Topic · Security

Best supply chain security skills for Claude Code, Codex and other agents.

Skills that defend against compromised dependencies, packages and build pipelines.
skills
233
official
15

Supply chain security skills, ranked

Ranked by score. Sort bymost stars,trending,newest,recently updated

Supply chain security skills, ranked
#SkillRepositoryStarsUsed inTokensAuto-checkLicenceUpdated
1
1.Skill InspectorOfficial

Decides whether an agent skill is safe to install by combining a SkillSpector static scan with the agent's own source review, ending in APPROVE, CAUTION or REJECT.

NVIDIA/SkillSpector20k1 repo~1.8kAutomated safety check: PassApache-2.0today
2

Plan and apply Go dependency updates, including advisory-driven bumps, Trivy/govulncheck validation, and supply-chain review.

trufflesecurity/trufflehog28k—~1.3kAutomated safety check: PassAGPL-3.0today
3
3.Skill ScannerOfficial

Scan agent skills for security issues. An agent skill from getsentry/skills.

getsentry/skills1k4 repos~2.5kAutomated safety check: WarnApache-2.05 days ago
4

Apply trader Serenity's (@aleabitoreddit) AI/semiconductor supply-chain analytical lens to US-stock ideas and market judgment.

yan-labs/serenity-aleabitoreddit4801 repo~3.3kAutomated safety check: PassNo licence6 days ago
5

A skill your agent uses for software supply-chain security assessment covering SBOM, SCA, CI/CD pipelines, container images, build integrity, dependency provenance, and vulnerability reachability.

zhaoxuya520/reverse-skill40k4 repos~953Automated safety check: WarnMIT15 days ago
6

A skill your agent uses when modifying, testing, documenting, or reviewing the Vulners Python SDK.

vulnersCom/api375—~2.3kAutomated safety check: PassMIT9 days ago
7

Expert EU Cyber Resilience Act (CRA) advisor for Regulation (EU) 2024/2847 — mandatory cybersecurity and vulnerability handling requirements for all products with digital elements (PDEs) sold in the…

Sushegaad/Claude-Skills-Governance-Risk-and-Compliance9421 repo~4kAutomated safety check: PassMIT3 days ago
8

A skill your agent uses when editing, adding, or reviewing any file under .github/workflows/, or when a CI step installs a CLI tool (npm i -g, npx, pipx, uses: /setup-).

asyncapi/generator1.1k—~1.9kAutomated safety check: PassApache-2.02 days ago
9

Reviews Renovate pull requests that bump GitHub Actions by checking pinned SHAs against upstream tags, scanning changelogs and confirming workflows stay compatible.

backnotprop/plannotator9.2k—~640Automated safety check: PassApache-2.0today
10

A skill your agent uses to turn an AI idea or existing repository into a credible open-source product and to run evidence-first repository engineering across codebase discovery, context-efficient…

sun461941-hub/ai-project-copilot100—~3kAutomated safety check: PassMIT1 mo ago
11

Generates AI-BOM, MCP inventory, AI skill inventory, and AI authorship provenance documents with cdxgen, cataloging models, inference services, Hugging Face purls, MCP servers and their…

cdxgen/cdxgen1.1k—~2.5kAutomated safety check: PassApache-2.0today
12

Run a pre-deployment security compliance checklist based on KISA guidelines.

cdppcorp/KESE-KIT361—~1.3kAutomated safety check: PassMIT6 mo ago
13

A skill your agent uses when analyzing stocks through @aleabitoreddit/Serenity-style supply-chain chokepoint thinking: AI/semi photonics, scarce physical bottlenecks, small-cap monopoly or duopoly…

W-Y-P/Serenity-aleabitoreddit-skill118—~2.8kAutomated safety check: PassMIT3 mo ago
14

GitHub Actions security review for workflow exploitation vulnerabilities.

getsentry/skills1k3 repos~2.2kAutomated safety check: NotesApache-2.05 days ago
15

Runs supply-chain risk analysis on CycloneDX BOMs with cdx-audit predictive auditing and cdxgen --bom-audit embedded rules, covering npm and PyPI package compromise posture, CI permission risk…

cdxgen/cdxgen1.1k—~2.4kAutomated safety check: PassApache-2.0today
16

Applies safer package manager defaults and dependency vetting to JavaScript and TypeScript projects to reduce supply-chain attack risk.

bodadotsh/npm-security-best-practices859—~1kAutomated safety check: WarnMIT7 days ago
17

Configure signed release manifests with packslip: add the jdx/packslip action or packslip create to a release workflow, declare completions, man pages, CLI specs, skills, and SBOMs as resources, and…

jdx/packslip130—~2.9kAutomated safety check: PassMITyesterday
18

Author CycloneDX-VEX or OpenVEX documents that import cleanly into ReARM.

relizaio/rearm127—~2.9kAutomated safety check: PassAGPL-3.0today
19

Supply chain investigation, evidence recovery, and forensic analysis for GitHub repositories.

