assessing-third-party-components
Use for a standalone ungoverned read-only clearance of an exact third-party software component or immutable artifact, including provenance, license, dependencies, and conformance checks before adoption or maintenance. Includes packages, vendored artifacts, Actions, images, toolchains, CLIs, and agent plugins; a governed advisory enters maintenance first, and mutation and generic vendor, release, deployment, Git, PR, or review work are excluded.
Pinned to revision 4a40c0d3cfa8, so it is the text this page describes rather than whatever the author pushed since.
Files
- skills/assessing-third-party-components/SKILL.md
- skills/assessing-third-party-components/agents/openai.yaml
- skills/assessing-third-party-components/references/component-clearance-contract.md
- skills/assessing-third-party-components/references/component-policy-contract.md
Every link opens the file at its source, pinned to the revision this page describes.