Agent skill

Proactive Security Monitor

by epam in epam/ai-dial-chat

Proactive supply-chain watch for this repo. An agent skill from epam/ai-dial-chat.

Apache-2.0Auto-check passedSecurity

Install Proactive Security Monitor

skills CLI
$ npx skills add epam/ai-dial-chat --skill proactive-security-monitor -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install epam/ai-dial-chat proactive-security-monitor --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/epam/ai-dial-chat.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/proactive-security-monitor .claude/skills/proactive-security-monitor && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
proactive-security-monitor
GitHub stars
504
Token cost
~1.9k tokens
SKILL.md length
833 words
Files
2
Skills in repo
18
Repo updated
First seen
Licence
Apache-2.0

At a glance

Proactive supply-chain watch for this repo. An agent skill from epam/ai-dial-chat.

  • Works in 3 steps: Deterministic OSV pass — run the… → Industry-news pass — your own judgment → Enrich the envelope (preserve the OSV…
  • Tasks that involve Supply chain security
  • SKILL.md covers Process, Output and Required tools
  • Runs Shell scripts from its folder; calls bash; reaches cisa.gov and openssf.org

What it does

Proactive Security Monitor is an agent skill from epam/ai-dial-chat. Proactive supply-chain watch for this repo. Resolves the npm SBOM and batch-queries OSV.dev for freshly-modified advisories (committed fetch.sh), then runs an industry-news pass (CISA KEV, OpenSSF, GitHub Security Lab, Socket, The Hacker News) filtered to this project's stack, and emits both as one findings set for the downstream triager. Use as the daily/scheduled producer half of the proactive-security-monitor → security-monitor-triager chain.

Its SKILL.md is about 1.9k tokens, which your agent loads only when the skill is triggered. The skill folder holds 1 other file (for example `fetch.sh`).

It sits in Security, covering Supply chain security. It works with npm and GitHub. The repository describes itself as: A default UI for AI DIAL. The licence is Apache-2.0.

When your agent uses it

  • Tasks that involve Supply chain security

Example prompts

  • “/proactive-security-monitor”

Requirements

  • Node.js
  • A Bash shell

Workflow steps

3 steps, taken from the step headings in SKILL.md.

  1. Deterministic OSV pass — run the committed script
  2. Industry-news pass — your own judgment
  3. Enrich the envelope (preserve the OSV findings)

What it can do on your machine

Read from SKILL.md and the folder at commit 3455656. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships script files (Shell), which the agent can run.

    Shell commands in SKILL.md call:

    • bash

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • cisa.gov
    • openssf.org
    • github.blog
    • socket.dev
    • feeds.feedburner.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Proactive Security Monitor loads about 1.9k tokens when it runs. Until then it costs about 119 tokens; SKILL.md has 833 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~119
When it runs · the whole SKILL.md, loaded when a task matches
~1.9k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from epam/ai-dial-chat at commit 3455656, republished under its Apache-2.0 licence (© epam). 833 words, ~1,872 tokens.

Download SKILL.mdSave it as .claude/skills/proactive-security-monitor/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
proactive-security-monitor
description
Proactive supply-chain watch for this repo. Resolves the npm SBOM and batch-queries OSV.dev for freshly-modified advisories (committed fetch.sh), then runs an industry-news pass (CISA KEV, OpenSSF, GitHub Security Lab, Socket, The Hacker News) filtered to this project's stack, and emits both as one findings set for the downstream triager. Use as the daily/scheduled producer half of the proactive-security-monitor → security-monitor-triager chain.
disable-model-invocation
true

Proactive Security Monitor (producer)

You are the producer in a two-stage proactive-security loop. Your job is to surface what is newly worth a human's attention this run — freshly-disclosed dependency advisories and moving-target supply-chain incidents from the security press — and hand them, un-triaged, to the skeptical security-monitor-triager stage. You find; the triager validates reachability. Do not assess exploitability or read application code here — that is the triager's job, against the correct branch's source.

