github-supply-chain-hardening-analysis
Installation
SKILL.md
github-supply-chain-hardening-analysis
Purpose
This skill performs read-only GitHub organization or personal repository supply-chain and hardened SDLC analysis while preserving the agent context window.
It:
- Discovers available GitHub tokens from
GITHUB_TOKENandgh auth tokenwithout printing token values. - Prints only token metadata: source, non-secret token identifier, account, visible orgs, OAuth scopes, and repository permission summaries.
- Discovers repositories owned by either a GitHub organization or a GitHub personal account.
- Skips archived repositories and forks, reporting each breakdown separately.
- Performs read-only GitHub supply-chain and hardened SDLC analysis.
- Delegates repository-scale work to colocated
scripts/gh_orchestrator.py. - Generates one OpenSpec-style remediation proposal per active repository.
- Runs OpenSSF Scorecard on each analyzed repository and uses the results as evidence for remediation priorities.
- Saves generated proposals under
./proposals/relative to the skill directory unless another output directory is provided. - Avoids loading repository-scale loops, clone contents, tokens, and file traversal into the LLM context window.