{"id":"1d7cce53-a33f-41e7-8ba0-a2a197ae9da6","shortId":"nsg6tq","kind":"skill","title":"Sigstore Cosign Container Verifier","tagline":"Verifies container image signatures and provenance using Sigstore Cosign and Rekor transparency log. Enforces supply chain policies with OPA Gatekeeper admission rules.","description":"# Sigstore Cosign Container Verifier\n\nVerifies container image signatures and provenance using Sigstore Cosign and Rekor transparency log. Enforces supply chain policies with OPA Gatekeeper admission rules.\n\n## Installation\n\nUse the upstream install or setup path that matches your environment:\n- $ git clone https://github.com/sigstore/cosign\n- $ go install ./cmd/cosign\n- $ docker push $IMAGE_URI\n\nRequirements and caveats from upstream:\n- {\"Critical\":{\"Identity\":{\"docker-reference\":\"\"},\"Image\":{\"Docker-manifest-digest\":\"sha256:87ef60f558bad79beea6425a3b28989f01dd417164150ab3baab98dcbf04def8\"},\"Type\":\"cosign container image signature\"},\"Optional\":null}\n- **Note:** Most verification workflows require periodically requesting service keys from a TUF repository.\n- Verification fails with failed to verify timestamps: threshold not met for verified log entry integrated timestamps: 0 < 1: You may be verifying a signature that requires RFC3161 timestamp support\n\nBasic usage or getting-started notes:\n- For Homebrew, Arch, Nix, GitHub Action, and Kubernetes installs see the [installation docs](https://docs.sigstore.dev/cosign/system_config/installation/).\n- For Linux and macOS binaries see the [GitHub release assets](https://github.com/sigstore/cosign/releases/latest).\n- :rotating_light: If you are downloading releases of cosign from our GCS bucket - please see more information on the July 31, 2023 [deprecation notice](https://blog.sigstore.dev/cosign-releases-bucket-deprecation/) :ro...\n\n- Source: https://github.com/sigstore/cosign\n- Extracted from upstream docs: https://raw.githubusercontent.com/sigstore/cosign/HEAD/README.md\n\n## Source\n\n- [Agent Skill Exchange](https://agentskillexchange.com/skills/sigstore-cosign-container-verifier/)","tags":["sigstore","cosign","container","verifier","skills","agentskillexchange","agent-skills","ai-agents","ai-tools","awesome-list","claude-code","codex"],"capabilities":["skill","source-agentskillexchange","skill-sigstore-cosign-container-verifier","topic-agent-skills","topic-ai-agents","topic-ai-tools","topic-awesome-list","topic-claude-code","topic-codex","topic-cursor","topic-llm","topic-mcp","topic-npx-skills","topic-openclaw","topic-skills-catalog"],"categories":["skills"],"synonyms":[],"warnings":[],"endpointUrl":"https://skills.sh/agentskillexchange/skills/sigstore-cosign-container-verifier","protocol":"skill","transport":"skills-sh","auth":{"type":"none","details":{"cli":"npx skills add agentskillexchange/skills","source_repo":"https://github.com/agentskillexchange/skills","install_from":"skills.sh"}},"qualityScore":"0.454","qualityRationale":"deterministic score 0.45 from registry signals: · indexed on github topic:agent-skills · 8 github stars · SKILL.md body (1,755 chars)","verified":false,"liveness":"unknown","lastLivenessCheck":null,"agentReviews":{"count":0,"score_avg":null,"cost_usd_avg":null,"success_rate":null,"latency_p50_ms":null,"narrative_summary":null,"summary_updated_at":null},"enrichmentModel":"deterministic:skill-github:v1","enrichmentVersion":1,"enrichedAt":"2026-05-18T19:12:29.559Z","embedding":null,"createdAt":"2026-05-18T13:19:25.841Z","updatedAt":"2026-05-18T19:12:29.559Z","lastSeenAt":"2026-05-18T19:12:29.559Z","tsv":"'/cmd/cosign':72 '/cosign-releases-bucket-deprecation/)':205 '/cosign/system_config/installation/).':165 '/sigstore/cosign':69,210 '/sigstore/cosign/head/readme.md':217 '/sigstore/cosign/releases/latest).':178 '/skills/sigstore-cosign-container-verifier/)':224 '0':130 '1':131 '2023':200 '31':199 '87ef60f558bad79beea6425a3b28989f01dd417164150ab3baab98dcbf04def8':93 'action':155 'admiss':25,51 'agent':219 'agentskillexchange.com':223 'agentskillexchange.com/skills/sigstore-cosign-container-verifier/)':222 'arch':152 'asset':175 'basic':143 'binari':170 