Supply Chain Security Watch

On-demand Category 1 researcher for software supply-chain security — SBOM standards (CycloneDX, SPDX), SLSA framework, Sigstore, in-toto, OpenSSF Scorecard, npm / PyPI / Maven malware trends, and major supply-chain incidents. Output at vault/research/supply-chain/YYYY-MM-DD-{slug}.md. Composes with sbom-reviewer (control side), daily-cve-digest (active matching side), and actions-workflow-hardener (workflow side). The Mini Shai-Hulud research at [[2026-06-20-actions-hardening-post-shai-hulud]] is the kind of output this skill produces on demand. Use when the user asks to research a supply-chain security standard, framework, ecosystem trend, or landscape question on demand — producing a fresh, cited research note — not for the scheduled stack-matched CVE roundup (daily-cve-digest), auditing a specific SBOM (sbom-reviewer), or dissecting one specific incident (incident-postmortem-research).

themarmack bf6115f 4.8 KB Updated

File contents

themarmack/research-bot/tree/main/.claude/skills/supply-chain-security-watch commit bf6115f67c

Frequently asked questions

npx skillmds@latest add themarmack/supply-chain-security-watch