Skill Scanner
getsentry/skills
Scan agent skills for security issues. An agent skill from getsentry/skills.
Supply chain mapping, supplier dependency analysis, customer concentration, geographic concentration, bottleneck identification, supply chain risk, logistics network, sourcing strategy, inventory…
$ npx skills add agentii-ai/agentii-investment-intelligence --skill supply-chain -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install agentii-ai/agentii-investment-intelligence supply-chain --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/agentii-ai/agentii-investment-intelligence.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/vertical-plugins/industry-analysis/skills/agentii/supply-chain .claude/skills/supply-chain && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "supply-chain" agent skill from https://github.com/agentii-ai/agentii-investment-intelligence/tree/main/plugins/vertical-plugins/industry-analysis/skills/agentii/supply-chain into .claude/skills/supply-chain/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "supply-chain", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/agentii-ai/agentii-investment-intelligence/tree/main/plugins/vertical-plugins/industry-analysis/skills/agentii/supply-chainType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add agentii-ai/agentii-investment-intelligence --skill supply-chain -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install agentii-ai/agentii-investment-intelligence supply-chain --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/agentii-ai/agentii-investment-intelligence.git skills-src && mkdir -p .agents/skills && cp -r skills-src/plugins/vertical-plugins/industry-analysis/skills/agentii/supply-chain .agents/skills/supply-chain && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "supply-chain" agent skill from https://github.com/agentii-ai/agentii-investment-intelligence/tree/main/plugins/vertical-plugins/industry-analysis/skills/agentii/supply-chain into .agents/skills/supply-chain/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "supply-chain", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add agentii-ai/agentii-investment-intelligence --skill supply-chain -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install agentii-ai/agentii-investment-intelligence supply-chain --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/agentii-ai/agentii-investment-intelligence.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/plugins/vertical-plugins/industry-analysis/skills/agentii/supply-chain .cursor/skills/supply-chain && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "supply-chain" agent skill from https://github.com/agentii-ai/agentii-investment-intelligence/tree/main/plugins/vertical-plugins/industry-analysis/skills/agentii/supply-chain into .cursor/skills/supply-chain/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "supply-chain", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/agentii-ai/agentii-investment-intelligence.git --path plugins/vertical-plugins/industry-analysis/skills/agentii/supply-chain--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add agentii-ai/agentii-investment-intelligence --skill supply-chain -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install agentii-ai/agentii-investment-intelligence supply-chain --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/agentii-ai/agentii-investment-intelligence.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/plugins/vertical-plugins/industry-analysis/skills/agentii/supply-chain .gemini/skills/supply-chain && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "supply-chain" agent skill from https://github.com/agentii-ai/agentii-investment-intelligence/tree/main/plugins/vertical-plugins/industry-analysis/skills/agentii/supply-chain into .gemini/skills/supply-chain/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "supply-chain", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install agentii-ai/agentii-investment-intelligence supply-chainInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add agentii-ai/agentii-investment-intelligence --skill supply-chain -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/agentii-ai/agentii-investment-intelligence.git skills-src && mkdir -p .github/skills && cp -r skills-src/plugins/vertical-plugins/industry-analysis/skills/agentii/supply-chain .github/skills/supply-chain && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "supply-chain" agent skill from https://github.com/agentii-ai/agentii-investment-intelligence/tree/main/plugins/vertical-plugins/industry-analysis/skills/agentii/supply-chain into .github/skills/supply-chain/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "supply-chain", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add agentii-ai/agentii-investment-intelligence --skill supply-chain -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install agentii-ai/agentii-investment-intelligence supply-chain --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/agentii-ai/agentii-investment-intelligence.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/plugins/vertical-plugins/industry-analysis/skills/agentii/supply-chain .opencode/skills/supply-chain && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "supply-chain" agent skill from https://github.com/agentii-ai/agentii-investment-intelligence/tree/main/plugins/vertical-plugins/industry-analysis/skills/agentii/supply-chain into .opencode/skills/supply-chain/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "supply-chain", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
supply-chainSupply chain mapping, supplier dependency analysis, customer concentration, geographic concentration, bottleneck identification, supply chain risk, logistics network, sourcing strategy, inventory…
Supply Chain is an agent skill from agentii-ai/agentii-investment-intelligence. Supply chain mapping, supplier dependency analysis, customer concentration, geographic concentration, bottleneck identification, supply chain risk, logistics network, sourcing strategy, inventory management, vertical integration analysis
Its SKILL.md is about 1.8k tokens, which your agent loads only when the skill is triggered. The skill folder holds 5 other files, including reference files (for example `references/knowledge-frameworks.md`, `references/methodology.md` and `references/modes.md`).
