Agent skill

Supply Chain Advisory

by athola in athola/claude-night-market

Audits dependency supply chains for bad versions, lockfile drift, and artifact integrity.

MITAuto-check passedSecurity

Install Supply Chain Advisory

skills CLI
$ npx skills add athola/claude-night-market --skill supply-chain-advisory -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install athola/claude-night-market supply-chain-advisory --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/athola/claude-night-market.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/leyline/skills/supply-chain-advisory .claude/skills/supply-chain-advisory && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
supply-chain-advisory
GitHub stars
341
Token cost
~1.1k tokens
SKILL.md length
372 words
Files
4
Skills in repo
152
Repo updated
First seen
Licence
MIT

At a glance

Audits dependency supply chains for bad versions, lockfile drift, and artifact integrity.

  • Works in 3 steps: SessionStart hook: warns per-session… → make supply-chain-scan: CI/local… → This skill: manual audit guidance
  • Handling incidents
  • SKILL.md covers Overview, When To Use, When NOT To Use and Known-Bad Versions Blocklist, plus 4 more sections
  • Calls make and uv

What it does

Supply Chain Advisory is an agent skill from athola/claude-night-market. Audits dependency supply chains for bad versions, lockfile drift, and artifact integrity. Use when adding deps, handling incidents, or releasing a plugin.

Its SKILL.md is about 1.1k tokens, which your agent loads only when the skill is triggered. The skill folder holds 4 other files (for example `known-bad-versions.json`, `modules/incident-response.md` and `modules/scanning-patterns.md`).

It sits in Security, covering Supply chain security and Dependency management. The repository describes itself as: 23 Claude Code plugins: TDD enforcement hooks, git/PR workflows, spec-driven development, code review, project lifecycle, fix-from-error, maintenance automation, context… The licence is MIT.

When your agent uses it

  • Handling incidents
  • Releasing a plugin

Example prompts

  • “Use the supply-chain-advisory skill to audit dependency supply chains for bad versions, lockfile drift, and artifact integrity”
  • “/supply-chain-advisory”

Requirements

  • Python 3

Workflow steps

3 steps, taken from the first numbered list in SKILL.md.

  1. SessionStart hook: warns per-session when compromised
  2. make supply-chain-scan: CI/local scanning target
  3. This skill: manual audit guidance

What it can do on your machine

Read from SKILL.md and the folder at commit 9f3eb00. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • make
    • uv

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use uv, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Supply Chain Advisory loads about 1.1k tokens when it runs. Until then it costs about 44 tokens; SKILL.md has 372 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~44
When it runs · the whole SKILL.md, loaded when a task matches
~1.1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from athola/claude-night-market at commit 9f3eb00, republished under its MIT licence (© athola). 372 words, ~1,120 tokens.

Download SKILL.mdSave it as .claude/skills/supply-chain-advisory/SKILL.md (or your agent's skills folder). This skill also uses 3 other files; get the full folder from GitHub.
name
supply-chain-advisory
description
Audits dependency supply chains for bad versions, lockfile drift, and artifact integrity. Use when adding deps, handling incidents, or releasing a plugin.
alwaysApply
false
category
infrastructure
tags
security, supply-chain, dependencies, vulnerability, pypi
dependencies
error-patterns
provides.infrastructure
supply-chain-scanning, dependency-auditing, incident-response
provides.patterns
known-bad-detection, lockfile-audit, artifact-scanning
usage_patterns
dependency-security-check, incident-response, supply-chain-audit
complexity
intermediate
model_hint
standard
estimated_tokens
500

Overview

Supply chain attacks bypass traditional code review by compromising upstream dependencies. This skill provides patterns for detecting, preventing, and responding to compromised packages in Python ecosystems.

When To Use

  • After a supply chain advisory is published
  • When auditing dependencies for a new or existing project
  • During incident response for a suspected compromise
  • When adding the SessionStart hook to a project

When NOT To Use

  • General CVE triage unrelated to dependency supply chain
  • Application-level vulnerability scanning (use a SAST tool)
  • License compliance audits (different concern)

Known-Bad Versions Blocklist

The blocklist is at ${CLAUDE_SKILL_DIR}/known-bad-versions.json. It is consumed by:

