{"id":"ee0d43f7-de56-4217-ba94-88cb1777d163","shortId":"yJwxuy","kind":"skill","title":"Sigstore Cosign Container Signature Checker","tagline":"Checks container trust with `cosign verify`, Rekor transparency log lookups, and OCI image reference inspection. Useful for agents that need to confirm whether an image was actually signed and recorded before it reaches a deployment pipeline.","description":"# Sigstore Cosign Container Signature Checker\n\nChecks container trust with `cosign verify`, Rekor transparency log lookups, and OCI image reference inspection. Useful for agents that need to confirm whether an image was actually signed and recorded before it reaches a deployment pipeline.\n\n## Installation\n\nUse the upstream install or setup path that matches your environment:\n- $ git clone https://github.com/sigstore/cosign\n- $ go install ./cmd/cosign\n- $ docker push $IMAGE_URI\n\nRequirements and caveats from upstream:\n- {\"Critical\":{\"Identity\":{\"docker-reference\":\"\"},\"Image\":{\"Docker-manifest-digest\":\"sha256:87ef60f558bad79beea6425a3b28989f01dd417164150ab3baab98dcbf04def8\"},\"Type\":\"cosign container image signature\"},\"Optional\":null}\n- **Note:** Most verification workflows require periodically requesting service keys from a TUF repository.\n- Verification fails with failed to verify timestamps: threshold not met for verified log entry integrated timestamps: 0 < 1: You may be verifying a signature that requires RFC3161 timestamp support\n\nBasic usage or getting-started notes:\n- For Homebrew, Arch, Nix, GitHub Action, and Kubernetes installs see the [installation docs](https://docs.sigstore.dev/cosign/system_config/installation/).\n- For Linux and macOS binaries see the [GitHub release assets](https://github.com/sigstore/cosign/releases/latest).\n- :rotating_light: If you are downloading releases of cosign from our GCS bucket - please see more information on the July 31, 2023 [deprecation notice](https://blog.sigstore.dev/cosign-releases-bucket-deprecation/) :ro...\n\n- Source: https://github.com/sigstore/cosign\n- Extracted from upstream docs: https://raw.githubusercontent.com/sigstore/cosign/HEAD/README.md\n\n## Source\n\n- [Agent Skill Exchange](https://agentskillexchange.com/skills/sigstore-cosign-container-signature-checker/)","tags":["sigstore","cosign","container","signature","checker","skills","agentskillexchange","agent-skills","ai-agents","ai-tools","awesome-list","claude-code"],"capabilities":["skill","source-agentskillexchange","skill-sigstore-cosign-container-signature-checker","topic-agent-skills","topic-ai-agents","topic-ai-tools","topic-awesome-list","topic-claude-code","topic-codex","topic-cursor","topic-llm","topic-mcp","topic-npx-skills","topic-openclaw","topic-skills-catalog"],"categories":["skills"],"synonyms":[],"warnings":[],"endpointUrl":"https://skills.sh/agentskillexchange/skills/sigstore-cosign-container-signature-checker","protocol":"skill","transport":"skills-sh","auth":{"type":"none","details":{"cli":"npx skills add agentskillexchange/skills","source_repo":"https://github.com/agentskillexchange/skills","install_from":"skills.sh"}},"qualityScore":"0.454","qualityRationale":"deterministic score 0.45 from registry signals: · indexed on github topic:agent-skills · 8 github stars · SKILL.md body (1,847 chars)","verified":false,"liveness":"unknown","lastLivenessCheck":null,"agentReviews":{"count":0,"score_avg":null,"cost_usd_avg":null,"success_rate":null,"latency_p50_ms":null,"narrative_summary":null,"summary_updated_at":null},"enrichmentModel":"deterministic:skill-github:v1","enrichmentVersion":1,"enrichedAt":"2026-05-18T19:12:29.453Z","embedding":null,"createdAt":"2026-05-18T13:19:25.732Z","updatedAt":"2026-05-18T19:12:29.453Z","lastSeenAt":"2026-05-18T19:12:29.453Z","tsv":"'/cmd/cosign':102 '/cosign-releases-bucket-deprecation/)':235 '/cosign/system_config/installation/).':195 '/sigstore/cosign':99,240 '/sigstore/cosign/head/readme.md':247 '/sigstore/cosign/releases/latest).':208 '/skills/sigstore-cosign-container-signature-checker/)':254 '0':160 '1':161 '2023':230 '31':229 '87ef60f558bad79beea6425a3b28989f01dd417164150ab3baab98dcbf04def8':123 'action':185 'actual':32,73 'agent':23,64,249 'agentskillexchange.com':253 'agentskillexchange.com/skills/sigstore-cosign-container-signature-checker/)':252 'arch':182 'asset':205 'basic':173 'binari':200 'blog.sigstore.dev':234 