Agent skill

Interlinked Supply Chain

by QuentinCody in QuentinCody/interlinked-cli

Respond to blocked package installs and manage the Interlinked supply-chain allowlist.

MITAuto-check passedSecurity

Install Interlinked Supply Chain

skills CLI
$ npx skills add QuentinCody/interlinked-cli --skill interlinked-supply-chain -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install QuentinCody/interlinked-cli interlinked-supply-chain --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/QuentinCody/interlinked-cli.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/interlinked-supply-chain .claude/skills/interlinked-supply-chain && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
interlinked-supply-chain
GitHub stars
178
Token cost
~2.8k tokens
SKILL.md length
1,243 words
Files
2
Skills in repo
12
Repo updated
First seen
Licence
MIT

At a glance

Respond to blocked package installs and manage the Interlinked supply-chain allowlist.

  • Works in 6 steps: Read the reason — it names the rule and… → Unpinned version? Add the exact version:… → Unapproved package? Stop and surface to… → …
  • Tasks that involve Supply chain security
  • SKILL.md covers Load this when, What gets blocked, When an install is blocked:… and Getting a package approved…, plus 4 more sections
  • Calls npm and pip

What it does

Interlinked Supply Chain is an agent skill from QuentinCody/interlinked-cli. Respond to blocked package installs and manage the Interlinked supply-chain allowlist. Load this when npm/pnpm/yarn/bun/pip/pipx/poetry/uv/cargo/gem/bundle/go/composer/mvn/dotnet install is BLOCKED with [interlinked:supply-chain], when adding a dependency to package.json / requirements.txt / pyproject.toml / Cargo.toml / go.mod is refused, when a version is rejected as "not an exact pin", when npm ci fails a lockfile-snapshot check, or when you need to approve a package (interlinked allowlist add), snapshot a…

Its SKILL.md is about 2.8k tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files (for example `agents/openai.yaml`).

It sits in Security, covering Supply chain security, Dependency management and Creative writing and fiction. It works with npm, Go, Rust and pnpm. The repository describes itself as: The harness for your harness. Local hooks, taste enforcement, and developer observability for AI coding agents (Claude Code, Codex, Cursor, Copilot CLI). The licence is MIT.

When your agent uses it

  • Tasks that involve Supply chain security
  • Tasks that involve Dependency management
  • Tasks that involve Creative writing and fiction

Example prompts

  • “not an exact pin”
  • “/interlinked-supply-chain”

Requirements

  • Python 3
  • Node.js

Workflow steps

6 steps, taken from the first numbered list in SKILL.md.

  1. Read the reason — it names the rule and the fix.
  2. Unpinned version? Add the exact version: npm install lodash@4.17.21 (only if lodash
  3. Unapproved package? Stop and surface to the human. State the package, version, and
  4. Snapshot mismatch (a sync like npm ci)? The manifest/lockfile changed vs the approved
  5. Custom registry? Drop the --registry/--index-url override; use the default registry.
  6. Daemon down ([harness-offline])? interlinked harness start, then retry.

What it can do on your machine

Read from SKILL.md and the folder at commit a2adc8a. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • npm
    • pip

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use npm and pip, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Interlinked Supply Chain loads about 2.8k tokens when it runs. Until then it costs about 169 tokens; SKILL.md has 1,243 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~169
When it runs · the whole SKILL.md, loaded when a task matches
~2.8k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from QuentinCody/interlinked-cli at commit a2adc8a, republished under its MIT licence (© QuentinCody). 1,243 words, ~2,777 tokens.

