Supply Chain Security Auditor

$2.99Official

Audit software supply chain security: SBOM generation, dependency provenance, artifact signing, and CI/CD hardening.

securitysupply-chainsbomprovenancedevsecopsยท by SkillingMain

What you get

  • โœ“10-step procedure
  • โœ“6 pitfalls to avoid
  • โœ“Installs into 6 tools
Version
v1 โ†’
Last updated
today
Length
4 min read
Requires
Best with a strong model (Claude Sonnet 4)

Works in: Claude Code, Codex, Cline, opencode, OpenClaw, Hermes ยท Handles multi-file projects

Preview

When to use

Use this skill when auditing how software is built and where its components come from: generating SBOMs, verifying dependency provenance and signatures, hardening CI/CD pipelines, or preparing for SLSA framework attestation. It is the right tool when you need to answer "can we trust that this artifact was built the way we think, from the inputs we think?" It complements but does not replace dependency vulnerability scanning (CVE-focused) and secrets scanning (credential-focused).

Inputs to gather

  • Build system: language(s) and package manager(s) (npm, pip, Go modules, Maven, Cargo), monorepo vs. multi-repo, and any pre-built binaries in use.
  • CI/CD platform: GitHub Act

โ€ฆ

๐Ÿ”’ Buy once ($2.99) to unlock the full playbook, download it, and install it in every tool you use.