netresearch / agent-enterprise-readiness
Netresearch AI skill for enterprise security assessment, SLSA compliance and quality automation
Package info
github.com/netresearch/enterprise-readiness-skill
Language:Shell
Type:ai-agent-skill
pkg:composer/netresearch/agent-enterprise-readiness
Requires
Requires (Dev)
None
Suggests
None
Provides
None
Conflicts
None
Replaces
- dev-main
- v4.18.3
- v4.18.2
- v4.18.1
- v4.18.0
- v4.17.5
- v4.17.4
- v4.17.3
- v4.17.2
- v4.17.1
- v4.17.0
- v4.16.1
- v4.16.0
- v4.15.2
- v4.15.1
- v4.15.0
- v4.14.0
- v4.12.1
- v4.12.0
- v4.11.0
- v4.10.0
- v4.9.0
- v4.8.0
- v4.7.1
- v4.7.0
- v4.6.0
- v4.5.0
- v4.4.3
- v4.4.2
- v4.4.1
- v4.4.0
- v4.3.2
- v4.3.1
- v4.3.0
- v4.2.1
- v4.2.0
- v4.1.0
- v4.0.0
- v3.9.0
- v3.8.2
- v3.8.1
- v3.8.0
- v3.7.1
- v3.7.0
- dev-docs/node-ci-sonar-codeql-checklist
- dev-fix/codeowner-review-incompatibility
- dev-fix/skill-quality-standards
- dev-chore/scorecard-optimization
- dev-feat/conversation-resolution
This package is auto-updated.
Last update: 2026-10-01 22:28:29 UTC
README
Enterprise Readiness Skill
Netresearch AI skill for assessing and enhancing software projects to meet enterprise-grade standards for security, quality, and automation.
🔌 Compatibility
This is an Agent Skill following the open standard originally developed by Anthropic and released for cross-platform use.
Supported Platforms:
- ✅ Claude Code (Anthropic)
- ✅ Cursor
- ✅ GitHub Copilot
- ✅ Other skills-compatible AI agents
Skills are portable packages of procedural knowledge that work across any AI agent supporting the Agent Skills specification.
Features
- OpenSSF Framework Alignment - Complete coverage across Scorecard, Best Practices Badge (Passing/Silver/Gold), SLSA, and S2C2F
- Dynamic Scoring - Fair cross-stack assessment with platform/language-specific criteria
- Supply Chain Security - SLSA provenance, artifact signing, SBOM generation, dependency scanning
- Quality Gates - Testing layers, coverage thresholds, static analysis, secret scanning
- Automation Scripts - Ready-to-use scripts for security hardening and compliance checks
- Badge Progression - Guided path from Passing → Silver → Gold certification
Installation
Marketplace (Recommended)
Add the Netresearch marketplace once, then browse and install skills:
# Claude Code
/plugin marketplace add netresearch/claude-code-marketplace
/plugin install enterprise-readiness@netresearch-claude-code-marketplace
Without a marketplace
Since Claude Code 2.1.157 a plugin directory under your personal skills directory loads on its own, including the commands this repo ships:
mkdir -p ~/.claude/skills git clone https://github.com/netresearch/enterprise-readiness-skill.git \ ~/.claude/skills/enterprise-readiness
It loads as enterprise-readiness@skills-dir on the next session. Update with git -C ~/.claude/skills/enterprise-readiness pull and start a new session; remove it by deleting the directory. This route has no claude plugin update.
npx (skills.sh)
Install with any Agent Skills-compatible agent:
npx skills add https://github.com/netresearch/enterprise-readiness-skill --skill enterprise-readiness
Limitation:
npx skillsinstallsSKILL.md-based skills only. This repo also shipscommands, which it does not install — use the marketplace or the skills directory for those.
Download Release
Download the latest release and extract to your agent's skills directory.
Git Clone
git clone https://github.com/netresearch/enterprise-readiness-skill.git
Composer (PHP Projects)
composer require netresearch/enterprise-readiness-skill
Requires netresearch/composer-agent-skill-plugin.
npm (Node Projects)
npm install --save-dev \ @netresearch/agent-skill-coordinator \ github:netresearch/enterprise-readiness-skill
Requires @netresearch/agent-skill-coordinator, which discovers the skill in node_modules and registers it in AGENTS.md via a postinstall hook. For pnpm, also allowlist the coordinator's postinstall:
{
"pnpm": {
"onlyBuiltDependencies": ["@netresearch/agent-skill-coordinator"]
}
}
Usage
The skill triggers on keywords like:
- "enterprise readiness", "production ready"
- "OpenSSF", "security scorecard", "best practices badge"
- "SLSA", "supply chain security", "SBOM"
- "quality gates", "CI/CD hardening"
Example Prompts
"Assess this project for enterprise readiness"
"What's needed for OpenSSF Best Practices Silver badge?"