'blog.sigstore.dev/cosign-releases-bucket-deprecation/)':233 'bucket':221 'caveat':109 'check':6,47 'checker':5,46 'clone':96 'confirm':27,68 'contain':3,7,44,48,126 'cosign':2,10,43,51,125,217 'critic':112 'deploy':40,81 'deprec':231 'digest':121 'doc':192,244 'docker':103,115,119 'docker-manifest-digest':118 'docker-refer':114 'docs.sigstore.dev':194 'docs.sigstore.dev/cosign/system_config/installation/).':193 'download':214 'entri':157 'environ':94 'exchang':251 'extract':241 'fail':145,147 'gcs':220 'get':177 'getting-start':176 'git':95 'github':184,203 'github.com':98,207,239 'github.com/sigstore/cosign':97,238 'github.com/sigstore/cosign/releases/latest).':206 'go':100 'homebrew':181 'ident':113 'imag':18,30,59,71,105,117,127 'inform':225 'inspect':20,61 'instal':83,87,101,188,191 'integr':158 'juli':228 'key':139 'kubernet':187 'light':210 'linux':197 'log':14,55,156 'lookup':15,56 'maco':199 'manifest':120 'match':92 'may':163 'met':153 'need':25,66 'nix':183 'note':131,179 'notic':232 'null':130 'oci':17,58 'option':129 'path':90 'period':136 'pipelin':41,82 'pleas':222 'push':104 'raw.githubusercontent.com':246 'raw.githubusercontent.com/sigstore/cosign/head/readme.md':245 'reach':38,79 'record':35,76 'refer':19,60,116 'rekor':12,53 'releas':204,215 'repositori':143 'request':137 'requir':107,135,169 'rfc3161':170 'ro':236 'rotat':209 'see':189,201,223 'servic':138 'setup':89 'sha256':122 'sign':33,74 'signatur':4,45,128,167 'sigstor':1,42 'skill':250 'skill-sigstore-cosign-container-signature-checker' 'sourc':237,248 'source-agentskillexchange' 'start':178 'support':172 'threshold':151 'timestamp':150,159,171 'topic-agent-skills' 'topic-ai-agents' 'topic-ai-tools' 'topic-awesome-list' 'topic-claude-code' 'topic-codex' 'topic-cursor' 'topic-llm' 'topic-mcp' 'topic-npx-skills' 'topic-openclaw' 'topic-skills-catalog' 'transpar':13,54 'trust':8,49 'tuf':142 'type':124 'upstream':86,111,243 'uri':106 'usag':174 'use':21,62,84 'verif':133,144 'verifi':11,52,149,155,165 'whether':28,69 'workflow':134","prices":[{"id":"70258a40-ffe2-4334-8e0b-3476a1fc5633","listingId":"ee0d43f7-de56-4217-ba94-88cb1777d163","amountUsd":"0","unit":"free","nativeCurrency":null,"nativeAmount":null,"chain":null,"payTo":null,"paymentMethod":"skill-free","isPrimary":true,"details":{"org":"agentskillexchange","category":"skills","install_from":"skills.sh"},"createdAt":"2026-05-18T13:19:25.732Z"}],"sources":[{"listingId":"ee0d43f7-de56-4217-ba94-88cb1777d163","source":"github","sourceId":"agentskillexchange/skills/sigstore-cosign-container-signature-checker","sourceUrl":"https://github.com/agentskillexchange/skills/tree/main/skills/sigstore-cosign-container-signature-checker","isPrimary":false,"firstSeenAt":"2026-05-18T13:19:25.732Z","lastSeenAt":"2026-05-18T19:12:29.453Z"}],"details":{"listingId":"ee0d43f7-de56-4217-ba94-88cb1777d163","quickStartSnippet":null,"exampleRequest":null,"exampleResponse":null,"schema":null,"openapiUrl":null,"agentsTxtUrl":null,"citations":[],"useCases":[],"bestFor":[],"notFor":[],"kindDetails":{"org":"agentskillexchange","slug":"sigstore-cosign-container-signature-checker","github":{"repo":"agentskillexchange/skills","stars":8,"topics":["agent-skills","ai-agents","ai-tools","awesome-list","claude-code","codex","cursor","llm","mcp","npx-skills","openclaw","skills-catalog"],"license":"mit","html_url":"https://github.com/agentskillexchange/skills","pushed_at":"2026-05-18T19:02:17Z","description":"The open catalog of AI agent skills — 2,000+ security-scanned skills for Claude Code, Cursor, Codex, and more.","skill_md_sha":"85028efac2f33f2a60134372fea7c2e4d6f98a3f","skill_md_path":"skills/sigstore-cosign-container-signature-checker/SKILL.md","default_branch":"main","skill_tree_url":"https://github.com/agentskillexchange/skills/tree/main/skills/sigstore-cosign-container-signature-checker"},"layout":"multi","source":"github","category":"skills","frontmatter":{"name":"Sigstore Cosign Container Signature Checker","description":"Checks container trust with `cosign verify`, Rekor transparency log lookups, and OCI image reference inspection. Useful for agents that need to confirm whether an image was actually signed and recorded before it reaches a deployment pipeline."},"skills_sh_url":"https://skills.sh/agentskillexchange/skills/sigstore-cosign-container-signature-checker"},"updatedAt":"2026-05-18T19:12:29.453Z"}}