Download SKILL.mdSave it as .claude/skills/interlinked-supply-chain/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
interlinked-supply-chain
description
Respond to blocked package installs and manage the Interlinked supply-chain allowlist. Load this when `npm/pnpm/yarn/bun/pip/pipx/poetry/uv/cargo/gem/bundle/go/composer/mvn/dotnet` install is BLOCKED with `[interlinked:supply-chain]`, when adding a dependency to package.json / requirements.txt / pyproject.toml / Cargo.toml / go.mod is refused, when a version is rejected as "not an exact pin", when `npm ci` fails a lockfile-snapshot check, or when you need to approve a package (`interlinked allowlist add`), snapshot a lockfile, or verify deps. Package installs are default-deny; a package needs both allowlist membership AND an exact version pin.

interlinked-supply-chain — package installs are default-deny

In an Interlinked-guarded repo, every package install is blocked before it runs unless the exact package is pre-approved on .interlinked/package-allowlist.json. The stance: any new dependency is potentially malicious (a response to the npm/PyPI malware surge). You cannot install your way out, and you cannot silently self-approve. When blocked, the correct move is almost always to surface the need to the human, not to force-approve.

Two independent requirements for an install to pass: (a) the name is allowlisted AND (b) the version is an exact pin (pkg@1.2.3). An approved name at a floating version (lodash, lodash@^4, lodash@latest) is still blocked — a range can resolve to a newer, compromised release.

PyPI names use standard canonical spelling: case-insensitive, with runs of -, _ and . collapsed to -. PyYAML and pyyaml use the same grant. This does not authorize a different version. Conflicting legacy aliases fail closed; an authorized add replaces aliases with one canonical entry, and remove removes all aliases. Other ecosystems retain their own semantics. tests readiness python --json only proposes already-approved exact install argv; it never installs or adds an approval. Resolve missing grants through the existing operator boundary.

Load this when

  • A package install was blocked with [interlinked:supply-chain].
  • Editing a manifest (package.json, requirements.txt, pyproject.toml, Cargo.toml, go.mod, Gemfile, composer.json, *.csproj, …) to add a dep was refused.
  • npm ci / bare npm install / pip install -r fails a snapshot check.
  • You need to approve, snapshot, list, or verify allowlisted packages.

What gets blocked

ActionResultWhy
npm install left-pad (name not allowlisted)blocknot approved
npm install lodash / lodash@^4 / lodash@latestblocknot an exact pin (range/tag)
npm install lodash@4.17.21 (allowlisted + pinned)allow—
npm install --registry https://evil.tld pkg / --index-url …blockcustom registry bypasses signing
npm install git+https://… / tarball URL / file: specblocknever auto-approved (bypasses registry)
npm ci / bare npm install / pip install -r req.txt with no matching snapshotblocklockfile not snapshot-approved
Edit package.json to add "evil": "^1"blockmanifest-edit gate (a second, separate gate)
npm uninstall x / version bump of an existing depallownothing new enters
npm install ./local-dir (local path)allowin-workspace, version-controlled
install verb while the daemon is downblock (fail-closed)a dead guard is a security failure

Example block text:

[interlinked:supply-chain] npm add: 'left-pad' is not in the npm allowlist.
Run `interlinked allowlist add npm left-pad` after reviewing the package.

When an install is blocked: what to do

First, question the dependency — the cheapest approved package is the one you don't add. Confirm it's actually needed and not trivially replaceable (stdlib/native, or a dep already present); many "blocked install" situations are really "don't add this" (e.g. left-pad → native padStart). If it is warranted:

  1. Read the reason — it names the rule and the fix.
  2. Unpinned version? Add the exact version: npm install lodash@4.17.21 (only if lodash is already allowlisted).
  3. Unapproved package? Stop and surface to the human. State the package, version, and why you need it, and propose: interlinked allowlist add <ecosystem> <package> --by <human> --reason "…". Do not --force. Do not switch to editing the manifest (that's the second gate, also blocked).
  4. Snapshot mismatch (a sync like npm ci)? The manifest/lockfile changed vs the approved snapshot — a human re-runs interlinked allowlist snapshot --by <human>.
  5. Custom registry? Drop the --registry/--index-url override; use the default registry.
  6. Daemon down ([harness-offline])? interlinked harness start, then retry.