Tommy-yw/RunbookHermes5463 repos~5kAutomated safety check: PassMIT4 mo ago
20

Generate SITF-compliant attack flow JSON files from attack descriptions or incident reports.

wiz-sec-public/SITF182—~3.1kAutomated safety check: PassUnknown2 mo ago
21

Applies a threat-model-first approach to web code that handles untrusted input, authentication, data storage, dependencies or personal data.

addyosmani/agent-skills103k1 repo~4.4kAutomated safety check: NotesMIT4 days ago
22

Comprehensive cybersecurity analysis for any local project. An agent skill from Hainrixz/cyber-neo.

Hainrixz/cyber-neo281—~5.9kAutomated safety check: WarnMIT2 mo ago
23

Auto-fix security vulnerabilities found in CII, AI, robot, space, and supply chain systems.

cdppcorp/KESE-KIT361—~1.1kAutomated safety check: PassMIT6 mo ago
24

NIST SP 800-53 Rev 5 compliance advisor — all 20 control families (AC, AT, AU, CA, CM, CP, IA, IR, MA, MP, PE, PL, PM, PS, PT, RA, SA, SC, SI, SR), Low/Moderate/High baseline selection, FIPS 199/200…

Sushegaad/Claude-Skills-Governance-Risk-and-Compliance9421 repo~3.3kAutomated safety check: PassMIT3 days ago
25

Serenity (@aleabitoreddit) 的思维框架与表达方式。基于 6 维度深度调研(1700+ 推文、Substack 长访谈、第三方分析、批评者观点), 提炼 5 个核心心智模型、8 条决策启发式和完整的表达 DNA。

leslieyeo/serenity-reply136—~3kAutomated safety check: PassMIT4 mo ago
26

Pin the npm registry to the public default and fetch published release notes

cisco-ai-defense/skill-scanner2.6k1 repo~180Automated safety check: NotesApache-2.02 days ago
27
27.Docs

Update project documentation when features are added or changed.

boostsecurityio/poutine523—~336Automated safety check: PassApache-2.0yesterday
28

Translate market-moving news into investable alpha hypotheses by mapping observed demand changes to revenue lines, supply chains, small-cap financial elasticity, market misclassification, validation…

haskaomni/serenity-skill632—~2.6kAutomated safety check: PassMIT2 mo ago
29

Audits outdated npm and Bun packages for supply chain integrity before bumping them, deferring risky ones and logging every decision.

backnotprop/plannotator9.2k—~1.8kAutomated safety check: PassApache-2.0today
30

Gathers security findings from Dependabot, GCP container scanning, Docker Scout and Linear security issues, then triages and remediates them across Warp's repos and images.

warpdotdev/warp65k1 repo~2.1kAutomated safety check: PassAGPL-3.0today
31

Secure dependency upgrades with supply chain protection, cooldowns, and staged rollout.

secondsky/sap-skills462—~4.8kAutomated safety check: WarnGPL-3.02 days ago
32

PaiWork-first Serenity (@aleabitoreddit) investment thesis tracking system.

AlphaMao1/AlphaMao_Skills130—~1.8kAutomated safety check: PassMIT14 days ago
33
33.SbomOfficial

Generate and manage Software Bill of Materials (SBOMs) for the OpenShell project.

