{"id":"2cc78843-d745-4e7b-add5-63ed52feef66","shortId":"DNNRSA","kind":"skill","title":"Sigstore Cosign Verifier","tagline":"Automates container image signature verification using Cosign CLI and the Rekor transparency log API. Validates SLSA provenance attestations and checks Fulcio certificate chains for keyless signing.","description":"# Sigstore Cosign Verifier\n\nAutomates container image signature verification using Cosign CLI and the Rekor transparency log API. Validates SLSA provenance attestations and checks Fulcio certificate chains for keyless signing.\n\n## Installation\n\nUse the upstream install or setup path that matches your environment:\n- $ git clone https://github.com/sigstore/cosign\n- $ go install ./cmd/cosign\n- $ docker push $IMAGE_URI\n\nRequirements and caveats from upstream:\n- {\"Critical\":{\"Identity\":{\"docker-reference\":\"\"},\"Image\":{\"Docker-manifest-digest\":\"sha256:87ef60f558bad79beea6425a3b28989f01dd417164150ab3baab98dcbf04def8\"},\"Type\":\"cosign container image signature\"},\"Optional\":null}\n- **Note:** Most verification workflows require periodically requesting service keys from a TUF repository.\n- Verification fails with failed to verify timestamps: threshold not met for verified log entry integrated timestamps: 0 < 1: You may be verifying a signature that requires RFC3161 timestamp support\n\nBasic usage or getting-started notes:\n- For Homebrew, Arch, Nix, GitHub Action, and Kubernetes installs see the [installation docs](https://docs.sigstore.dev/cosign/system_config/installation/).\n- For Linux and macOS binaries see the [GitHub release assets](https://github.com/sigstore/cosign/releases/latest).\n- :rotating_light: If you are downloading releases of cosign from our GCS bucket - please see more information on the July 31, 2023 [deprecation notice](https://blog.sigstore.dev/cosign-releases-bucket-deprecation/) :ro...\n\n- Source: https://github.com/sigstore/cosign\n- Extracted from upstream docs: https://raw.githubusercontent.com/sigstore/cosign/HEAD/README.md\n\n## Source\n\n- [Agent Skill Exchange](https://agentskillexchange.com/skills/sigstore-cosign-verifier-2/)","tags":["sigstore","cosign","verifier","skills","agentskillexchange","agent-skills","ai-agents","ai-tools","awesome-list","claude-code","codex","cursor"],"capabilities":["skill","source-agentskillexchange","skill-sigstore-cosign-verifier-2","topic-agent-skills","topic-ai-agents","topic-ai-tools","topic-awesome-list","topic-claude-code","topic-codex","topic-cursor","topic-llm","topic-mcp","topic-npx-skills","topic-openclaw","topic-skills-catalog"],"categories":["skills"],"synonyms":[],"warnings":[],"endpointUrl":"https://skills.sh/agentskillexchange/skills/sigstore-cosign-verifier-2","protocol":"skill","transport":"skills-sh","auth":{"type":"none","details":{"cli":"npx skills add agentskillexchange/skills","source_repo":"https://github.com/agentskillexchange/skills","install_from":"skills.sh"}},"qualityScore":"0.454","qualityRationale":"deterministic score 0.45 from registry signals: · indexed on github topic:agent-skills · 8 github stars · SKILL.md body (1,767 chars)","verified":false,"liveness":"unknown","lastLivenessCheck":null,"agentReviews":{"count":0,"score_avg":null,"cost_usd_avg":null,"success_rate":null,"latency_p50_ms":null,"narrative_summary":null,"summary_updated_at":null},"enrichmentModel":"deterministic:skill-github:v1","enrichmentVersion":1,"enrichedAt":"2026-05-18T19:12:29.726Z","embedding":null,"createdAt":"2026-05-18T13:19:26.133Z","updatedAt":"2026-05-18T19:12:29.726Z","lastSeenAt":"2026-05-18T19:12:29.726Z","tsv":"'/cmd/cosign':78 '/cosign-releases-bucket-deprecation/)':211 '/cosign/system_config/installation/).':171 '/sigstore/cosign':75,216 '/sigstore/cosign/head/readme.md':223 '/sigstore/cosign/releases/latest).':184 '/skills/sigstore-cosign-verifier-2/)':230 '0':136 '1':137 '2023':206 '31':205 '87ef60f558bad79beea6425a3b28989f01dd417164150ab3baab98dcbf04def8':99 'action':161 'agent':225 'agentskillexchange.com':229 'agentskillexchange.com/skills/sigstore-cosign-verifier-2/)':228 'api':17,46 'arch':158 'asset':181 'attest':21,50 'autom':4,33 