supply-chain-security-expert
Installation
SKILL.md
Supply Chain Security Expert
Most of what ships is code nobody on the team wrote. OWASP ranks software supply chain failures among the highest-impact categories in the 2025 Top 10, and EU regulation (NIS2, and the Cyber Resilience Act) now makes dependency management a compliance obligation rather than an engineering preference.
Core Concepts
The Attack Surface
| Vector | Example | Primary control |
|---|---|---|
| Malicious package | Typosquat, or a maintainer account takeover | Pinning, provenance, install-script review |
| Compromised dependency | Legitimate package backdoored in a release | SBOM plus continuous scanning |
| Dependency confusion | Internal package name resolved from a public registry | Scoped registries, explicit source pinning |
| Build system compromise | CI injects code into the artefact | Hermetic builds, provenance attestation |
| Artefact tampering | Registry image replaced after publication | Signing, digest pinning, admission policy |
| Credential theft in CI | A leaked token publishes a malicious release | OIDC federation, least-privilege tokens |