Getting a package approved (human sign-off operations)

An agent can record a request without granting approval:

bash
interlinked allowlist propose npm example-package --package-version 1.2.3 --reason "Needed for the public API" --json

This writes a pending record under .interlinked/package-proposals/. It does not contact a registry, install anything, change the allowlist, or send a message. Writer identity remains unknown. Surface the concrete request for operator review; the operator provisions approval separately. In an externally frozen deployment, approval files and their path ancestors must be protected by the supervisor while proposal/receipt state stays writable. A same-UID local daemon and a proposal label do not establish that boundary.

bash
interlinked allowlist add <ecosystem> <package> --by <name> [--reason <t>] [--version-range <r>] [--force]

--by is required. Ecosystems: npm, pypi, cargo, rubygems, go, composer, maven, gradle, nuget. --by is an attribution label, not authenticated approval. The local writable allowlist does not enforce an immutable-policy experiment: an agent with the same filesystem authority can change it. Such a deployment needs policy owned outside the agent's write scope (including its parent directory), with direct edits, replacement and CLI writes tested against that boundary. Guidance to request approval is not that boundary. add runs three admission screens (cheapest first) and refuses without --force if any fires:

  1. Typosquat (npm only, offline) — Levenshtein ≤2 to a popular package name.
  2. License (network) — the version's declared SPDX license vs the committed license_allowlist (recorded on the entry, re-checked later at manifest-edit time).
  3. OSV advisories (network, api.osv.dev) — open vulnerabilities against the version.

--force = "I reviewed this and accept the risk"; it records the finding as a note instead of refusing. An agent should not --force on its own initiative — approving a bad package is the worst failure mode (install then proceeds silently). Surface the screen output to the human. Screens 2–3 fail open with a loud note: when offline — a clean add with "screen skipped" notes did not pass those screens.

Whole-lockfile approval (unblocks npm ci / bare install / pip install -r):

bash
interlinked allowlist snapshot --by <name> [--lockfile <name>]   # sha256 every manifest+lockfile in cwd

Re-snapshot whenever the manifest/lockfile changes — the gate matches on exact hash.

Show full SKILL.md (401 more words)Show less

Command surface

CommandPurpose
interlinked allowlist add <eco> <pkg> --by <name> [--reason] [--version-range] [--force]Approve one package (3 screens).
interlinked allowlist remove <eco> <pkg>Delete an entry.
interlinked allowlist list [--ecosystem <e>] [--json]Show approved packages + snapshots.
interlinked allowlist snapshot --by <name> [--lockfile <n>]Hash + store manifest/lockfile state.
interlinked allowlist verifyDiff every committed manifest's deps vs the allowlist; exits 1 on any unapproved (CI-gateable).

Allowlist file format — .interlinked/package-allowlist.json (committed, PR-reviewed)

json
{
  "version": 1,
  "packages": { "npm": { "lodash": { "approved_by": "qcody", "reason": "utility",
                                      "version_range": "^4.0.0", "license": "MIT" } }, "pypi": {}, … },
  "lockfile_snapshots": { "package-lock.json": { "sha256": "…", "approved_by": "qcody" } },
  "license_allowlist": ["MIT", "Apache-2.0", …]
}

Malformed JSON loads as an empty allowlist (fail-safe: never blocks bootstrap on syntax; verify surfaces the parse error separately). A per-package version_range additionally constrains which requested version passes. license_allowlist is optional — when absent (as in a minimal file), admission falls back to a permissive built-in default seed.

Gotchas

  • Fail-closed when the daemon is down. The cold paths block installs (the coarse .mjs path blocks all install verbs and tells you to interlinked harness start).
  • Exact-pin is separate from membership. An allowlisted name is still blocked at a floating version. Pin grammar is per-ecosystem (npm/cargo/go need full major.minor.patch; PyPI ==24.2; RubyGems '7.1'; Maven/Gradle reject -SNAPSHOT).
  • Manifest-edit is a distinct gate. Get the package approved first, then edit the manifest, then install at the pin. Flipping a dep to a git/path/URL source counts as new → blocked. A plain version bump of an existing dep is allowed. Supported manifest classifiers retain a dependency's exact registry version when checking a version-scoped approval. For example, PyYAML==6.0.2 can satisfy an approval for 6.0.2; it is not treated as an unspecified request. Python extras and environment markers do not supply the package version. A wrong, missing or ambiguous pin cannot borrow a version from a marker, URL or nested table. This does not add unsupported manifest syntaxes or authorize an agent to approve its own dependencies.
  • interlinked audit is NOT this. It's the tamper-evident guard-decision log (see interlinked-observability). The dependency-vuln (SCA) lane runs in the default interlinked verify (the dep-audit tool, npm audit-based). Membership auditing = interlinked allowlist verify.
  • A few harness dev-tools are pre-allowed for membership (npm vitest/@vitest/coverage-v8/ @vitest/coverage-istanbul; pypi pytest/pytest-cov/coverage/radon) so the coverage gate isn't a catch-22 — they still need an exact pin. Everything else is default-deny.
  • --ignore-scripts warn still fires on allowlisted installs (defense-in-depth).
  • Env bypass INTERLINKED_DISABLE_PACKAGE_GUARD=1 is logged and defeats the whole layer for that command — for documented bootstrap flows only, not for getting unstuck.
  • interlinked-harness — the general PreToolUse guard this gate is part of.
  • interlinked-observability — interlinked audit (the guard-log integrity check).

