product image
product image
product image

SSDF attestation audit Skill for Claude

$12

Finds each GitHub Actions line that contradicts your SSDF attestation

On one 21-line deploy workflow it printed 8 findings (7 errors, 1 warning) from 14 rules, each with file:line, the SSDF practice and the attestation section.

Who it’s for
For platform and DevSecOps engineers at software vendors who must sign the secure software development attestation for federal customers.

What breaks, and when
A missing SBOM (PS.3.2), no vulnerability check (RV.1.1) or a secret in the build log (PO.5.2) contradicts what the attestation says; the scan dates it against fiscal-year end 2027-09-30.

What you get
• A scanner Claude runs over every workflow file - not a guess from memory

See it first
The real output of the bundled example is on getreadystack.com/skills/ssdf-attestation-audit/ — free, no sign-up, so you see what it finds before you pay.

Install in 30 seconds
Unzip into ~/.claude/skills/, then ask Claude Code: “We have to sign the SSDF attestation for a federal customer. Can you check whether our GitHub Actions CI is ready? Don’t edit anything yet.”. Needs Node 16+.

What it does not do
Reads workflow YAML only; it does not call GitHub, resolve tags to SHAs or fill in the attestation form.

FAQ
Q: How is this different from asking Claude without the skill?
A: The skill carries a dated rule table and a scanner that reads every file, so Claude quotes the exact date and line instead of guessing from memory.
Q: How do I get the files?
A: In your Whop library after paying: the lesson “ssdf-attestation-audit.zip”.