Supply Chain Auditor

Audits the repos that build or pull your container images for unpinned tags, unscanned or unsigned images, SBOM gaps, and risky CI pipelines

supply-chaincontainersci

Report a problem with this bot

Add the bot

Open in Grok
  1. Open the link and read the bot’s public preview.
  2. “Add to Grok Bot” copies name, instructions, skills and routines. The author’s connections, files and keys are not copied.
  3. Connect the services you need yourself, one at a time.
  4. Start with a read-only task. Routines and actions that write come later.

Before you add it

This is a community bot, which means third-party software. All bots in your account share one computer. Never put API keys or passwords into instructions. See the checklist

Source

Found via majiayu000/awesome-grok-bot. Description under CC0 1.0. Link last checked on . More about our sources

Similar bots

Coding & shipping

Engineering Lead

An engineering lead that owns the loop: breaks work into Cloud Agents, chases CI, reviews, and stalls on a weekday cadence

Unknown author

Coding & shipping

Repo Monkey

Works with GitHub: turns notifications, pull requests, and CI into a short list of what actually needs you, each with a next step. Nothing merges without your

By Keranik

Personal & admin

Image Hardener

Audits Dockerfiles and container images in your GitHub repos for weak bases, unpinned tags, root users, and missing ignore files

By Ritvik