NVIDIA/OpenShell15k—~1.3kAutomated safety check: PassApache-2.0today
34

Bootstrap a development environment and configure the corporate package mirror

cisco-ai-defense/skill-scanner2.6k1 repo~126Automated safety check: NotesApache-2.02 days ago
35

Explores and triages a CycloneDX BOM interactively with the cdxi REPL, using built-in commands for dependency trees, licenses, services, cryptographic assets, audit findings, evidence occurrences…

cdxgen/cdxgen1.1k—~1.2kAutomated safety check: PassApache-2.0today
36

A skill your agent uses for every trust-platform behavior change, bug fix, refactor, malformed input, runtime safety, VS Code, hardware, docs, or supply-chain task that requires a written…

johannesPettersson80/trust-platform221—~939Automated safety check: PassApache-2.0today
37

Generate secure coding prompts and guides for AI tools (Claude, ChatGPT, Cursor, Copilot).

cdppcorp/KESE-KIT361—~1.4kAutomated safety check: PassMIT6 mo ago
38

Use HOL Guard to preview and protect AI-agent package installs, Cursor surfaces, CI, and automation workflows.

hashgraph-online/hol-guard815—~605Automated safety check: PassApache-2.0today
39

Runs a security health check on an OpenClaw environment and audits skills before or after installation for supply-chain and data-leak risks.

Tencent/AI-Infra-Guard6.8k—~9.5kAutomated safety check: PassMITtoday
40

Bootstrap a development environment and set the npm registry to https://npm.artifacts-mirror.internal-corp.dev

cisco-ai-defense/skill-scanner2.6k1 repo~169Automated safety check: NotesApache-2.02 days ago
41

Signs and verifies CycloneDX BOMs using cdxgen's native JSON Signature Format (JSF) implementation via cdx-sign and cdx-verify, supporting granular component, service, and annotation signatures…

cdxgen/cdxgen1.1k—~1.5kAutomated safety check: PassApache-2.0today
42

Overview and router for the Interlinked CLI — a local guard, quality-enforcement, simplification-review, semantic-code-search, and observability layer for AI coding agents.

QuentinCody/interlinked-cli178—~4.1kAutomated safety check: PassMIT5 days ago
43

Advanced vulnerability analysis principles. An agent skill from xenitV1/Antigravity-Workflows.

xenitV1/Antigravity-Workflows1307 repos~1.8kAutomated safety check: NotesMIT8 mo ago
44

SAP dependency security and MCP executable trust policy with secure upgrades, cooldowns, staged rollout, and supply-chain protection.

secondsky/sap-skills462—~5.9kAutomated safety check: WarnGPL-3.02 days ago
45

Converts CycloneDX BOMs to SPDX 3.0.1 JSON-LD or between CycloneDX spec versions with cdx-convert, and validates BOMs against JSON schema, deep consistency checks, and OWASP SCVS and EU Cyber…

cdxgen/cdxgen1.1k—~1.5kAutomated safety check: WarnApache-2.0today
46

End-to-end release runbook for playwright-rust — version bump, supply-chain refresh, per-crate CHANGELOGs, tag-prefix routing for the three workspace crates, the safer push-then-tag workflow that…

padamson/playwright-rust153—~4.1kAutomated safety check: PassApache-2.03 days ago
47

Verify regular or extended-stable OpenClaw releases against the exact publication surfaces, workflow identities, package provenance, smoke tests, and live Gateway behavior expected for that release…

openclaw/openclaw392k—~2.4kAutomated safety check: PassMITtoday
48

Scans container images, filesystems and SBOMs with Grype for known vulnerabilities, ranks them by CVSS, EPSS and CISA KEV, and wires scans into CI/CD thresholds.

AgentSecOps/SecOpsAgentKit2201 repo~2.5kAutomated safety check: PassUnknown5 mo ago

Questions, answered from the data.

What is the best supply chain security skill?

Skill Inspector (official) from NVIDIA/SkillSpector ranks first of the 233 supply chain security skills listed here, with the highest score: its repository has 20k GitHub stars, 1 other GitHub owner carry a copy, its SKILL.md loads about 1.8k tokens and it passes the automated safety check with no findings. Next come Dep Updates and Skill Scanner.

Which supply chain security skills are official?

15 of the 233 supply chain security skills are official, published by the vendor's own GitHub organization: Skill Inspector, Skill Scanner, Gha Security Review, Sbom, Vibe CI Supply Chain and 10 more.

How are these skills ranked?

By Skill Navigator score, which combines the GitHub stars of the skill's repository (shared across that repo's skills and discounted for large collections), how many other GitHub owners carry a copy of the skill, and automated SKILL.md quality checks, minus penalties for safety-check warnings and for each further skill from the same repository. Skills that fail the safety check are not listed.