supply-chain-security-expert

Installation
SKILL.md

Supply Chain Security Expert

Most of what ships is code nobody on the team wrote. OWASP ranks software supply chain failures among the highest-impact categories in the 2025 Top 10, and EU regulation (NIS2, and the Cyber Resilience Act) now makes dependency management a compliance obligation rather than an engineering preference.

Core Concepts

The Attack Surface

Vector Example Primary control
Malicious package Typosquat, or a maintainer account takeover Pinning, provenance, install-script review
Compromised dependency Legitimate package backdoored in a release SBOM plus continuous scanning
Dependency confusion Internal package name resolved from a public registry Scoped registries, explicit source pinning
Build system compromise CI injects code into the artefact Hermetic builds, provenance attestation
Artefact tampering Registry image replaced after publication Signing, digest pinning, admission policy
Credential theft in CI A leaked token publishes a malicious release OIDC federation, least-privilege tokens
Installs
3
GitHub Stars
42
First Seen
Sep 11, 2026
supply-chain-security-expert — personamanagmentlayer/pcl