Agent skill

Supply Chain Guard

by davila7 in davila7/claude-code-templates

Detect and remediate software supply chain attacks in npm, PyPI, crates.io, GitHub Actions, and CI/CD pipelines by scanning for known compromised packages, malicious versions, filesystem IOCs, C2…

MITAuto-check: notesDevOps & Cloud

Install Supply Chain Guard

skills CLI
$ npx skills add davila7/claude-code-templates --skill supply-chain-guard -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install davila7/claude-code-templates supply-chain-guard --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/davila7/claude-code-templates.git skills-src && mkdir -p .claude/skills && cp -r skills-src/cli-tool/components/skills/security/supply-chain-guard .claude/skills/supply-chain-guard && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
supply-chain-guard
GitHub stars
33k
Token cost
~1.7k tokens
SKILL.md length
797 words
Files
6 (incl. scripts, references)
Skills in repo
479
Repo updated
First seen
Licence
MIT

At a glance

Detect and remediate software supply chain attacks in npm, PyPI, crates.io, GitHub Actions, and CI/CD pipelines by scanning for known compromised packages, malicious versions, filesystem IOCs, C2…

  • Works in 5 steps: Understand the Project → Run the Appropriate Scanners → Interpret Results → …
  • Tasks that involve Supply chain security
  • SKILL.md covers When to Use This Skill, Instructions, Reference Files and Current Threat Landscape (as…, plus 1 more section
  • Runs Shell scripts from its folder; calls bash, npm and pip

What it does

Supply Chain Guard is an agent skill from davila7/claude-code-templates. Detect and remediate software supply chain attacks in npm, PyPI, crates.io, GitHub Actions, and CI/CD pipelines by scanning for known compromised packages, malicious versions, filesystem IOCs, C2 indicators, and CI/CD misconfigurations.

Its SKILL.md is about 1.7k tokens, which your agent loads only when the skill is triggered. The skill folder holds 7 other files, including scripts and reference files (for example `references/ioc-database.md`, `scripts/scan-all.sh` and `scripts/scan-ci.sh`).

It sits in DevOps & Cloud, covering Supply chain security and CI/CD. It works with npm, GitHub Actions and Rust. The repository describes itself as: CLI tool for configuring and monitoring Claude Code. The licence is MIT.

When your agent uses it

  • Tasks that involve Supply chain security
  • Tasks that involve CI/CD

Example prompts

  • “/supply-chain-guard”

Requirements

  • Python 3
  • Node.js
  • A Bash shell
  • Docker

Workflow steps

5 steps, taken from the step headings in SKILL.md.

  1. Understand the Project
  2. Run the Appropriate Scanners
  3. Interpret Results
  4. Remediate
  5. Harden the Project

What it can do on your machine

Read from SKILL.md and the folder at commit c0ca7da. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 4 files in scripts/ (Shell), which the agent can run.

    Shell commands in SKILL.md call:

    • bash
    • npm
    • pip

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use npm and pip, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Supply Chain Guard loads about 1.7k tokens when it runs, and up to ~3.1k if it reads all its reference files. Until then it costs about 64 tokens; SKILL.md has 797 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~64
When it runs · the whole SKILL.md, loaded when a task matches
~1.7k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~3.1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteMentions a .env fileSKILL.md:63
    posure** — npm tokens, PyPI credentials, .env files
  • NoteMentions a .env fileSKILL.md:138
    - Steal .env files, AWS credentials, SSH keys

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from davila7/claude-code-templates at commit c0ca7da, republished under its MIT licence (© davila7). 797 words, ~1,681 tokens.

Download SKILL.mdSave it as .claude/skills/supply-chain-guard/SKILL.md (or your agent's skills folder). This skill also uses 5 other files; get the full folder from GitHub.
name
supply-chain-guard
description
Detect and remediate software supply chain attacks in npm, PyPI, crates.io, GitHub Actions, and CI/CD pipelines by scanning for known compromised packages, malicious versions, filesystem IOCs, C2 indicators, and CI/CD misconfigurations.
metadata.author
dan-avila
metadata.version
1.0
metadata.ioc-db-date
2026-03-31

Supply Chain Guard

Automated detection and remediation of software supply chain attacks across npm, PyPI, crates.io, GitHub Actions, and CI/CD pipelines. Built from real-world attack intelligence gathered through March 31, 2026.

