canon-supply-chain-analysis

Compose a governed supply-chain packet with SBOM, vulnerability, license, and legacy evidence.

1|Updated Mar 26, 2026
One-click install
npx skills add https://github.com/apply-the/canon --skill canon-supply-chain-analysis
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: canon-supply-chain-analysis
Source: https://github.com/apply-the/canon/tree/main/.agents/skills/canon-supply-chain-analysis
Command: npx skills add https://github.com/apply-the/canon --skill canon-supply-chain-analysis

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Use when you need a governed supply-chain-analysis packet for an existing repository with explicit SBOM, vulnerability, license, and legacy posture evidence.

Core Features & Use Cases

  • Bounded governance: create auditable packets that document dependency posture, licensing, SBOMs, and legacy risks.
  • Evidence integration: collate vulnerability triage notes, license compliance, and modernization pressure into a single packet.
  • Stakeholder-ready outputs: generate a portable, reviewable artifact set for approvals and publishing.

Quick Start

Trigger a governed supply-chain-analysis run for the currently bounded repository surface.

Frequently Asked Questions about canon-supply-chain-analysis

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I generate a governed supply-chain analysis packet for a repository?

Generate a governed supply-chain analysis packet by triggering an automated run that binds context to the local Canon installation and composes SBOM, vulnerability, license, and legacy posture evidence into a single reviewable artifact.

What is a supply-chain posture packet used for?

A supply-chain posture packet is used to document dependency, licensing, SBOM, and legacy risks in an auditable format, providing stakeholder-ready artifacts for formal approvals and publishing.

How do I automate SBOM and license compliance reporting for bounded code bases?

Automate SBOM and license compliance reporting by triggering a governed run that collates vulnerability triage notes and modernization pressure into a portable, bounded packet for the specified code base.

Do I need explicit inputs to document vulnerability and legacy posture risks?

Yes, documenting vulnerability and legacy posture risks requires explicit inputs such as RISK, ZONE, and authored inputs to accurately bind context and formalize the governance packet.

Can I capture dependency posture and modernization pressure in a single artifact?

Yes, you can capture dependency posture and modernization pressure in a single artifact by composing a bound packet that integrates vulnerability, license, and legacy evidence for stakeholder review.

When do I need a formal packet for repository supply-chain governance?

You need a formal packet for repository supply-chain governance when dependency posture, licensing compliance, and legacy risk must be captured as auditable evidence for bounded code bases requiring approvals.