moai-artifacts-builder

Automate artifact governance and lifecycle management with SBOM generation and compliance checks.

Updated Nov 24, 2025
One-click install
npx skills add https://github.com/jg-chalk-io/Nora-LiveKit --skill moai-artifacts-builder
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: moai-artifacts-builder
Source: https://github.com/jg-chalk-io/Nora-LiveKit/tree/main/.claude/skills/moai-artifacts-builder
Command: npx skills add https://github.com/jg-chalk-io/Nora-LiveKit --skill moai-artifacts-builder

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Manages artifacts with governance, SBOM, provenance, and supply chain security patterns.

Core Features & Use Cases

  • Artifact Types: 7 enterprise formats (containers, packages, binaries, docs, config, tests, source archives)
  • SBOM & Provenance: CycloneDX/ SPDX, SBOM validation.
  • Governance: RBAC, audit trails, immutability.

Quick Start

Define a container artifact and generate an SBOM, then sign and publish with provenance.

Frequently Asked Questions about moai-artifacts-builder

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I generate an SBOM for container images and software packages?

SBOM generation automates the creation of software component inventories in CycloneDX or SPDX formats. This Skill generates SBOMs across container images, language packages, binaries, and source archives, enabling visibility into dependencies and compliance with supply chain security standards.

What's the best way to implement artifact signing and provenance tracking?

Artifact signing and provenance tracking verify integrity and document the origin of software artifacts throughout their lifecycle. This Skill automates signature verification, provenance metadata attachment, and end-to-end governance across creation, validation, storage, and deployment workflows.

How can I enforce role-based access control and audit trails for artifact management?

RBAC and audit trails implement governance by restricting who accesses artifacts and recording all actions for compliance. This Skill applies immutable RBAC controls and comprehensive audit logging to enforce SOC 2 and ISO 27001 standards across artifact lifecycles.

Can I automate vulnerability scanning and compliance checks for multiple artifact types?

Automated vulnerability scanning and compliance checks detect security risks and policy violations without manual review. This Skill scans seven enterprise artifact formats—containers, packages, binaries, documentation, configuration, test reports, and source archives—against compliance standards.

Does this support both CycloneDX and SPDX SBOM formats?

SBOM format support ensures compatibility with enterprise tooling and standards bodies. This Skill generates and validates SBOMs in both CycloneDX and SPDX formats, enabling integration with downstream security and compliance platforms.

Why use centralized artifact governance instead of per-tool validation?

Centralized governance replaces fragmented, tool-specific validation with unified policies and visibility. This Skill manages artifact validation, storage, and retirement in a single system, reducing configuration drift and ensuring consistent security across all artifact types.