When to Use This Skill

Use this skill when:

  • The user asks to audit a project's dependencies for security issues
  • Before deploying code to production
  • When investigating a potential supply chain compromise
  • When the user mentions a recent supply chain attack and wants to check their projects
  • As a regular security check in development workflows
  • When setting up CI/CD pipelines and wanting to harden them
  • When a new supply chain attack is reported and the user wants to verify exposure

Instructions

Step 1: Understand the Project

Identify what the user's project uses:

  • Node.js/npm: Look for package.json, package-lock.json, yarn.lock, pnpm-lock.yaml
  • Python/PyPI: Look for requirements.txt, Pipfile, pyproject.toml, poetry.lock
  • Rust/crates.io: Look for Cargo.toml, Cargo.lock
  • CI/CD: Look for .github/workflows/, Dockerfile, docker-compose.yml
Step 2: Run the Appropriate Scanners

The skill includes three specialized scanners plus a unified runner. All scripts are in the scripts/ directory.

Full audit (recommended):

bash
bash /path/to/supply-chain-guard/scripts/scan-all.sh /path/to/project

Individual scanners:

bash
# npm/Node.js projects
bash /path/to/supply-chain-guard/scripts/scan-npm.sh /path/to/project

# Python/PyPI projects
bash /path/to/supply-chain-guard/scripts/scan-python.sh /path/to/project

# CI/CD pipeline audit
bash /path/to/supply-chain-guard/scripts/scan-ci.sh /path/to/project

Each scanner checks for:

  1. Known compromised packages — exact matches against the IOC database
  2. Malicious versions — specific version numbers known to contain malware
  3. Filesystem IOCs — persistence mechanisms left by attackers
  4. Network IOCs — C2 domains and IPs in source code
  5. CI/CD misconfigurations — unpinned actions, dangerous triggers, exposed secrets
  6. Credential exposure — npm tokens, PyPI credentials, .env files
Step 3: Interpret Results

Scanners exit with the number of issues found (0 = clean). Issues are categorized:

  • [CRITICAL] — Known malicious package or active IOC detected. Immediate action required.
  • [WARNING] — Security concern that needs investigation. May not be an active compromise.
Step 4: Remediate

Based on findings, guide the user through remediation:

If a compromised package is found:
  1. Remove or downgrade to a known safe version immediately
  2. Clear package caches: npm cache clean --force / pip cache purge
  3. Delete node_modules / .venv and reinstall from lockfile
  4. Rotate ALL credentials that were accessible from the environment
If filesystem IOCs are found:
  1. The system should be treated as fully compromised
  2. Identify and remove persistence mechanisms (systemd services, .pth files, cron jobs)
  3. Rotate every credential on the system
  4. Audit cloud provider logs (AWS CloudTrail, GCP Audit Logs, Azure Activity Log)
  5. Check for lateral movement in Kubernetes clusters
  6. Consider reimaging the machine
If CI/CD issues are found:
  1. Pin all GitHub Actions to full commit SHAs (not version tags)
  2. Add --ignore-scripts to npm install/ci commands
  3. Add --require-hashes to pip install commands
  4. Remove or secure pull_request_target triggers
  5. Apply least-privilege permissions to workflow tokens
  6. Audit pipeline execution logs for the attack window periods
Show full SKILL.md (352 more words)Show less
Step 5: Harden the Project

After remediation, recommend these preventive measures:

  1. Lock everything: Exact version pins + lockfiles committed to repo
  2. Hash-verify: Use npm ci (not npm install), pip install --require-hashes
  3. Disable scripts: Use --ignore-scripts by default, enable only for trusted packages
  4. Pin actions: All GitHub Actions pinned to full SHA, never tags
  5. Scope tokens: CI/CD tokens should have minimal permissions
  6. Monitor: Set up automated dependency scanning (but verify the scanner itself is not compromised — see Trivy incident)
  7. Network controls: Block known C2 domains/IPs at firewall level
  8. Audit regularly: Run this scanner before every deployment

Reference Files

  • references/ioc-database.md — Full IOC database with all compromised packages, malicious versions, C2 infrastructure, filesystem indicators, and attack timelines. Read this file for detailed intelligence on specific attacks.