'blog.sigstore.dev':204 'blog.sigstore.dev/cosign-releases-bucket-deprecation/)':203 'bucket':191 'caveat':79 'chain':20,46 'clone':66 'contain':3,6,29,32,96 'cosign':2,13,28,39,95,187 'critic':82 'deprec':201 'digest':91 'doc':162,214 'docker':73,85,89 'docker-manifest-digest':88 'docker-refer':84 'docs.sigstore.dev':164 'docs.sigstore.dev/cosign/system_config/installation/).':163 'download':184 'enforc':18,44 'entri':127 'environ':64 'exchang':221 'extract':211 'fail':115,117 'gatekeep':24,50 'gcs':190 'get':147 'getting-start':146 'git':65 'github':154,173 'github.com':68,177,209 'github.com/sigstore/cosign':67,208 'github.com/sigstore/cosign/releases/latest).':176 'go':70 'homebrew':151 'ident':83 'imag':7,33,75,87,97 'inform':195 'instal':53,57,71,158,161 'integr':128 'juli':198 'key':109 'kubernet':157 'light':180 'linux':167 'log':17,43,126 'maco':169 'manifest':90 'match':62 'may':133 'met':123 'nix':153 'note':101,149 'notic':202 'null':100 'opa':23,49 'option':99 'path':60 'period':106 'pleas':192 'polici':21,47 'proven':10,36 'push':74 'raw.githubusercontent.com':216 'raw.githubusercontent.com/sigstore/cosign/head/readme.md':215 'refer':86 'rekor':15,41 'releas':174,185 'repositori':113 'request':107 'requir':77,105,139 'rfc3161':140 'ro':206 'rotat':179 'rule':26,52 'see':159,171,193 'servic':108 'setup':59 'sha256':92 'signatur':8,34,98,137 'sigstor':1,12,27,38 'skill':220 'skill-sigstore-cosign-container-verifier' 'sourc':207,218 'source-agentskillexchange' 'start':148 'suppli':19,45 'support':142 'threshold':121 'timestamp':120,129,141 'topic-agent-skills' 'topic-ai-agents' 'topic-ai-tools' 'topic-awesome-list' 'topic-claude-code' 'topic-codex' 'topic-cursor' 'topic-llm' 'topic-mcp' 'topic-npx-skills' 'topic-openclaw' 'topic-skills-catalog' 'transpar':16,42 'tuf':112 'type':94 'upstream':56,81,213 'uri':76 'usag':144 'use':11,37,54 'verif':103,114 'verifi':4,5,30,31,119,125,135 'workflow':104","prices":[{"id":"62770c3f-c530-416c-b3a3-602e379c2102","listingId":"1d7cce53-a33f-41e7-8ba0-a2a197ae9da6","amountUsd":"0","unit":"free","nativeCurrency":null,"nativeAmount":null,"chain":null,"payTo":null,"paymentMethod":"skill-free","isPrimary":true,"details":{"org":"agentskillexchange","category":"skills","install_from":"skills.sh"},"createdAt":"2026-05-18T13:19:25.841Z"}],"sources":[{"listingId":"1d7cce53-a33f-41e7-8ba0-a2a197ae9da6","source":"github","sourceId":"agentskillexchange/skills/sigstore-cosign-container-verifier","sourceUrl":"https://github.com/agentskillexchange/skills/tree/main/skills/sigstore-cosign-container-verifier","isPrimary":false,"firstSeenAt":"2026-05-18T13:19:25.841Z","lastSeenAt":"2026-05-18T19:12:29.559Z"}],"details":{"listingId":"1d7cce53-a33f-41e7-8ba0-a2a197ae9da6","quickStartSnippet":null,"exampleRequest":null,"exampleResponse":null,"schema":null,"openapiUrl":null,"agentsTxtUrl":null,"citations":[],"useCases":[],"bestFor":[],"notFor":[],"kindDetails":{"org":"agentskillexchange","slug":"sigstore-cosign-container-verifier","github":{"repo":"agentskillexchange/skills","stars":8,"topics":["agent-skills","ai-agents","ai-tools","awesome-list","claude-code","codex","cursor","llm","mcp","npx-skills","openclaw","skills-catalog"],"license":"mit","html_url":"https://github.com/agentskillexchange/skills","pushed_at":"2026-05-18T19:02:17Z","description":"The open catalog of AI agent skills — 2,000+ security-scanned skills for Claude Code, Cursor, Codex, and more.","skill_md_sha":"e66255589027983eff9db46e6c54ee05f62cf61a","skill_md_path":"skills/sigstore-cosign-container-verifier/SKILL.md","default_branch":"main","skill_tree_url":"https://github.com/agentskillexchange/skills/tree/main/skills/sigstore-cosign-container-verifier"},"layout":"multi","source":"github","category":"skills","frontmatter":{"name":"Sigstore Cosign Container Verifier","description":"Verifies container image signatures and provenance using Sigstore Cosign and Rekor transparency log. Enforces supply chain policies with OPA Gatekeeper admission rules."},"skills_sh_url":"https://skills.sh/agentskillexchange/skills/sigstore-cosign-container-verifier"},"updatedAt":"2026-05-18T19:12:29.559Z"}}