Skip to main content

dependency-supply-chain-audit

Use when working on dependency review, vulnerable packages, lockfile risk, license concerns, and supply-chain hygiene. Focus on known CVEs, typosquatting risk, lockfile integrity, and update safety.

الانتقال إلى التثبيت

معلومات المصدر

المستودع
Mr-Q526/TeamCC-Platform
آخر نشاط في المصدر
١٥ أبريل ٢٠٢٦ في ٠٣:١٦
لغة SKILL.md المكتشفة
الإنجليزية
النجوم
٧
التفرعات
١

خيارات التثبيت

يُحدَّد Prompt الذي يراجع المصدر أولًا بشكل افتراضي. يمكنك التبديل إلى أمر مباشر أو تنزيل نسخة محلية.

مراجعة ملفات المصدر

اقرأ SKILL.md وأي ملفات مرافقة يعرضها SkillsMP قبل أن تقرر التثبيت.

مستكشف الملفات
4 ملفات

عرض SKILL.md

SKILL.md
تعليمات المصدر · معاينة للقراءة فقط
schemaVersion
2026-04-11T00:00:00.000Z
skillId
security/dependency-supply-chain-audit
name
dependency-supply-chain-audit
displayName
Dependency Supply Chain Audit
description
Use when working on dependency review, vulnerable packages, lockfile risk, license concerns, and supply-chain hygiene. Focus on known CVEs, typosquatting risk, lockfile integrity, and update safety.
aliases
["dependency-supply-chain-audit","Dependency Supply Chain Audit","dependencysupplychainaudit","依赖","依赖安全","dependency","供应链","软件供应链","链路","supply","chain","audit","代码审查","code review","评审","dependency security","供应链安全"]
version
0.1.0
sourceHash
sha256:6654ebbcbda29454e3a8ce8b881bb5f25e17adacde2d834c112f47a2e3970d40
domain
security
departmentTags
["security-platform"]
sceneTags
["security-audit","review"]
# Dependency Supply Chain Audit Use this skill when the task involves dependency review, vulnerable packages, lockfile risk, license concerns, and supply-chain hygiene. Goal: produce reliable engineering guidance and implementation steps focused on known CVEs, typosquatting risk, lockfile integrity, and update safety. ## Working model 1. Identify the affected system, data, users, and failure modes. 2. Define invariants, inputs, outputs, ownership, and rollback needs. 3. Prefer small, auditable changes with explicit validation. 4. Call out security, performance, concurrency, and data-loss risks when relevant. 5. Finish with concrete verification steps and residual risks. ## Rules - Ground recommendations in the current codebase or runtime evidence. - Prefer explicit contracts, typed boundaries, and defensive validation. - Do not hide operational concerns behind generic best practices. - Include negative cases, edge cases, and failure behavior. - For review tasks, list findings first with file and line references when possible. - For test or performance tasks, define the workload, success criteria, and measurement method. ## Checklist - Are assumptions and ownership boundaries explicit? - Are risky changes reversible or safely deployable? - Are observability and diagnostics sufficient for production issues? - Are tests or validation steps targeted to the actual risk? - Are security and data-integrity concerns addressed?
عرض على GitHub