Current Threat Landscape (as of 2026-03-31)

Active Campaign: TeamPCP (CRITICAL)

The most significant active threat. TeamPCP is executing a cascading credential-chain campaign:

  • Compromised Trivy (security scanner) → stole CI/CD secrets from thousands of pipelines
  • Used stolen npm tokens to deploy CanisterWorm across 141+ npm packages
  • Used stolen PyPI tokens to backdoor LiteLLM (95M monthly downloads) and Telnyx
  • Uses blockchain (ICP) for C2, making takedown impossible
  • Deploys WAV steganography for payload delivery
  • Targets Kubernetes for lateral movement
  • Has a destructive variant that wipes Iranian systems
Active: axios npm Hijack (2026-03-31)
  • axios@1.14.1 and axios@0.30.4 contain RAT dropper via fake plain-crypto-js dependency
  • 300M+ weekly downloads makes this extremely high-impact
  • Cross-platform RAT for macOS, Windows, and Linux
  • Compromised maintainer account (jasonsaayman)
Recent: Malicious Rust Crates (2026-02/03)
  • 5 crates impersonating time utilities on crates.io
  • Steal .env files, AWS credentials, SSH keys
  • First significant supply chain attack targeting Rust ecosystem
Historical but Relevant: Shai-Hulud Worm
  • Self-replicating npm worm that compromised ~1000 packages
  • Targets npm tokens for self-propagation
  • Destructive fallback: wipes home directory if exfiltration fails

Updating the IOC Database

When new supply chain attacks are reported:

  1. Search for the latest advisories from Socket, Aikido, Endor Labs, Snyk, JFrog
  2. Update references/ioc-database.md with new packages, versions, domains, IPs
  3. Update the scanner scripts with new package entries in the MALICIOUS_* arrays
  4. Update the ioc-db-date in the SKILL.md frontmatter

© davila7, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 5 other files (scripts, references) in cli-tool/components/skills/security/supply-chain-guard of davila7/claude-code-templates.

  • SKILL.md
  • references/ioc-database.md
  • scripts/scan-all.sh
  • scripts/scan-ci.sh
  • scripts/scan-npm.sh
  • scripts/scan-python.sh

Open the folder on GitHubat commit c0ca7da

Compare with similar skills

Supply Chain Guard next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Supply Chain Guard compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Supply Chain Guard this skilldavila7/claude-code-templates33k—~1.7kAutomated safety check: NotesMIT
GitHub Actions Supply Chain Pinningasyncapi/generator1.1k—~1.9kAutomated safety check: PassApache-2.0
CI Pipeline Synthesizerkajisho5/ffmpeg-skill1.9k1 repos~1.1kAutomated safety check: PassMIT
Vibe CI Supply Chainmistralai/mistral-vibe5.1k—~1kAutomated safety check: PassApache-2.0
CI/CD Pipeline Principlesirahardianto/awesome-agv156—~2.7kAutomated safety check: NotesMIT
Atmos CIcloudposse/atmos1.4k—~4.7kAutomated safety check: PassApache-2.0

Similar skills

  • A skill your agent uses when editing, adding, or reviewing any file under .github/workflows/, or when a CI step installs a CLI tool (npm i -g, npx, pipx, uses: /setup-).

    1.1k GitHub stars~1.9k tokensUpdated yesterday
    DevOps & CloudAuto-check passed
  • CI Pipeline Synthesizer

    kajisho5/ffmpeg-skill

    Generate GitHub Actions CI/CD pipeline configurations for automated building and testing of library and package projects.

    1.9k GitHub starsUsed in 1 repo~1.1k tokens
    DevOps & CloudAuto-check passed
  • Vibe CI Supply Chain

    mistralai/mistral-vibe

    Official

    Git workflow, CI/GitHub Actions, and supply-chain pinning rules for Mistral Vibe.

    5.1k GitHub stars~1k tokensUpdated yesterday
    DevOps & CloudAuto-check passed
  • CI/CD Pipeline Principles

    irahardianto/awesome-agv

    Rules for designing CI/CD pipelines in layers: universal lint, test and scan stages, container builds with SBOM attestation, and GitOps for orchestrated deployments.

    156 GitHub stars~2.7k tokensUpdated 6 days ago
    DevOps & CloudAuto-check: notes
  • Atmos CI

    cloudposse/atmos

    Atmos CI: Native CI with GitHub Actions containers, native outputs, SBOM workflow-artifact publication, collapsible log groups, affected/all matrix workflows, OIDC profiles, toolchain-aware jobs…

    1.4k GitHub stars~4.7k tokensUpdated yesterday
    DevOps & CloudAuto-check passed
  • Review Dependencies

    tobihagemann/turbo

    Detect package managers and CI action pins, then discover outdated or vulnerable dependencies.

    408 GitHub stars~1.5k tokensUpdated 2 days ago
    DevOps & CloudAuto-check passed

More from davila7/claude-code-templates

All 479 skills in this repo
  • Perplexity Web Search

    davila7/claude-code-templates

    Runs web-grounded searches through Perplexity's Sonar models over OpenRouter for current events, recent literature and cited facts beyond the model's training cutoff.

