cicd-posture

Generate deterministic CI/CD and supply chain posture assessments from Endor and GitHub evidence.

10|2|Updated May 4, 2026
One-click install
npx skills add https://github.com/endorlabs/endor-labs-agent-kit --skill cicd-posture
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: cicd-posture
Source: https://github.com/endorlabs/endor-labs-agent-kit/tree/main/gemini/cicd-posture
Command: npx skills add https://github.com/endorlabs/endor-labs-agent-kit --skill cicd-posture

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill requires endorctl, github-cli, and includes scripts (resource) and references (resource) components.

What problem does it solve?

This Skill provides a read-only assessment of the CI/CD and supply chain posture for a specified namespace, GitHub organization, repository set, or current repository.

Core Features & Use Cases

  • CI/CD Posture Assessment: Combines Endor SCPM, CI/CD, GitHub Actions, and supply-chain findings with read-only GitHub configuration evidence.
  • Deterministic Scores: Returns deterministic scores, critical overrides, evidence queries, and data gaps without mutating any system state.
  • Use Case: Use this Skill to assess the posture of a specific namespace or GitHub organization, providing a comprehensive view of the CI/CD and supply chain health.

Quick Start

Use the @cicd-posture skill to assess the CI/CD and supply chain posture for the Endor namespace <namespace>.

Frequently Asked Questions about cicd-posture

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I assess CI/CD and supply chain posture for a GitHub organization?

You can assess CI/CD and supply chain posture by combining Endor findings with read-only GitHub configuration evidence and local CI file inspection to generate deterministic scores, critical overrides, and data gaps for your organization.

What is CI/CD and supply chain posture assessment?

CI/CD and supply chain posture assessment combines Endor supply chain findings, GitHub Actions configurations, and local CI file evidence to output deterministic security scores, critical overrides, and data gaps without mutating any system state.

Do I need Endor and GitHub CLI access to check supply chain posture?

Yes, assessing supply chain posture requires Endor access for SCPM findings, GitHub access for configuration evidence, and local CI file access when applicable, utilizing the endorctl and github-cli dependencies to gather and evaluate evidence.

Can I evaluate CI/CD posture without modifying my repository configuration?

Yes, CI/CD posture assessment is strictly read-only and does not mutate any system state, safely combining Endor findings and GitHub configuration evidence to return deterministic scores, critical overrides, and data gaps.

What's the best way to identify data gaps in my GitHub Actions supply chain?

The best way to identify supply chain data gaps is to combine Endor findings with GitHub Actions configuration evidence using this Skill, which outputs a deterministic assessment highlighting missing evidence queries, critical overrides, and security scores.

Why does my CI/CD posture assessment show missing evidence queries?

CI/CD posture assessments show missing evidence queries when there are data gaps in the combined Endor findings, GitHub configuration evidence, or local CI file inspection, indicating insufficient access permissions or missing repository configuration data.