What problem does it solve?
This Skill provides external reconnaissance for software supply-chain attack surfaces, identifying potential vulnerabilities such as package-namespace squatting, dependency-confusion, and GitHub Actions injection openings.
Core Features & Use Cases
- External Reconnaissance: Identifies package-namespace squatting candidates, dependency-confusion vulnerabilities, GitHub Actions injection openings, container image registry exposure, and more.
- Use Case: Use this Skill to identify potential vulnerabilities in a target's software supply chain before they are exploited.
- Step-by-Step Process: This Skill guides through the process of discovering a target's public GitHub organization, enumerating public repos for sensitive artifacts, internal package-name discovery, dependency-confusion vulnerability check, typosquat candidates, GitHub Actions workflow injection scan, Docker/container image registry mining, SBOM/artifact metadata leakage, internal registry URL leakage, and npm/PyPI organizational presence.
Quick Start
Use the supply-chain-attack-recon skill to perform a reconnaissance on the target organization 'targetorg'.