maxtac-supply-chain-triage

Automate initial triage of supply-chain vulnerabilities from source code to shipped artifacts.

12|Updated Jun 1, 2026
One-click install
npx skills add https://github.com/philo-groves/MaxTAC --skill maxtac-supply-chain-triage
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: maxtac-supply-chain-triage
Source: https://github.com/philo-groves/MaxTAC/tree/main/plugins/maxtac-supply-chains/skills/maxtac-supply-chain-triage
Command: npx skills add https://github.com/philo-groves/MaxTAC --skill maxtac-supply-chain-triage

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes scripts (resource) and references (resource) components.

What problem does it solve?

This Skill addresses the complex challenge of initial routing and triage in supply-chain vulnerability research, ensuring efficient and targeted analysis.

Core Features & Use Cases

  • Initial Triage: Offers a structured approach to identifying and categorizing supply-chain vulnerabilities.
  • Artifact Analysis: Provides tools for mapping the journey of source code to shipped artifacts, preserving provenance evidence.
  • Use Case: When investigating a potential vulnerability in a software supply chain, this Skill helps to quickly determine the appropriate next steps and tools for a thorough analysis.

Quick Start

Run the maxtac-supply-chain-triage skill with the artifact you suspect to initiate the triage process.

Frequently Asked Questions about maxtac-supply-chain-triage

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I triage a supply chain vulnerability from source code to shipped artifacts?

Supply chain vulnerability triage maps the journey from source code to shipped artifacts to identify trust boundaries and attacker influence. This approach ensures provenance evidence is preserved for targeted analysis.

What is the best way to identify trust boundaries during software supply chain artifact analysis?

Artifact analysis identifies trust boundaries by mapping the path from source code to shipped artifacts. This structured triage process preserves provenance evidence and highlights attacker influence over the supply chain.

Do I need the Supply Chains pack to perform supply chain vulnerability research?

The Supply Chains pack is required for comprehensive supply chain vulnerability research. It provides the necessary tools to map source code to shipped artifacts and preserve provenance evidence during triage.

How do I start investigating a potential vulnerability in a software supply chain?

Initiate supply chain vulnerability triage by providing the suspected artifact to the analysis process. This automatically maps its journey from source code to shipped artifacts to determine the next investigative steps.

When should I use automated supply chain triage instead of manual vulnerability research?

Automated supply chain triage is suited for initial routing of vulnerabilities when you need to quickly map source code to shipped artifacts. Use it to preserve provenance evidence and determine appropriate next steps for thorough analysis.