supply-chain-analyst

Analyze software supply chain risks and generate SBOMs.

Updated Feb 22, 2026
One-click install
npx skills add https://github.com/Muath2000/TradeStation --skill supply-chain-analyst
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: supply-chain-analyst
Source: https://github.com/Muath2000/TradeStation/tree/main/.claude/skills/supply-chain-analyst
Command: npx skills add https://github.com/Muath2000/TradeStation --skill supply-chain-analyst

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes scripts (resource) and references (resource) components.

What problem does it solve?

This Skill helps organizations understand and mitigate risks within their complex software supply chains by mapping dependencies, identifying critical vendors, and simulating the impact of breaches.

Core Features & Use Cases

  • Dependency Mapping: Visualize the intricate relationships between your vendors, their sub-suppliers, and your business processes.
  • Risk Analysis: Identify concentration risks (single points of failure) and analyze Nth-party risks.
  • Breach Simulation: Model the cascading effects of a vendor compromise to understand the blast radius and potential impact.
  • Use Case: A security team can use this Skill to proactively identify if a critical Tier 3 supplier to one of their Tier 1 vendors experiences a data breach, and understand which of their own business processes would be affected.

Quick Start

Use the supply-chain-analyst skill to generate a dependency graph visualization for all Tier 1 vendors.

Frequently Asked Questions about supply-chain-analyst

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I generate an SBOM and check dependency security for my software supply chain?

To check dependency security and generate an SBOM, this Skill analyzes your software supply chain to map vendor relationships, identify critical dependencies, and assess Nth-party risks. It visualizes Tier 1 vendors and their sub-suppliers to pinpoint single points of failure.

What is SLSA compliance and how does provenance verification secure artifacts?

SLSA compliance verifies artifact signing and provenance to secure your software supply chain. This Skill checks SLSA compliance by verifying artifact signatures, ensuring traceability of dependencies, and confirming the integrity of your software components throughout the supply chain.

Can I simulate a vendor breach to understand the blast radius of a supply chain compromise?

Yes, you can simulate a vendor breach to understand the blast radius. This Skill models the cascading effects of a vendor compromise, allowing you to see exactly which business processes would be affected if a critical Tier 3 supplier experiences a data breach.

How do I map Nth-party risks and concentration risks in my software dependencies?

To map Nth-party and concentration risks, this Skill analyzes your software dependencies to identify single points of failure. It visualizes the intricate relationships between your vendors and sub-suppliers, highlighting critical dependencies that pose security risks to your business processes.

Does this tool analyze SLSA compliance for complex software supply chains with multiple Tier 1 vendors?

Yes, this tool analyzes SLSA compliance for complex software supply chains with multiple Tier 1 vendors. It assesses dependency security, verifies artifact signing, and generates an SBOM to ensure your entire vendor ecosystem meets supply chain security standards.

What are the limitations of dependency mapping when analyzing supply chain provenance?

Dependency mapping for supply chain provenance relies on accurate vendor data to identify concentration risks. Limitations include incomplete visibility into sub-supplier relationships or missing artifact signing metadata, which can affect the accuracy of breach simulation and SLSA compliance verification.