sca-security

Installation
SKILL.md

Software Composition Analysis (SCA)

Router skill for dependency security: SBOM generation, multi-source vuln correlation, license compliance, supply chain review, and reachability-driven triage. Optimized for polyglot repositories and PR-time lockfile review. Load the relevant workflow + ecosystem reference on demand — do not read the whole skill up front.

When to Use

  • Scanning project dependencies for known vulnerabilities (CVE / GHSA / OSV)
  • Generating an SBOM (CycloneDX or SPDX) for a repo, container, or binary
  • Reviewing a PR's lockfile delta for new vulns, license changes, malicious packages
  • Reachability analysis to prioritize the 5-15% of findings that are actually exploitable
  • License compliance against an allow/deny policy
  • Supply chain review: typosquatting, dependency confusion, malicious package triage
  • Ecosystem-specific audits: npm, yarn, pnpm, pip, poetry, Maven, Gradle, Go, Cargo, Ruby, Composer
  • CI/CD integration for continuous dependency scanning

Trigger Phrases

  • "scan dependencies", "check package vulnerabilities", "run npm audit"
  • "generate SBOM", "CycloneDX", "SPDX"
Related skills

More from hardw00t/ai-security-arsenal

Installs
6
GitHub Stars
39
First Seen
Feb 2, 2026