Topic · Security
Best supply chain security skills for Claude Code, Codex and other agents.
- skills
- 233
- official
- 15
Supply chain security skills, ranked
Ranked by score. Sort bymost stars,trending,newest,recently updated
| # | Skill | Repository | Stars | Used in | Tokens | Auto-check | Licence | Updated |
|---|---|---|---|---|---|---|---|---|
| 1 | Decides whether an agent skill is safe to install by combining a SkillSpector static scan with the agent's own source review, ending in APPROVE, CAUTION or REJECT. | NVIDIA/ | 20k | 1 repo | ~1.8k | Automated safety check: Pass | Apache-2.0 | today |
| 2 | Plan and apply Go dependency updates, including advisory-driven bumps, Trivy/govulncheck validation, and supply-chain review. | trufflesecurity/ | 28k | — | ~1.3k | Automated safety check: Pass | AGPL-3.0 | today |
| 3 | Scan agent skills for security issues. An agent skill from getsentry/skills. | getsentry/ | 1k | 4 repos | ~2.5k | Automated safety check: Warn | Apache-2.0 | 5 days ago |
| 4 | Apply trader Serenity's (@aleabitoreddit) AI/semiconductor supply-chain analytical lens to US-stock ideas and market judgment. | yan-labs/ | 480 | 1 repo | ~3.3k | Automated safety check: Pass | No licence | 6 days ago |
| 5 | A skill your agent uses for software supply-chain security assessment covering SBOM, SCA, CI/CD pipelines, container images, build integrity, dependency provenance, and vulnerability reachability. | zhaoxuya520/ | 40k | 4 repos | ~953 | Automated safety check: Warn | MIT | 15 days ago |
| 6 | A skill your agent uses when modifying, testing, documenting, or reviewing the Vulners Python SDK. | vulnersCom/ | 375 | — | ~2.3k | Automated safety check: Pass | MIT | 9 days ago |
| 7 | 7.Eu Cra Expert EU Cyber Resilience Act (CRA) advisor for Regulation (EU) 2024/2847 — mandatory cybersecurity and vulnerability handling requirements for all products with digital elements (PDEs) sold in the… | Sushegaad/ | 942 | 1 repo | ~4k | Automated safety check: Pass | MIT | 3 days ago |
| 8 | A skill your agent uses when editing, adding, or reviewing any file under .github/workflows/, or when a CI step installs a CLI tool (npm i -g, npx, pipx, uses: /setup-). | asyncapi/ | 1.1k | — | ~1.9k | Automated safety check: Pass | Apache-2.0 | 2 days ago |
| 9 | Reviews Renovate pull requests that bump GitHub Actions by checking pinned SHAs against upstream tags, scanning changelogs and confirming workflows stay compatible. | backnotprop/ | 9.2k | — | ~640 | Automated safety check: Pass | Apache-2.0 | today |
| 10 | A skill your agent uses to turn an AI idea or existing repository into a credible open-source product and to run evidence-first repository engineering across codebase discovery, context-efficient… | sun461941-hub/ | 100 | — | ~3k | Automated safety check: Pass | MIT | 1 mo ago |
| 11 | 11.AI Bom Generates AI-BOM, MCP inventory, AI skill inventory, and AI authorship provenance documents with cdxgen, cataloging models, inference services, Hugging Face purls, MCP servers and their… | cdxgen/ | 1.1k | — | ~2.5k | Automated safety check: Pass | Apache-2.0 | today |
| 12 | Run a pre-deployment security compliance checklist based on KISA guidelines. | cdppcorp/ | 361 | — | ~1.3k | Automated safety check: Pass | MIT | 6 mo ago |
| 13 | A skill your agent uses when analyzing stocks through @aleabitoreddit/Serenity-style supply-chain chokepoint thinking: AI/semi photonics, scarce physical bottlenecks, small-cap monopoly or duopoly… | W-Y-P/ | 118 | — | ~2.8k | Automated safety check: Pass | MIT | 3 mo ago |
| 14 | GitHub Actions security review for workflow exploitation vulnerabilities. | getsentry/ | 1k | 3 repos | ~2.2k | Automated safety check: Notes | Apache-2.0 | 5 days ago |
| 15 | 15.Bom Audit Runs supply-chain risk analysis on CycloneDX BOMs with cdx-audit predictive auditing and cdxgen --bom-audit embedded rules, covering npm and PyPI package compromise posture, CI permission risk… | cdxgen/ | 1.1k | — | ~2.4k | Automated safety check: Pass | Apache-2.0 | today |
| 16 | Applies safer package manager defaults and dependency vetting to JavaScript and TypeScript projects to reduce supply-chain attack risk. | bodadotsh/ | 859 | — | ~1k | Automated safety check: Warn | MIT | 7 days ago |
| 17 | 17.Packslip Configure signed release manifests with packslip: add the jdx/packslip action or packslip create to a release workflow, declare completions, man pages, CLI specs, skills, and SBOMs as resources, and… | jdx/ | 130 | — | ~2.9k | Automated safety check: Pass | MIT | yesterday |