It sits in Security, covering Supply chain security. The repository describes itself as: Claude-type skills for institutional equity research — 25 AI agent skills with SEC filings, XBRL financials, earnings calendars, DCF/comps/LBO models, and PPT generation. Powered… The licence is Apache-2.0.
5 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 86980e1. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md.
From the folder's file list and the shell code blocks in SKILL.md.
Hosts in commands or code, which the agent is likely to contact:
agentii.aiFrom URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Supply Chain loads about 1.8k tokens when it runs, and up to ~2.7k if it reads all its reference files. Until then it costs about 63 tokens; SKILL.md has 659 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from agentii-ai/agentii-investment-intelligence at commit 86980e1, republished under its Apache-2.0 licence (© agentii-ai). 659 words, ~1,803 tokens.
.claude/skills/supply-chain/SKILL.md (or your agent's skills folder). This skill also uses 4 other files; get the full folder from GitHub.| Parameter | Default Value | Rationale |
|---|---|---|
| ticker | (required) | Stock symbol to analyze |
| lookback_quarters | 4 | Standard lookback for this skill type |
This skill operates with retrieval_scope: unstructured_document_search. It performs unstructured document search at scale via the three-layer retrieval protocol (Layer 1→2→2.5→3), escalating to read_source_deep_outline only when lightweight labels cannot disambiguate pages, plus structured XBRL where needed.
Follows the retrieval strategy decision tree in contracts/retrieval.md. Primary branch: (b)/(c) Unstructured Query via the three-layer protocol. Resolve the canonical ticker first (exact → fuzzy alias → share-class) before any data call.
Default lookback: 4 fiscal quarter(s); maximum: 10. The default balances recency against the trend window this analysis requires.
Per frontmatter allowed_tools:
search_companies — ticker resolution + company context (entity-alias fuzzy match)search_xbrl_facts — primary structured financial facts (is_primary default)search_documents — Layer 1 document discovery (page-level silver records)search_sec_filings — Layer 1 SEC filing metadata indexget_company_financials — consolidated IS/BS/CF highlightslist_coverage — universe-level coverage discoveryread_source_outline — Layer 2 lightweight page map (description + keywords)read_source_deep_outline — Layer 2.5a deep page map (table_titles/drivers/metrics)list_xbrl_concepts — XBRL concept discovery for non-standard line items (namespace param; default us-gaap — use ifrs-full for foreign filers)read_source_pages — Layer 3 deep read of selected pages with table markerssearch_keyword_in_source — Layer 2.5b keyword page filter for large documentsget_company_fiscal_calendar/{ticker} then get_ticker_coverage/{ticker}; route on coverage.search_documents / search_sec_filings to find candidate filings by ticker/form_type/date.read_source_outline/{ticker}/{citation_id} — every description is platform-generated (description_provenance says which kind), so never quote it as the filing's words; a platform_metadata_placeholder means the page was not labelled, which is a reason to read it, not to skip it. Escalate to read_source_deep_outline only when labels can't disambiguate.search_keyword_in_source to narrow documents >50 pages.read_source_pages/{ticker}/{citation_id}?pages=page<N>,... for the 3–5 selected pages only.search_cross_period after fiscal-calendar resolution.## Output File, then append to agentii.md.Write the final deliverable to _cross/{descriptive-slug}_{YYYY-MM-DD_HHMM}_supply-chain_{affix}.md or _sector/{sector_name}/{YYYY-MM-DD_HHMM}_supply-chain_{affix}.md .
