auditing-supply-chain

Installation
SKILL.md

Auditing Supply Chain

Your build pipeline runs more untrusted code than your application does. A single unpinned action, a postinstall script, or a workflow with a writable token is a path from a stranger's commit to your production artifacts and your signing keys.

When to Use

  • Assessing risk from third-party dependencies in an application
  • Reviewing CI/CD pipelines, GitHub Actions, and release automation
  • Investigating a suspicious or malicious package
  • Producing or reviewing an SBOM
  • Hardening build provenance and artifact signing
  • Responding to a disclosed upstream compromise

When NOT to Use

Installs
22
GitHub Stars
146
First Seen
Jul 30, 2026
auditing-supply-chain — trilwu/secskills