$ npx skills add https://github.com/wgpsec/aboutsecurity --skill supply-chain-attack
核心思路:不攻击目标本身,攻击目标信任的上游依赖/构建流程