© QuentinCody, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file in skills/interlinked-supply-chain of QuentinCody/interlinked-cli.

  • SKILL.md
  • agents/openai.yaml

Open the folder on GitHubat commit a2adc8a

Compare with similar skills

Interlinked Supply Chain next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Interlinked Supply Chain compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Interlinked Supply Chain this skillQuentinCody/interlinked-cli178—~2.8kAutomated safety check: PassMIT
Uv WorkflowAedelon/claude-code-blueprint120—~1.2kAutomated safety check: NotesCustom licence
npm Supply Chain Securitybodadotsh/npm-security-best-practices858—~1kAutomated safety check: WarnMIT
Detecting Typosquatting Packagesmukul975/Anthropic-Cybersecurity-Skills34k—~3kAutomated safety check: PassApache-2.0
Memstack Security Dependency Auditcwinvestments/memstack423—~3.1kAutomated safety check: PassProprietary
Sca AuditOWASP/secure-agent-playbook188—~494Automated safety check: PassCC-BY-4.0

Similar skills

  • Uv Workflow

    Aedelon/claude-code-blueprint

    Master uv package manager for Python: project setup, dependency management, virtual environments, lockfiles, CI/CD integration, Docker builds, and migration from pip/poetry.

    120 GitHub stars~1.2k tokensUpdated 7 mo ago
    DevOps & CloudAuto-check: notes
  • npm Supply Chain Security

    bodadotsh/npm-security-best-practices

    Applies safer package manager defaults and dependency vetting to JavaScript and TypeScript projects to reduce supply-chain attack risk.

    858 GitHub stars~1k tokensUpdated 9 days ago
    SecurityAuto-check: warnings
  • Detecting Typosquatting Packages

    mukul975/Anthropic-Cybersecurity-Skills

    Flag misspelled, brandjacked, and typosquatted package names across npm, PyPI, and crates.io before installation, using edit-distance, keyboard-proximity, and known-target corpus matching with…

    34k GitHub stars~3k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • A skill your agent uses when the user says 'dependency audit', 'npm audit', 'pip audit', 'cargo audit', 'security vulnerabilities', 'outdated packages', 'supply chain', or needs to scan project…

    423 GitHub stars~3.1k tokensUpdated 13 days ago
    SecurityAuto-check passed
  • Sca Audit

    OWASP/secure-agent-playbook

    Scan project dependencies for known vulnerabilities (CVEs). An agent skill from OWASP/secure-agent-playbook.

    188 GitHub stars~494 tokensUpdated 14 days ago
    SecurityAuto-check passed
  • Dependency Awareness

    Goldziher/ai-rulez

    Per-language dependency vulnerability audit tool reference (cargo audit/deny, pip-audit, npm/pnpm audit, govulncheck, bundler-audit, composer audit, OWASP dependency-check, dotnet vulnerable…

    159 GitHub stars~250 tokensUpdated today
    SecurityAuto-check passed

More from QuentinCody/interlinked-cli

All 12 skills in this repo
  • Interlinked Cowork

    QuentinCody/interlinked-cli

    Package, test, and operate the experimental Interlinked Cowork plugin.

