Skip to main content

supply-chain-security-scanner

AI-powered software supply chain security auditing skill for agentic platforms. Performs comprehensive dependency vulnerability scanning across npm, PyPI, Maven, Go modules, Cargo, and container images. Generates SBOMs (Software Bill of Materials) in SPDX and CycloneDX formats using Syft and Grype. Validates license compliance against organizational policies and detects copyleft risks. Verifies cryptographic provenance and SLSA framework attestations using cosign and slsa-verifier. Executes a structured audit methodology—Scan → Analyze → Report → Remediate—producing machine-readable vulnerability reports with CVSS scores, exploitability assessments, and actionable fix recommendations aligned with OWASP Agentic Skills Top 10 guidance. Integrates with ecosystem vulnerability databases including NVD (National Vulnerability Database), GitHub Advisory Database (GHSA), and Open Source Vulnerabilities (OSV). Covers software composition analysis (SCA) workflows, dependency confusion detection, typosquatting checks, a

インストールへ移動

ソース情報

リポジトリ
JPeetz/agent-skills
ソースの最終更新活動
2026年8月31日 06:31
検出された SKILL.md の言語
英語
スター
5
フォーク
1

インストール方法

デフォルトでは、最初にソースを確認する Prompt が選択されています。直接コマンドに切り替えるか、ローカルコピーをダウンロードすることもできます。

ソースファイルを確認

インストールを決める前に、SKILL.md と SkillsMP に表示されている付属ファイルをお読みください。