    33k GitHub starsUsed in 11 repos~3.5k tokens
    Auto-check: notes
  • Neuropixels Data Analysis

    davila7/claude-code-templates

    Analyzes Neuropixels recordings from SpikeGLX or Open Ephys through preprocessing, drift correction, Kilosort4 spike sorting, quality metrics and curation.

    33k GitHub starsUsed in 9 repos~2.8k tokens
    Auto-check passed
  • Scientific Venue Templates

    davila7/claude-code-templates

    Supplies LaTeX templates and formatting rules for journals, conferences, posters, and grant proposals, then can check a draft against them.

    33k GitHub starsUsed in 9 repos~5.1k tokens
    Auto-check: notes
  • Brand Voice Content Creator

    davila7/claude-code-templates

    Analyzes a brand's existing writing to lock in a consistent voice, then builds SEO blog posts and platform-specific social content around it.

    33k GitHub starsUsed in 3 repos~1.9k tokens
    Auto-check passed
  • CAPA Officer

    davila7/claude-code-templates

    Guides corrective and preventive action (CAPA) work in a quality management system, from initiation and root cause analysis through effectiveness verification.

    33k GitHub starsUsed in 1 repo~2k tokens
    Auto-check passed
  • Fda Consultant Specialist

    davila7/claude-code-templates

    Senior FDA consultant and specialist for medical device companies including HIPAA compliance and requirement management.

    33k GitHub starsUsed in 1 repo~2.7k tokens
    Auto-check passed

Questions about Supply Chain Guard

What does Supply Chain Guard do?

Detect and remediate software supply chain attacks in npm, PyPI, crates.io, GitHub Actions, and CI/CD pipelines by scanning for known compromised packages, malicious versions, filesystem IOCs, C2…. Supply Chain Guard is an agent skill from davila7/claude-code-templates.io, GitHub Actions, and CI/CD pipelines by scanning for known compromised packages, malicious versions, filesystem IOCs, C2 indicators, and CI/CD misconfigurations.

When should I use Supply Chain Guard?

Supply Chain Guard fits situations like: tasks that involve Supply chain security; tasks that involve CI/CD.

How do I install Supply Chain Guard in Claude Code?

Run `npx skills add davila7/claude-code-templates --skill supply-chain-guard -a claude-code`. Or copy the skill folder (cli-tool/components/skills/security/supply-chain-guard in davila7/claude-code-templates) into .claude/skills/supply-chain-guard in your project. Claude Code loads it when a task matches its description.

How do I install Supply Chain Guard in Codex?

Run `npx skills add davila7/claude-code-templates --skill supply-chain-guard -a codex`. Or copy the skill folder (cli-tool/components/skills/security/supply-chain-guard in davila7/claude-code-templates) into .agents/skills/supply-chain-guard in your project. Codex loads it when a task matches its description.

Can I use Supply Chain Guard in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add davila7/claude-code-templates --skill supply-chain-guard -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/supply-chain-guard, .gemini/skills/supply-chain-guard, .github/skills/supply-chain-guard and .opencode/skills/supply-chain-guard in your project.

What does Supply Chain Guard need to run?

Going by SKILL.md and its folder, Supply Chain Guard needs a shell for the scripts in its folder and the command-line tools its instructions call (bash, npm and pip). Our summary lists: Python 3; Node.js; A Bash shell; Docker.

Does Supply Chain Guard access the network?

SKILL.md contains no URLs. Its commands use npm and pip, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Supply Chain Guard safe to install?

Our automated static check of SKILL.md found notes only (mentions a .env file), nothing it rates as a warning. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Supply Chain Guard use?

Supply Chain Guard is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Supply Chain Guard use?

About 1.7k tokens (SKILL.md is roughly 6.7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 1.4k tokens, read only when the agent opens those files.

What are the alternatives to Supply Chain Guard?

Skills that share tags, products or a category with Supply Chain Guard: GitHub Actions Supply Chain Pinning (asyncapi/generator, 1.1k stars), CI Pipeline Synthesizer (kajisho5/ffmpeg-skill, 1.9k stars), Vibe CI Supply Chain (mistralai/mistral-vibe, 5.1k stars) and CI/CD Pipeline Principles (irahardianto/awesome-agv, 156 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Supply Chain Guard?

davila7 (a GitHub user) maintains it in davila7/claude-code-templates, which has 32,512 GitHub stars. The repository holds 479 skills in this directory. The repository was last updated on October 10, 2026.

Source: davila7/claude-code-templates on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.