Supply Chain

Detects supply-chain risks in dependency manifests, lockfiles, install commands, and CI pipelines — missing lockfiles, absent vulnerability scanners, unverified installs, install hooks that pipe remote content to a shell, and AI-hallucinated package names. Use when writing package install commands, dependency manifests, CI/CD configs, build scripts, or code that loads external packages.

thejefflarson 69ccae2 4.0 KB Updated

File contents

thejefflarson/soundcheck/tree/main/.claude/skills/supply-chain commit 69ccae24d5

Frequently asked questions

npx skillmds@latest add thejefflarson/supply-chain