What problem does it solve?
Accepting OPL agent packages without verifying trust evidence like manifest digests, provenance, and dependency references can lead to security vulnerabilities, broken workflows, or unvetted code entering your registry or runtime. This Skill eliminates that risk by providing a structured, non-mutating review process for package trust before any install, sync, or registry action is taken.
Core Features & Use Cases
- Trust Evidence Inspection: Review manifest digests, carrier exposure, dependency references, provenance records, and registry install claims for any OPL agent package.
- Risk Classification: Identify and flag common trust gaps including missing manifest digests, dependency reference gaps, ambiguous carrier exposure, or overclaims of install readiness.
- Use Case: OPL platform operators or package owners can use this Skill to vet third-party agent packages before approving their registry entry or allowing installation on user systems.
Quick Start
Use the opl-agent-package-trust-reviewer skill to assess the trust evidence for the new clinical-trial-agent package before approving its addition to the OPL registry.