"Help me reach SLSA Level 2"
"Set up supply chain security for this Go project"
Structure
enterprise-readiness-skill/
├── skills/enterprise-readiness/
│ ├── SKILL.md # AI instructions
│ ├── checkpoints.yaml # Assessment checkpoints
│ ├── evals/evals.json # Evaluation cases
│ ├── references/ # OpenSSF criteria, guides, playbooks
│ │ ├── general.md # Universal checks
│ │ ├── github.md # GitHub-specific checks
│ │ ├── go.md # Go-specific checks
│ │ ├── openssf-badge-silver.md
│ │ ├── openssf-badge-gold.md
│ │ └── …
│ └── scripts/ # check-*.sh, verify-*.sh, add-spdx-headers.sh,
│ # analyze-bus-factor.sh, submit-badges.py
├── assets/
│ ├── templates/ # Governance, roadmap, architecture, CoC, audit, badge-exception templates
│ └── workflows/ # CodeQL, Scorecard, SLSA, dependency review, DCO workflows
├── commands/ # /audit and /slsa slash commands
├── outputStyles/ # Report output style
├── tests/ # Behaviour tests for the scripts
├── docs/ # Architecture, security assurance case, execution plans
├── README.md # This file
├── LICENSE-MIT # Code license (MIT)
├── LICENSE-CC-BY-SA-4.0 # Content license (CC-BY-SA-4.0)
├── composer.json # Composer distribution
└── package.json # npm distribution
Contributing
Contributions welcome! Please submit PRs for:
- Additional platform support (GitLab, Bitbucket)
- New language-specific checks
- Script improvements
- Documentation updates
Development and tests
Every script under skills/enterprise-readiness/scripts/ and the version check the pre-push hook runs (Build/Scripts/check-plugin-version.sh) has a behaviour test in tests/, named after the script (tests/<script>.sh, and tests/test_submit_badges.py for submit-badges.py). The tests build fixture directories and throw-away git repositories in a temporary directory and run the real script against them, checking exit codes and output: pass and fail verdicts, thresholds, excluded directories, signed and unsigned tags, and error paths. go and gh are replaced by stubs, and submit-badges.py talks to a fake HTTP opener, so no test calls a Go toolchain, GitHub or bestpractices.dev. Shared helpers are in tests/helpers.bash.
The tests need bash, git, jq, make, ssh-keygen, gpg and python3. Run them from the repository root:
for t in tests/*.sh; do bash "$t" || exit 1; done python3 tests/test_submit_badges.py
Each shell test prints ok or FAIL per case, with the captured output of a failing case indented below it, and ends with a passed, failed tally; it exits non-zero if any case failed. The Python test uses unittest and reports failures the same way. CI runs the same files on every pull request and on pushes to main (.github/workflows/tests.yml), and fails if no test file is found. The pre-commit hooks in .pre-commit-config.yaml run the linters that lint.yml runs in CI.
New or changed behaviour in a script needs a test case in tests/ in the same pull request.
Governance and policies
This repository follows the Netresearch organisation policies:
- Governance: who decides, how changes are accepted, and how disputes are resolved.
- Roadmap: planned and excluded work for the coming year.
- Handling of dependency and code analysis findings: thresholds, deadlines and exceptions for dependency and static-analysis findings.
- Secret management: how CI and release credentials are stored, accessed and rotated.
- Access roster: the accounts that can change code, settings or releases of this repository, with their access level.
- Security assurance case: threat model, trust boundaries and countermeasures for this skill.
Every pull request to main runs these security checks (.github/workflows/security.yml): dependency review, Composer Audit, Opengrep (static analysis), Betterleaks (secret scanning) and zizmor (workflow analysis). CodeQL analyses the GitHub Actions workflows and the Python code through the repository's default setup. The only secrets this repository's workflows use are the organisation GitHub App credentials passed to the dependency auto-merge job (auto-merge-deps.yml); releases are signed with short-lived OIDC credentials (release.yml).
License
This project uses split licensing:
- Code (scripts, workflows, configs): MIT
- Content (skill definitions, documentation, references): CC-BY-SA-4.0
See the individual license files for full terms.
Credits
Developed and maintained by Netresearch DTT GmbH.
Made with ❤️ for Open Source by Netresearch