supply-chain-audit

Installation
SKILL.md

What this skill does

Performs a comprehensive software supply chain security assessment: inventories all dependencies, runs SCA tooling across detected ecosystems, evaluates SLSA framework compliance (Levels 1–4), generates a CycloneDX/SPDX SBOM, and analyzes exposure across four attack vector categories (dependency, build pipeline, source code, distribution). Outputs a risk findings table, SLSA compliance matrix, and prioritized remediation roadmap.

When to use

  • When evaluating supply chain risk before a major release or acquisition
  • When responding to a supply chain incident (SolarWinds/XZ-style events)
  • When achieving SLSA Level 2+ compliance for a service
  • When preparing a software bill of materials for a customer or regulator
  • When auditing third-party code integrated into your codebase

Prerequisites

Installs
5
GitHub Stars
21
First Seen
May 9, 2026
supply-chain-audit — woohyun212/security-skill