auditing-supply-chain
Installation
SKILL.md
Auditing Supply Chain
Your build pipeline runs more untrusted code than your application does. A single unpinned action, a postinstall script, or a workflow with a writable token is a path from a stranger's commit to your production artifacts and your signing keys.
When to Use
- Assessing risk from third-party dependencies in an application
- Reviewing CI/CD pipelines, GitHub Actions, and release automation
- Investigating a suspicious or malicious package
- Producing or reviewing an SBOM
- Hardening build provenance and artifact signing
- Responding to a disclosed upstream compromise