img src="https://agentmods.dev/badge/skills/zfinix/aster/supply-chain-safety/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/zfinix/aster/supply-chain-safety"><img src="https://agentmods.dev/badge/skills/zfinix/aster/supply-chain-safety.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00038 | $0.00480 |
| Opus 5 | $0.00019 | $0.00240 |
| Sonnet 5 | $0.00008 | $0.00096 |
| Haiku 4.5 | $0.00004 | $0.00048 |
Grade D, and why
supply-chain-safety scanned grade D with 3 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 9d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Downloads and executes remote codehighSupply chain
curl | sh runs whatever the server returns today, which is not necessarily what it returned when this was reviewed.
6. **Never pipe the internet into a shell.** No `curl ... | bash`, no Unrestricted tool accessmediumExcessive agency
A wildcard tool grant or "run any command" leaves no least-privilege boundary at all.
prepare) run arbitrary code with your privileges and are the top npm Makes network callslowCapability
Not a fault in itself. Listed so you know the mod talks to something, and to what.
6. **Never pipe the internet into a shell.** No `curl ... | bash`, no What it actually says
Supply chain safety
- Install with scripts off. Lifecycle hooks (preinstall, postinstall,
prepare) run arbitrary code with your privileges and are the top npm
attack vector:
npm ci --ignore-scripts,pnpm install --ignore-scripts,bun install(scripts off by default for new deps). If the project truly needs a hook (native builds), run that one package's build explicitly afterward and say so. - Reproduce, do not resolve. In an existing repo use the lockfile
verbatim:
npm ci,pnpm install --frozen-lockfile,bun install --frozen-lockfile. Plainnpm installmay silently upgrade what the repo pinned. - Verify a package exists before adding it. Models hallucinate package
names, and attackers register those names (slopsquatting). Check the
registry first:
npm view <name> versions time downloads— a package that appeared last week with three downloads is not the library you meant. - Prefer boring versions. The freshest release is the compromise window; recent campaigns shipped malware in brand-new patch versions of trusted packages. Pin exact versions and let a new release age unless it fixes something you need.
- Read the lockfile diff before committing it. New transitive deps,
changed registry URLs, or git/tarball sources appearing in a routine
change are the dependency-confusion signature.
git diff --statthe lockfile and question anything you did not intend to add. - Never pipe the internet into a shell. No
curl ... | bash, nowget ... | sh. Download to a file, read it, then decide. - Audit is a signal, not a chore.
npm audit --omit=devafter installs; report criticals to the user rather than auto-fixing with--force(that is a blind major bump).
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 9d ago First seen · 36 lines · 38 tokens per session scan D a0ee6997169d
supply-chain-safety is a skill published in the GitHub repository Zfinix/aster (77 stars, last pushed 2d ago), licensed Apache-2.0. It adds 38 tokens to every session and 480 once invoked, about $0.0002 per session on Opus 5. A static security scan graded it D with 3 findings (downloads and executes remote code, unrestricted tool access, makes network calls). No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other skills, from other repositories
harness
Use when governing a workspace's control plane, code or not — the 01-TOOLS/ tooling layer, the 02-DOCS/ chaos→knowledge wiki, the root Knowledge map. Audits it, migrates legacy XX- folders, scaffolds provider tooling, sweeps the inbox, writes root CLAUDE.md/AGENTS.md. NOT the bootstrap front door (that is init, which…
ctx
Codebase intelligence and evidence-driven governance with the indexed ctx CLI. Use when exploring an unfamiliar repository, locating symbols or callers, checking for existing implementations, estimating change impact, enforcing architecture rules, scoring a branch, finding hotspots or duplication, or analyzing…
lemma-user
Operate an existing Lemma pod from the CLI as a human or agent: inspect resources, query tables and records under RLS, search and read pod files (converted markdown, page images), run functions and workflows, submit waiting workflow forms, chat with pod agents, message pod members, and execute third-party connector…
lemma-app-qa
Test and verify Lemma pod apps through real end-to-end user journeys in authenticated local and deployed contexts. Use when asked to QA, dogfood, smoke-test, regression-test, acceptance-test, reproduce, or verify a Lemma app; validate UI behavior against durable pod state; check auth, RLS, delegated workloads…
lemma-builder
Design and build complete Lemma pods: model tables/files/functions/agents/workflows/schedules/connectors/surfaces/apps from a problem statement, author a local pod bundle, import progressively with the Lemma CLI, and verify every layer. Use for pod design, creation, restructuring, import/export, and app development.…
lemma-evals
Design, run, and review repeatable evaluations for Lemma agents, functions, and workflows. Use when defining evaluation contracts and case datasets, comparing a baseline with a candidate revision or runtime, checking deterministic correctness or rubric-scored judgment, measuring repeated-run variance, testing…