  1. SessionStart hook: warns per-session when compromised versions detected
  2. make supply-chain-scan: CI/local scanning target
  3. This skill: manual audit guidance
Blocklist Format
json
{
  "package_name": [{
    "versions": ["x.y.z"],
    "date": "YYYY-MM-DD",
    "description": "What the attack did",
    "indicators": ["files or patterns to search for"],
    "source": "advisory URL",
    "severity": "critical|high|medium"
  }]
}
Adding a New Entry
  1. Add the entry to ${CLAUDE_SKILL_DIR}/known-bad-versions.json
  2. Add version exclusions (!=x.y.z) to affected pyproject.toml files
  3. Document in docs/dependency-audit.md under Supply Chain Incidents
  4. Run make supply-chain-scan to verify detection works

Quick Scan Commands

Check all lockfiles on machine for known-bad versions
bash
# Scan uv.lock files for a specific compromised version
grep -r "package_name.*version" --include="uv.lock" /path/to/projects

# Search for malicious artifacts
find /path/to/projects -name "suspicious_file.pth" 2>/dev/null

# Check installed versions in virtualenvs
find /path/to/projects -path "*/.venv/lib/*/PACKAGE*/METADATA" \
  -exec grep "^Version:" {} +
Verify lockfile hash integrity

uv.lock includes SHA256 hashes for every package. If a package is re-published with different content under the same version, uv sync will fail with a hash mismatch. This is your strongest automatic defense.

Show full SKILL.md (169 more words)Show less

Defense Layers

LayerToolCatches
Lockfile hashesuv.lock SHA256Tampered re-published versions
Version exclusionspyproject.toml !=Known-bad versions on fresh resolve
SessionStart hooksanctum hookPer-session warning for compromised deps
CI scanningOSV, SafetyCVE database, and advisory matching
Artifact scanningmake supply-chain-scanMalicious files (.pth, scripts)

Limitations

  • Zero-day supply chain attacks have no prior advisory: lockfile hashes are the only automatic defense during the attack window
  • Safety/CVE databases lag behind real-world compromises
  • OSV provides broader coverage but is still reactive

Exit Criteria

  • ${CLAUDE_SKILL_DIR}/known-bad-versions.json checked against all lockfiles in scope; any match reported with package name, bad version, severity, and advisory URL
  • When a new known-bad entry is added: version exclusion (!=x.y.z) added to the affected pyproject.toml, entry documented in docs/dependency-audit.md, and make supply-chain-scan run to confirm detection works
  • uv.lock SHA256 hash integrity verified; uv sync failure on hash mismatch surfaces as an explicit supply-chain warning rather than a generic install error
  • Artifact scan checks for malicious file patterns (.pth files, unexpected scripts) in virtualenv paths before the session proceeds

© athola, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 3 other files in plugins/leyline/skills/supply-chain-advisory of athola/claude-night-market.

  • SKILL.md
  • known-bad-versions.json
  • modules/incident-response.md
  • modules/scanning-patterns.md

Open the folder on GitHubat commit 9f3eb00

Compare with similar skills

Supply Chain Advisory next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Supply Chain Advisory compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Supply Chain Advisory this skillathola/claude-night-market341—~1.1kAutomated safety check: PassMIT
Dependency Update Auditbacknotprop/plannotator9.3k—~1.8kAutomated safety check: PassApache-2.0
Dependency Upgradesecondsky/sap-skills462—~4.8kAutomated safety check: WarnGPL-3.0
npm Supply Chain Securitybodadotsh/npm-security-best-practices858—~1kAutomated safety check: WarnMIT
Detecting Typosquatting Packagesmukul975/Anthropic-Cybersecurity-Skills34k—~3kAutomated safety check: PassApache-2.0
Renovate Actions PR Reviewbacknotprop/plannotator9.3k—~640Automated safety check: PassApache-2.0

Similar skills

  • Dependency Update Audit

    backnotprop/plannotator

    Audits outdated npm and Bun packages for supply chain integrity before bumping them, deferring risky ones and logging every decision.

    9.3k GitHub stars~1.8k tokensUpdated today
    SecurityAuto-check passed
  • Dependency Upgrade

    secondsky/sap-skills

    Secure dependency upgrades with supply chain protection, cooldowns, and staged rollout.

    462 GitHub stars~4.8k tokensUpdated 6 days ago
    SecurityAuto-check: warnings
  • npm Supply Chain Security

    bodadotsh/npm-security-best-practices

    Applies safer package manager defaults and dependency vetting to JavaScript and TypeScript projects to reduce supply-chain attack risk.

    858 GitHub stars~1k tokensUpdated 10 days ago
    SecurityAuto-check: warnings
  • Detecting Typosquatting Packages

    mukul975/Anthropic-Cybersecurity-Skills

    Flag misspelled, brandjacked, and typosquatted package names across npm, PyPI, and crates.io before installation, using edit-distance, keyboard-proximity, and known-target corpus matching with…

    34k GitHub stars~3k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Renovate Actions PR Review

    backnotprop/plannotator

    Reviews Renovate pull requests that bump GitHub Actions by checking pinned SHAs against upstream tags, scanning changelogs and confirming workflows stay compatible.