This is the time-axis complement to the repo's PR-time scanners (Trivy, Dependabot, dependency-review): it pulls fresh advisory + incident signal on a schedule rather than waiting for the next PR or the weekly Dependabot run.

Process

1. Deterministic OSV pass — run the committed script

Run exactly this single Bash command (your only Bash allowance):

bash .claude/skills/proactive-security-monitor/fetch.sh

It resolves the npm SBOM from package-lock.json (no install), batch-queries OSV.dev, keeps advisories modified within the recent window, and writes a schema-valid stage-output.json with the CVE hits already inlined under payload.findings[] and an empty payload.news array. Read stage-output.json to confirm it exists and see what the OSV pass found. Do not rewrite payload.findings[] — you will only add to this envelope below.

If the command is denied or errors before the file exists, the script still writes a status: "failed" envelope; in that case stop after reading it.

2. Industry-news pass — your own judgment

Independent of OSV, fetch these sources with WebFetch (look back over the same recent window) and extract items disclosed/updated in that window. The RSS/Atom feeds (e.g. The Hacker News) are broader than supply-chain only — their items span all of infosec — so be especially strict applying the stack + supply-chain filter below; drop generic threat-intel that does not touch this project's stack or a supply-chain/registry/CI vector:

SourceURL
CISA KEV (newly added CVEs)https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json
OpenSSF bloghttps://openssf.org/blog/
GitHub Security Labhttps://github.blog/security/
Socket.dev bloghttps://socket.dev/blog
The Hacker News — RSS feedhttps://feeds.feedburner.com/TheHackersNews

This project's stack — filter every item against it: Node.js · TypeScript · NestJS 11 · React 19 · react-router 7 · Express 5 · Vite · Nx monorepo · helmet · i18next · rxjs · mime-types · reflect-metadata · npm / npm registry · GitHub Actions toolchain (epam/ai-dial-ci reusable workflows, actions/*, step-security/harden-runner).

Classify every item into exactly one tag:

  • RELEVANT — names a package in the SBOM, or a Node/npm/TypeScript/React/NestJS/Vite/Nx-specific incident, or an npm-registry or GitHub-Actions-toolchain attack.
  • TANGENTIAL — a supply-chain technique or registry-abuse case in another ecosystem (PyPI, RubyGems, Maven, Go, etc.) that plausibly translates to this stack. Include only with a one-sentence translation rationale. Default to IGNORE if unsure.
  • IGNORE — audited, not applicable. Keep title + source so the filter is auditable; no analysis.

Record every fetch deterministically. For each source in the table above, note the WebFetch outcome so coverage gaps are a fact, not model narration. You will emit these in step 3 as payload.news_sources[] — one entry per table row, each {source, url, attempted, ok, item_count, note?}:

  • A WebFetch that errors (HTTP 403, timeout, unreachable, unparseable) ⇒ {attempted: true, ok: false, item_count: 0, note: "<reason, e.g. HTTP 403 bot block>"}.
  • A WebFetch that succeeds but yields no in-window items ⇒ {attempted: true, ok: true, item_count: 0} (a real, reachable-but-empty source — not a coverage gap).
  • A WebFetch that succeeds with items ⇒ {attempted: true, ok: true, item_count: <N items extracted from that source>}.

item_count is the count of items extracted from that source before the RELEVANT/TANGENTIAL/IGNORE filter, so a source can be ok: true with a positive item_count even if every item ends up IGNORE.

Show full SKILL.md (280 more words)Show less
3. Enrich the envelope (preserve the OSV findings)

Use the Write tool to write stage-output.json again, carrying over payload.findings[] and every other payload key from step 1 unchanged, and adding the news pass:

  • payload.news — array of {tag, title, source, url, date, rationale?, stack_hit?, suggested_action?} for RELEVANT and TANGENTIAL items (and an auditable list of IGNORE titles under payload.news_ignored).
  • payload.news_sources — array with one entry per source row in the step-2 table, each {source, url, attempted, ok, item_count, note?}, populated from the per-source WebFetch outcomes recorded in step 2. This makes coverage gaps deterministic: a source that returned 403/error appears as ok: false with a note, distinct from a reachable source that simply had no in-window items (ok: true, item_count: 0). The triager reads this instead of inferring reach from prose.
  • For each RELEVANT item that maps to a concrete repo action (e.g. "SHA-pin a mutable uses: ref", "confirm token rotation"), add a suggested_action.
  • Update summary to one line covering both passes, e.g. "OSV: 2 in-window; News: 3 RELEVANT, 4 TANGENTIAL (incl. GitHub Actions campaign)."
  • Set status to passed_with_findings if there is any OSV finding OR any RELEVANT/TANGENTIAL news item; otherwise passed.