    178 GitHub stars~1.6k tokensUpdated yesterday
    Auto-check passed
  • Interlinked

    QuentinCody/interlinked-cli

    Overview and router for the Interlinked CLI — a local guard, quality-enforcement, simplification-review, semantic-code-search, and observability layer for AI coding agents.

    178 GitHub stars~4.1k tokensUpdated yesterday
    Auto-check passed
  • Interlinked Coordination

    QuentinCody/interlinked-cli

    Coordinate with other agents/humans via the optional Interlinked MCP Server, and use local checkpoints & file reservations.

    178 GitHub stars~2.9k tokensUpdated yesterday
    Auto-check passed
  • Interlinked Observability

    QuentinCody/interlinked-cli

    Investigate agent activity and JSONL/gzip evidence. An agent skill from QuentinCody/interlinked-cli.

    178 GitHub stars~10k tokensUpdated yesterday
    Auto-check passed
  • Interlinked Semantic Index

    QuentinCody/interlinked-cli

    Install and operate Interlinked's optional local semantic function index.

    178 GitHub stars~1.7k tokensUpdated yesterday
    Auto-check passed
  • Interlinked Spec Audit

    QuentinCody/interlinked-cli

    Keep prose specs and design docs honest against the code using Interlinked's spec-audit system.

    178 GitHub stars~3.3k tokensUpdated yesterday
    Auto-check passed

Categories

Questions about Interlinked Supply Chain

What does Interlinked Supply Chain do?

Respond to blocked package installs and manage the Interlinked supply-chain allowlist. Interlinked Supply Chain is an agent skill from QuentinCody/interlinked-cli. Respond to blocked package installs and manage the Interlinked supply-chain allowlist.

When should I use Interlinked Supply Chain?

Interlinked Supply Chain fits situations like: tasks that involve Supply chain security; tasks that involve Dependency management; tasks that involve Creative writing and fiction.

How do I install Interlinked Supply Chain in Claude Code?

Run `npx skills add QuentinCody/interlinked-cli --skill interlinked-supply-chain -a claude-code`. Or copy the skill folder (skills/interlinked-supply-chain in QuentinCody/interlinked-cli) into .claude/skills/interlinked-supply-chain in your project. Claude Code loads it when a task matches its description.

How do I install Interlinked Supply Chain in Codex?

Run `npx skills add QuentinCody/interlinked-cli --skill interlinked-supply-chain -a codex`. Or copy the skill folder (skills/interlinked-supply-chain in QuentinCody/interlinked-cli) into .agents/skills/interlinked-supply-chain in your project. Codex loads it when a task matches its description.

Can I use Interlinked Supply Chain in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add QuentinCody/interlinked-cli --skill interlinked-supply-chain -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/interlinked-supply-chain, .gemini/skills/interlinked-supply-chain, .github/skills/interlinked-supply-chain and .opencode/skills/interlinked-supply-chain in your project.

What does Interlinked Supply Chain need to run?

Going by SKILL.md and its folder, Interlinked Supply Chain needs the command-line tools its instructions call (npm and pip). Our summary lists: Python 3; Node.js.

Does Interlinked Supply Chain access the network?

SKILL.md contains no URLs. Its commands use npm and pip, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Interlinked Supply Chain safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Interlinked Supply Chain use?

Interlinked Supply Chain is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Interlinked Supply Chain use?

About 2.8k tokens (SKILL.md is roughly 11k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Interlinked Supply Chain?

Skills that share tags, products or a category with Interlinked Supply Chain: Uv Workflow (Aedelon/claude-code-blueprint, 120 stars), npm Supply Chain Security (bodadotsh/npm-security-best-practices, 858 stars), Detecting Typosquatting Packages (mukul975/Anthropic-Cybersecurity-Skills, 34k stars) and Memstack Security Dependency Audit (cwinvestments/memstack, 423 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Interlinked Supply Chain?

QuentinCody (a GitHub user) maintains it in QuentinCody/interlinked-cli, which has 178 GitHub stars. The repository holds 12 skills in this directory. The repository was last updated on October 9, 2026.

Source: QuentinCody/interlinked-cli on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.