    9.3k GitHub stars~640 tokensUpdated today
    DevelopmentAuto-check passed
  • Gathers security findings from Dependabot, GCP container scanning, Docker Scout and Linear security issues, then triages and remediates them across Warp's repos and images.

    65k GitHub starsUsed in 1 repo~2.1k tokens
    SecurityAuto-check passed

More from athola/claude-night-market

All 152 skills in this repo
  • Night Market Diagnostics Toolkit

    athola/claude-night-market

    Run and interpret repo diagnostic scripts (ratchets, validators, token stats).

    341 GitHub stars~3.4k tokensUpdated yesterday
    Auto-check passed
  • Skills Eval

    athola/claude-night-market

    Evaluate Claude skill quality through auditing. An agent skill from athola/claude-night-market.

    341 GitHub stars~1.6k tokensUpdated yesterday
    Auto-check passed
  • Agent Teams

    athola/claude-night-market

    Coordinates Claude agent teams via filesystem protocol. An agent skill from athola/claude-night-market.

    341 GitHub stars~2.5k tokensUpdated yesterday
    Auto-check passed
  • Delegation Core

    athola/claude-night-market

    Delegates execution to eight CLIs (Gemini, Qwen, MiniMax, GLM, Muse, Codex, OpenCode, Glimmer).

    341 GitHub stars~2.5k tokensUpdated yesterday
    Auto-check passed
  • Elegant Code

    athola/claude-night-market

    Guide minimal code via a decision ladder with full safety, edge, and negative-case coverage.

    341 GitHub stars~2.1k tokensUpdated yesterday
    Auto-check passed
  • Skill Library Mission

    athola/claude-night-market

    Build a project skill library in .claude/skills/ via discovery, parallel authoring, and review.

    341 GitHub stars~1.6k tokensUpdated yesterday
    Auto-check passed

Questions about Supply Chain Advisory

What does Supply Chain Advisory do?

Audits dependency supply chains for bad versions, lockfile drift, and artifact integrity. Supply Chain Advisory is an agent skill from athola/claude-night-market. Audits dependency supply chains for bad versions, lockfile drift, and artifact integrity.

When should I use Supply Chain Advisory?

Supply Chain Advisory fits situations like: handling incidents; releasing a plugin.

How do I install Supply Chain Advisory in Claude Code?

Run `npx skills add athola/claude-night-market --skill supply-chain-advisory -a claude-code`. Or copy the skill folder (plugins/leyline/skills/supply-chain-advisory in athola/claude-night-market) into .claude/skills/supply-chain-advisory in your project. Claude Code loads it when a task matches its description.

How do I install Supply Chain Advisory in Codex?

Run `npx skills add athola/claude-night-market --skill supply-chain-advisory -a codex`. Or copy the skill folder (plugins/leyline/skills/supply-chain-advisory in athola/claude-night-market) into .agents/skills/supply-chain-advisory in your project. Codex loads it when a task matches its description.

Can I use Supply Chain Advisory in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add athola/claude-night-market --skill supply-chain-advisory -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/supply-chain-advisory, .gemini/skills/supply-chain-advisory, .github/skills/supply-chain-advisory and .opencode/skills/supply-chain-advisory in your project.

What does Supply Chain Advisory need to run?

Going by SKILL.md and its folder, Supply Chain Advisory needs the command-line tools its instructions call (make and uv). Our summary lists: Python 3.

Does Supply Chain Advisory access the network?

SKILL.md contains no URLs. Its commands use uv, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Supply Chain Advisory safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Supply Chain Advisory use?

Supply Chain Advisory is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Supply Chain Advisory use?

About 1.1k tokens (SKILL.md is roughly 4.5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Supply Chain Advisory?

Skills that share tags, products or a category with Supply Chain Advisory: Dependency Update Audit (backnotprop/plannotator, 9.3k stars), Dependency Upgrade (secondsky/sap-skills, 462 stars), npm Supply Chain Security (bodadotsh/npm-security-best-practices, 858 stars) and Detecting Typosquatting Packages (mukul975/Anthropic-Cybersecurity-Skills, 34k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Supply Chain Advisory?

athola (a GitHub user) maintains it in athola/claude-night-market, which has 341 GitHub stars. The repository holds 152 skills in this directory. The repository was last updated on October 9, 2026.

Source: athola/claude-night-market on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.