Keep any comment_markdown short (≤5 lines, no nested code fences) — long markdown inside JSON is escape-error-prone. The downstream triager reads the structured payload, not prose.

Output

One stage-output.json at repo root: {stage, status, summary, payload:{findings[], news[], news_ignored[], news_sources[], ...}}. The OSV findings[] come from fetch.sh; you add news[], news_ignored[], and news_sources[] (one {source, url, attempted, ok, item_count, note?} entry per step-2 source, recording each WebFetch outcome so coverage gaps are deterministic). The triager stage consumes this whole payload.

Required tools

Bash(bash .claude/skills/proactive-security-monitor/fetch.sh:*), Read, WebFetch, Skill. (Write is granted by the platform.)

© epam, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file in .claude/skills/proactive-security-monitor of epam/ai-dial-chat.

  • SKILL.md
  • fetch.sh

Open the folder on GitHubat commit 3455656

Compare with similar skills

Proactive Security Monitor next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Proactive Security Monitor compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Proactive Security Monitor this skillepam/ai-dial-chat504—~1.9kAutomated safety check: PassApache-2.0
GitHub Actions Supply Chain Pinningasyncapi/generator1.1k—~1.9kAutomated safety check: PassApache-2.0
Stash Supply Chain Securitycipherstash/stack157—~5.2kAutomated safety check: WarnMIT
Verify Releaseopenclaw/openclaw392k—~2.4kAutomated safety check: PassMIT
Supply Chain Securityzhaoxuya520/reverse-skill41k4 repos~953Automated safety check: WarnMIT
npm Supply Chain Securitybodadotsh/npm-security-best-practices858—~1kAutomated safety check: WarnMIT

Similar skills

  • A skill your agent uses when editing, adding, or reviewing any file under .github/workflows/, or when a CI step installs a CLI tool (npm i -g, npx, pipx, uses: /setup-).

    1.1k GitHub stars~1.9k tokensUpdated yesterday
    DevOps & CloudAuto-check passed
  • Supply-chain security controls for the @cipherstash/stack monorepo.

    157 GitHub stars~5.2k tokensUpdated yesterday
    DevelopmentAuto-check: warnings
  • Verify Release

    openclaw/openclaw

    Verify regular or extended-stable OpenClaw releases against the exact publication surfaces, workflow identities, package provenance, smoke tests, and live Gateway behavior expected for that release…

    392k GitHub stars~2.4k tokensUpdated today
    Testing & QAAuto-check passed
  • Supply Chain Security

    zhaoxuya520/reverse-skill

    A skill your agent uses for software supply-chain security assessment covering SBOM, SCA, CI/CD pipelines, container images, build integrity, dependency provenance, and vulnerability reachability.

    41k GitHub starsUsed in 4 repos~953 tokens
    SecurityAuto-check: warnings
  • npm Supply Chain Security

    bodadotsh/npm-security-best-practices

    Applies safer package manager defaults and dependency vetting to JavaScript and TypeScript projects to reduce supply-chain attack risk.

    858 GitHub stars~1k tokensUpdated 10 days ago
    SecurityAuto-check: warnings
  • Oss Forensics

    Tommy-yw/RunbookHermes

    Supply chain investigation, evidence recovery, and forensic analysis for GitHub repositories.

    546 GitHub starsUsed in 3 repos~5k tokens
    SecurityAuto-check passed

More from epam/ai-dial-chat

All 18 skills in this repo
  • Refactoring Audit

    epam/ai-dial-chat

    Deep codebase refactoring audit for AI DIAL Chat. An agent skill from epam/ai-dial-chat.