| 18 | Author CycloneDX-VEX or OpenVEX documents that import cleanly into ReARM. | relizaio/ | 127 | — | ~2.9k | Automated safety check: Pass | AGPL-3.0 | today |
| 19 | Supply chain investigation, evidence recovery, and forensic analysis for GitHub repositories. | Tommy-yw/ | 546 | 3 repos | ~5k | Automated safety check: Pass | MIT | 4 mo ago |
| 20 | 20.Attack Flow Generate SITF-compliant attack flow JSON files from attack descriptions or incident reports. | wiz-sec-public/ | 182 | — | ~3.1k | Automated safety check: Pass | Unknown | 2 mo ago |
| 21 | Applies a threat-model-first approach to web code that handles untrusted input, authentication, data storage, dependencies or personal data. | addyosmani/ | 103k | 1 repo | ~4.4k | Automated safety check: Notes | MIT | 4 days ago |
| 22 | 22.Cyber Neo Comprehensive cybersecurity analysis for any local project. An agent skill from Hainrixz/cyber-neo. | Hainrixz/ | 281 | — | ~5.9k | Automated safety check: Warn | MIT | 2 mo ago |
| 23 | 23.Kesekit Fix Auto-fix security vulnerabilities found in CII, AI, robot, space, and supply chain systems. | cdppcorp/ | 361 | — | ~1.1k | Automated safety check: Pass | MIT | 6 mo ago |
| 24 | 24.Nist 800 53 NIST SP 800-53 Rev 5 compliance advisor — all 20 control families (AC, AT, AU, CA, CM, CP, IA, IR, MA, MP, PE, PL, PM, PS, PT, RA, SA, SC, SI, SR), Low/Moderate/High baseline selection, FIPS 199/200… | Sushegaad/ | 942 | 1 repo | ~3.3k | Automated safety check: Pass | MIT | 3 days ago |
| 25 | Serenity (@aleabitoreddit) 的思维框架与表达方式。基于 6 维度深度调研(1700+ 推文、Substack 长访谈、第三方分析、批评者观点), 提炼 5 个核心心智模型、8 条决策启发式和完整的表达 DNA。 | leslieyeo/ | 136 | — | ~3k | Automated safety check: Pass | MIT | 4 mo ago |
| 26 | Pin the npm registry to the public default and fetch published release notes | cisco-ai-defense/ | 2.6k | 1 repo | ~180 | Automated safety check: Notes | Apache-2.0 | 2 days ago |
| 27 | 27.Docs Update project documentation when features are added or changed. | boostsecurityio/ | 523 | — | ~336 | Automated safety check: Pass | Apache-2.0 | yesterday |
| 28 | Translate market-moving news into investable alpha hypotheses by mapping observed demand changes to revenue lines, supply chains, small-cap financial elasticity, market misclassification, validation… | haskaomni/ | 632 | — | ~2.6k | Automated safety check: Pass | MIT | 2 mo ago |
| 29 | Audits outdated npm and Bun packages for supply chain integrity before bumping them, deferring risky ones and logging every decision. | backnotprop/ | 9.2k | — | ~1.8k | Automated safety check: Pass | Apache-2.0 | today |
| 30 | Gathers security findings from Dependabot, GCP container scanning, Docker Scout and Linear security issues, then triages and remediates them across Warp's repos and images. | warpdotdev/ | 65k | 1 repo | ~2.1k | Automated safety check: Pass | AGPL-3.0 | today |
| 31 | Secure dependency upgrades with supply chain protection, cooldowns, and staged rollout. | secondsky/ | 462 | — | ~4.8k | Automated safety check: Warn | GPL-3.0 | 2 days ago |
| 32 | PaiWork-first Serenity (@aleabitoreddit) investment thesis tracking system. | AlphaMao1/ | 130 | — | ~1.8k | Automated safety check: Pass | MIT | 14 days ago |
| 33 | Generate and manage Software Bill of Materials (SBOMs) for the OpenShell project. | NVIDIA/ | 15k | — | ~1.3k | Automated safety check: Pass | Apache-2.0 | today |
| 34 | Bootstrap a development environment and configure the corporate package mirror | cisco-ai-defense/ | 2.6k | 1 repo | ~126 | Automated safety check: Notes | Apache-2.0 | 2 days ago |
| 35 | 35.Bom Explore Explores and triages a CycloneDX BOM interactively with the cdxi REPL, using built-in commands for dependency trees, licenses, services, cryptographic assets, audit findings, evidence occurrences… | cdxgen/ | 1.1k | — | ~1.2k | Automated safety check: Pass | Apache-2.0 | today |
| 36 | A skill your agent uses for every trust-platform behavior change, bug fix, refactor, malformed input, runtime safety, VS Code, hardware, docs, or supply-chain task that requires a written… | johannesPettersson80/ | 221 | — | ~939 | Automated safety check: Pass | Apache-2.0 | today |
| 37 | Generate secure coding prompts and guides for AI tools (Claude, ChatGPT, Cursor, Copilot). | cdppcorp/ | 361 | — | ~1.4k | Automated safety check: Pass | MIT | 6 mo ago |