'basic':149 'binari':176 'blog.sigstore.dev':210 'blog.sigstore.dev/cosign-releases-bucket-deprecation/)':209 'bucket':197 'caveat':85 'certif':25,54 'chain':26,55 'check':23,52 'cli':11,40 'clone':72 'contain':5,34,102 'cosign':2,10,31,39,101,193 'critic':88 'deprec':207 'digest':97 'doc':168,220 'docker':79,91,95 'docker-manifest-digest':94 'docker-refer':90 'docs.sigstore.dev':170 'docs.sigstore.dev/cosign/system_config/installation/).':169 'download':190 'entri':133 'environ':70 'exchang':227 'extract':217 'fail':121,123 'fulcio':24,53 'gcs':196 'get':153 'getting-start':152 'git':71 'github':160,179 'github.com':74,183,215 'github.com/sigstore/cosign':73,214 'github.com/sigstore/cosign/releases/latest).':182 'go':76 'homebrew':157 'ident':89 'imag':6,35,81,93,103 'inform':201 'instal':59,63,77,164,167 'integr':134 'juli':204 'key':115 'keyless':28,57 'kubernet':163 'light':186 'linux':173 'log':16,45,132 'maco':175 'manifest':96 'match':68 'may':139 'met':129 'nix':159 'note':107,155 'notic':208 'null':106 'option':105 'path':66 'period':112 'pleas':198 'proven':20,49 'push':80 'raw.githubusercontent.com':222 'raw.githubusercontent.com/sigstore/cosign/head/readme.md':221 'refer':92 'rekor':14,43 'releas':180,191 'repositori':119 'request':113 'requir':83,111,145 'rfc3161':146 'ro':212 'rotat':185 'see':165,177,199 'servic':114 'setup':65 'sha256':98 'sign':29,58 'signatur':7,36,104,143 'sigstor':1,30 'skill':226 'skill-sigstore-cosign-verifier-2' 'slsa':19,48 'sourc':213,224 'source-agentskillexchange' 'start':154 'support':148 'threshold':127 'timestamp':126,135,147 'topic-agent-skills' 'topic-ai-agents' 'topic-ai-tools' 'topic-awesome-list' 'topic-claude-code' 'topic-codex' 'topic-cursor' 'topic-llm' 'topic-mcp' 'topic-npx-skills' 'topic-openclaw' 'topic-skills-catalog' 'transpar':15,44 'tuf':118 'type':100 'upstream':62,87,219 'uri':82 'usag':150 'use':9,38,60 'valid':18,47 'verif':8,37,109,120 'verifi':3,32,125,131,141 'workflow':110","prices":[{"id":"c3baa870-4e9f-4611-a0db-dbb8fff0fccf","listingId":"2cc78843-d745-4e7b-add5-63ed52feef66","amountUsd":"0","unit":"free","nativeCurrency":null,"nativeAmount":null,"chain":null,"payTo":null,"paymentMethod":"skill-free","isPrimary":true,"details":{"org":"agentskillexchange","category":"skills","install_from":"skills.sh"},"createdAt":"2026-05-18T13:19:26.133Z"}],"sources":[{"listingId":"2cc78843-d745-4e7b-add5-63ed52feef66","source":"github","sourceId":"agentskillexchange/skills/sigstore-cosign-verifier-2","sourceUrl":"https://github.com/agentskillexchange/skills/tree/main/skills/sigstore-cosign-verifier-2","isPrimary":false,"firstSeenAt":"2026-05-18T13:19:26.133Z","lastSeenAt":"2026-05-18T19:12:29.726Z"}],"details":{"listingId":"2cc78843-d745-4e7b-add5-63ed52feef66","quickStartSnippet":null,"exampleRequest":null,"exampleResponse":null,"schema":null,"openapiUrl":null,"agentsTxtUrl":null,"citations":[],"useCases":[],"bestFor":[],"notFor":[],"kindDetails":{"org":"agentskillexchange","slug":"sigstore-cosign-verifier-2","github":{"repo":"agentskillexchange/skills","stars":8,"topics":["agent-skills","ai-agents","ai-tools","awesome-list","claude-code","codex","cursor","llm","mcp","npx-skills","openclaw","skills-catalog"],"license":"mit","html_url":"https://github.com/agentskillexchange/skills","pushed_at":"2026-05-18T19:02:17Z","description":"The open catalog of AI agent skills — 2,000+ security-scanned skills for Claude Code, Cursor, Codex, and more.","skill_md_sha":"3f28ba0a72c82d64944f2fbf624779616ff865f6","skill_md_path":"skills/sigstore-cosign-verifier-2/SKILL.md","default_branch":"main","skill_tree_url":"https://github.com/agentskillexchange/skills/tree/main/skills/sigstore-cosign-verifier-2"},"layout":"multi","source":"github","category":"skills","frontmatter":{"name":"Sigstore Cosign Verifier","description":"Automates container image signature verification using Cosign CLI and the Rekor transparency log API. Validates SLSA provenance attestations and checks Fulcio certificate chains for keyless signing."},"skills_sh_url":"https://skills.sh/agentskillexchange/skills/sigstore-cosign-verifier-2"},"updatedAt":"2026-05-18T19:12:29.726Z"}}