    504 GitHub stars~4.3k tokensUpdated today
    Auto-check passed
  • Read unresolved GitHub code review threads for the pull request associated with the current branch, classify each comment, and implement and verify required code fixes.

    504 GitHub stars~1.7k tokensUpdated today
    Auto-check passed
  • Create Ticket

    epam/ai-dial-chat

    Interactively create OR update GitHub issues (Bug, Feature, Task) for the current repository.

    504 GitHub stars~4.6k tokensUpdated today
    Auto-check passed
  • Dep Scan

    epam/ai-dial-chat

    Runs Trivy filesystem scan against the repo root and emits structured vulnerability findings (CVE, package, versions) in the SDLC reviewer schema.

    504 GitHub stars~1.2k tokensUpdated today
    Auto-check passed
  • Figma

    epam/ai-dial-chat

    Design-to-code workflow for Figma designs. An agent skill from epam/ai-dial-chat.

    504 GitHub stars~997 tokensUpdated today
    Auto-check passed
  • Git Ship

    epam/ai-dial-chat

    A skill your agent uses whenever the user wants to commit, push, or ship changes in a git repository.

    504 GitHub stars~1.2k tokensUpdated today
    Auto-check passed

Works with

Categories

Questions about Proactive Security Monitor

What does Proactive Security Monitor do?

Proactive supply-chain watch for this repo. An agent skill from epam/ai-dial-chat. Proactive Security Monitor is an agent skill from epam/ai-dial-chat. Proactive supply-chain watch for this repo.

When should I use Proactive Security Monitor?

Proactive Security Monitor fits situations like: tasks that involve Supply chain security.

How do I install Proactive Security Monitor in Claude Code?

Run `npx skills add epam/ai-dial-chat --skill proactive-security-monitor -a claude-code`. Or copy the skill folder (.claude/skills/proactive-security-monitor in epam/ai-dial-chat) into .claude/skills/proactive-security-monitor in your project. Claude Code loads it when a task matches its description.

How do I install Proactive Security Monitor in Codex?

Run `npx skills add epam/ai-dial-chat --skill proactive-security-monitor -a codex`. Or copy the skill folder (.claude/skills/proactive-security-monitor in epam/ai-dial-chat) into .agents/skills/proactive-security-monitor in your project. Codex loads it when a task matches its description.

Can I use Proactive Security Monitor in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add epam/ai-dial-chat --skill proactive-security-monitor -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/proactive-security-monitor, .gemini/skills/proactive-security-monitor, .github/skills/proactive-security-monitor and .opencode/skills/proactive-security-monitor in your project.

What does Proactive Security Monitor need to run?

Going by SKILL.md and its folder, Proactive Security Monitor needs a shell for the scripts in its folder and the command-line tools its instructions call (bash). Our summary lists: Node.js; A Bash shell.

Does Proactive Security Monitor access the network?

SKILL.md names 5 domains. In commands or code: cisa.gov, openssf.org, github.blog, socket.dev and feeds.feedburner.com; the agent is likely to contact these when it follows the instructions. This is read from the text; nothing was executed.

Is Proactive Security Monitor safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Proactive Security Monitor use?

Proactive Security Monitor is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Proactive Security Monitor use?

About 1.9k tokens (SKILL.md is roughly 7.5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Proactive Security Monitor?

Skills that share tags, products or a category with Proactive Security Monitor: GitHub Actions Supply Chain Pinning (asyncapi/generator, 1.1k stars), Stash Supply Chain Security (cipherstash/stack, 157 stars), Verify Release (openclaw/openclaw, 392k stars) and Supply Chain Security (zhaoxuya520/reverse-skill, 41k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Proactive Security Monitor?

epam (a GitHub organization) maintains it in epam/ai-dial-chat, which has 504 GitHub stars. The repository holds 18 skills in this directory. The repository was last updated on October 9, 2026.

Source: epam/ai-dial-chat on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.