| 38 | Use HOL Guard to preview and protect AI-agent package installs, Cursor surfaces, CI, and automation workflows. | hashgraph-online/ | 815 | — | ~605 | Automated safety check: Pass | Apache-2.0 | today |
| 39 | Runs a security health check on an OpenClaw environment and audits skills before or after installation for supply-chain and data-leak risks. | Tencent/ | 6.8k | — | ~9.5k | Automated safety check: Pass | MIT | today |
| 40 | Bootstrap a development environment and set the npm registry to https://npm.artifacts-mirror.internal-corp.dev | cisco-ai-defense/ | 2.6k | 1 repo | ~169 | Automated safety check: Notes | Apache-2.0 | 2 days ago |
| 41 | 41.Bom Signing Signs and verifies CycloneDX BOMs using cdxgen's native JSON Signature Format (JSF) implementation via cdx-sign and cdx-verify, supporting granular component, service, and annotation signatures… | cdxgen/ | 1.1k | — | ~1.5k | Automated safety check: Pass | Apache-2.0 | today |
| 42 | 42.Interlinked Overview and router for the Interlinked CLI — a local guard, quality-enforcement, simplification-review, semantic-code-search, and observability layer for AI coding agents. | QuentinCody/ | 178 | — | ~4.1k | Automated safety check: Pass | MIT | 5 days ago |
| 43 | Advanced vulnerability analysis principles. An agent skill from xenitV1/Antigravity-Workflows. | xenitV1/ | 130 | 7 repos | ~1.8k | Automated safety check: Notes | MIT | 8 mo ago |
| 44 | SAP dependency security and MCP executable trust policy with secure upgrades, cooldowns, staged rollout, and supply-chain protection. | secondsky/ | 462 | — | ~5.9k | Automated safety check: Warn | GPL-3.0 | 2 days ago |
| 45 | Converts CycloneDX BOMs to SPDX 3.0.1 JSON-LD or between CycloneDX spec versions with cdx-convert, and validates BOMs against JSON schema, deep consistency checks, and OWASP SCVS and EU Cyber… | cdxgen/ | 1.1k | — | ~1.5k | Automated safety check: Warn | Apache-2.0 | today |
| 46 | End-to-end release runbook for playwright-rust — version bump, supply-chain refresh, per-crate CHANGELOGs, tag-prefix routing for the three workspace crates, the safer push-then-tag workflow that… | padamson/ | 153 | — | ~4.1k | Automated safety check: Pass | Apache-2.0 | 3 days ago |
| 47 | Verify regular or extended-stable OpenClaw releases against the exact publication surfaces, workflow identities, package provenance, smoke tests, and live Gateway behavior expected for that release… | openclaw/ | 392k | — | ~2.4k | Automated safety check: Pass | MIT | today |
| 48 | Scans container images, filesystems and SBOMs with Grype for known vulnerabilities, ranks them by CVSS, EPSS and CISA KEV, and wires scans into CI/CD thresholds. | AgentSecOps/ | 220 | 1 repo | ~2.5k | Automated safety check: Pass | Unknown | 5 mo ago |
Questions, answered from the data.
What is the best supply chain security skill?
Skill Inspector (official) from NVIDIA/SkillSpector ranks first of the 233 supply chain security skills listed here, with the highest score: its repository has 20k GitHub stars, 1 other GitHub owner carry a copy, its SKILL.md loads about 1.8k tokens and it passes the automated safety check with no findings. Next come Dep Updates and Skill Scanner.
Which supply chain security skills are official?
15 of the 233 supply chain security skills are official, published by the vendor's own GitHub organization: Skill Inspector, Skill Scanner, Gha Security Review, Sbom, Vibe CI Supply Chain and 10 more.
How are these skills ranked?
By Skill Navigator score, which combines the GitHub stars of the skill's repository (shared across that repo's skills and discounted for large collections), how many other GitHub owners carry a copy of the skill, and automated SKILL.md quality checks, minus penalties for safety-check warnings and for each further skill from the same repository. Skills that fail the safety check are not listed.
Explore related skills
Category
More topics in Security
- Security review611
- Web application vulnerabilities460
- Vulnerability scanning303
- Static analysis and SAST281
- Security operations248
- Threat modeling207
- Penetration testing183
- Cryptography155
- Prompt injection and agent security154
- Red teaming and adversary simulation147
- Reverse engineering and malware132
- OSINT117
- Secure coding105
- Cloud security90
- Digital forensics86
- Smart contract auditing80
- Fuzzing75
- Bug bounty74
- Network security66
- Capture the flag45
- Mobile application security42
- Access reviews and audit trails34