{ticker} {citation_id} page<N> citations.Citations & memory: follow contracts/citation-and-memory.md — ≥1 citation per 200 words; every material fact, table row, and metric is immediately followed by its inline clickable https://agentii.ai/v/{ticker}/{citation_id}/{N} link; a bottom Citations section provides a non-duplicative roll-up index; the closing TUI reply includes a compact Key Citations list (headline 5–10 facts) of clickable /v/ URLs; and append the run to agentii.md per contracts/agentii-md-schema.md.
Run canonical pre-flight per contracts/preflight.md.
Include the X-Agentii-Trace header on every tool call per contracts/x-agentii-trace-header.md — carry the _run_id from your first tool result and name yourself (and your parent, if you were spawned).
contracts/memory-load.md.key_metrics, conclusions, facts_count, deducted_count, views_count, citation_count) per contracts/output-frontmatter-schema.md.[FACT]/[DEDUCTED]/[VIEW] — see contracts/snapshot-synthesis.md.sessions/{YYYY-MM-DD}/ and update sessions/INDEX.md per contracts/session-format.md.End the closing chat reply with a compact Key Citations list (headline 5–10 facts), each a clickable https://agentii.ai/v/{ticker}/{citation_id}/{N} link, so the user can cmd+click straight to the exact SEC page. See contracts/citation-and-memory.md.
| Error | Action |
|---|---|
| Ticker not found | Suggest checking spelling or trying list_coverage |
| No data available | Flag in Coverage Gaps, proceed with available data |
| API key invalid | Direct user to agentii.ai/api-keys |
| MCP server unreachable | Retry once; if persistent, halt with AGENTII_MCP_UNREACHABLE |
references/methodology.md — tool fallbacks, retrieval strategy, analysis frameworkreferences/output-structure.md — detailed deliverable sections and ordering© agentii-ai, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 4 other files (references) in plugins/vertical-plugins/industry-analysis/skills/agentii/supply-chain of agentii-ai/agentii-investment-intelligence.
Open the folder on GitHubat commit 86980e1
Supply Chain next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Supply Chain this skillagentii-ai/agentii-investment-intelligence | 207 | — | ~1.8k | Automated safety check: Pass | Apache-2.0 | |
| Skill Scannergetsentry/skills | 1k | 4 repos | ~2.5k | Automated safety check: Warn | Apache-2.0 | |
| Serenity Aleabitoreddityan-labs/serenity-aleabitoreddit | 481 | 1 repos | ~3.3k | Automated safety check: Pass | None | |
| Eu CraSushegaad/Claude-Skills-Governance-Risk-and-Compliance | 946 | 1 repos | ~4k | Automated safety check: Pass | MIT | |
| Kesekit Checkcdppcorp/KESE-KIT | 360 | — | ~1.3k | Automated safety check: Pass | MIT | |
| Bom Auditcdxgen/cdxgen | 1.1k | — | ~2.4k | Automated safety check: Pass | Apache-2.0 |
getsentry/skills
Scan agent skills for security issues. An agent skill from getsentry/skills.
yan-labs/serenity-aleabitoreddit
Apply trader Serenity's (@aleabitoreddit) AI/semiconductor supply-chain analytical lens to US-stock ideas and market judgment.
