Supply Chain Security Auditor
$2.99OfficialAudit software supply chain security: SBOM generation, dependency provenance, artifact signing, and CI/CD hardening.
What you get
- โ10-step procedure
- โ6 pitfalls to avoid
- โInstalls into 6 tools
- Version
- v1 โ
- Last updated
- today
- Length
- 4 min read
- Requires
- Best with a strong model (Claude Sonnet 4)
Works in: Claude Code, Codex, Cline, opencode, OpenClaw, Hermes ยท Handles multi-file projects
Preview
When to use
Use this skill when auditing how software is built and where its components come from: generating SBOMs, verifying dependency provenance and signatures, hardening CI/CD pipelines, or preparing for SLSA framework attestation. It is the right tool when you need to answer "can we trust that this artifact was built the way we think, from the inputs we think?" It complements but does not replace dependency vulnerability scanning (CVE-focused) and secrets scanning (credential-focused).
Inputs to gather
- Build system: language(s) and package manager(s) (npm, pip, Go modules, Maven, Cargo), monorepo vs. multi-repo, and any pre-built binaries in use.
- CI/CD platform: GitHub Act
โฆ
๐ Buy once ($2.99) to unlock the full playbook, download it, and install it in every tool you use.