github-supply-chain-hardening-analysis

Installation
SKILL.md

github-supply-chain-hardening-analysis

Purpose

This skill performs read-only GitHub organization or personal repository supply-chain and hardened SDLC analysis while preserving the agent context window.

It:

  • Discovers available GitHub tokens from GITHUB_TOKEN and gh auth token without printing token values.
  • Prints only token metadata: source, non-secret token identifier, account, visible orgs, OAuth scopes, and repository permission summaries.
  • Discovers repositories owned by either a GitHub organization or a GitHub personal account.
  • Skips archived repositories and forks, reporting each breakdown separately.
  • Performs read-only GitHub supply-chain and hardened SDLC analysis.
  • Delegates repository-scale work to colocated scripts/gh_orchestrator.py.
  • Generates one OpenSpec-style remediation proposal per active repository.
  • Runs OpenSSF Scorecard on each analyzed repository and uses the results as evidence for remediation priorities.
  • Saves generated proposals under ./proposals/ relative to the skill directory unless another output directory is provided.
  • Avoids loading repository-scale loops, clone contents, tokens, and file traversal into the LLM context window.
Installs
3
First Seen
Jul 19, 2026
github-supply-chain-hardening-analysis — richardslater/skills