Sushegaad/Claude-Skills-Governance-Risk-and-Compliance
Expert EU Cyber Resilience Act (CRA) advisor for Regulation (EU) 2024/2847 — mandatory cybersecurity and vulnerability handling requirements for all products with digital elements (PDEs) sold in the…
cdppcorp/KESE-KIT
Run a pre-deployment security compliance checklist based on KISA guidelines.
cdxgen/cdxgen
Runs supply-chain risk analysis on CycloneDX BOMs with cdx-audit predictive auditing and cdxgen --bom-audit embedded rules, covering npm and PyPI package compromise posture, CI permission risk…
jdx/packslip
Configure signed release manifests with packslip: add the jdx/packslip action or packslip create to a release workflow, declare completions, man pages, CLI specs, skills, and SBOMs as resources, and…
agentii-ai/agentii-investment-intelligence
Adversarial verification of research theses — cross-run/cross-thesis contradiction via the entity index, pre-mortem (Klarman/Kahneman: assume the loss already happened, reverse the path), inversion…
agentii-ai/agentii-investment-intelligence
Chart pattern recognition, price action patterns, candlestick signal bars, pullback bar counting H1/H2/H3/H4, trend channels, micro channels, trading ranges, breakouts, major trend reversals 5-step…
agentii-ai/agentii-investment-intelligence
The research-domain clarification skill — find underspecified items in a thesis spec.md (prose wrongif, universe rows without rationale, missing budget/expiry/pins, ambiguous pillars), ask the human…
agentii-ai/agentii-investment-intelligence
Scaffold and amend the L1 Investment Constitution — [ALLCAPS] placeholder bootstrap, SemVer bump rules, Sync Impact Report, MINOR/MAJOR re-examination dispatch after the gate-5 budget confirm.
agentii-ai/agentii-investment-intelligence
Append-only gap closure and the cadence engine for research theses.
agentii-ai/agentii-investment-intelligence
Execute research tasks — checklist soft gate, phase dispatch with explicit thesisdir, budget enforcement (halt + approval card on overrun), skillpin recording (versionhash content-hashed per skill…
Categories
Supply chain mapping, supplier dependency analysis, customer concentration, geographic concentration, bottleneck identification, supply chain risk, logistics network, sourcing strategy, inventory…. Supply Chain is an agent skill from agentii-ai/agentii-investment-intelligence.
Supply Chain fits situations like: tasks that involve Supply chain security.
Run `npx skills add agentii-ai/agentii-investment-intelligence --skill supply-chain -a claude-code`. Or copy the skill folder (plugins/vertical-plugins/industry-analysis/skills/agentii/supply-chain in agentii-ai/agentii-investment-intelligence) into .claude/skills/supply-chain in your project. Claude Code loads it when a task matches its description.
Run `npx skills add agentii-ai/agentii-investment-intelligence --skill supply-chain -a codex`. Or copy the skill folder (plugins/vertical-plugins/industry-analysis/skills/agentii/supply-chain in agentii-ai/agentii-investment-intelligence) into .agents/skills/supply-chain in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add agentii-ai/agentii-investment-intelligence --skill supply-chain -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/supply-chain, .gemini/skills/supply-chain, .github/skills/supply-chain and .opencode/skills/supply-chain in your project.
SKILL.md names no scripts, command-line tools or credentials: Supply Chain is instructions for the agent only.
SKILL.md names 1 domain. In commands or code: agentii.ai; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Supply Chain is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 1.8k tokens (SKILL.md is roughly 7.2k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 889 tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Supply Chain: Skill Scanner (getsentry/skills, 1k stars), Serenity Aleabitoreddit (yan-labs/serenity-aleabitoreddit, 481 stars), Eu Cra (Sushegaad/Claude-Skills-Governance-Risk-and-Compliance, 946 stars) and Kesekit Check (cdppcorp/KESE-KIT, 360 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
agentii-ai (a GitHub user) maintains it in agentii-ai/agentii-investment-intelligence, which has 207 GitHub stars. The repository holds 79 skills in this directory. The repository was last updated on September 29, 2026.
Source: agentii-ai/agentii-investment-intelligence on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.