supply-chain-attack-recon

Map external software supply-chain risks across GitHub, SBOMs, and CI/CD configurations.

Updated Jun 5, 2026
One-click install
npx skills add https://github.com/sseshachala/Claude-BugHunter-archive --skill supply-chain-attack-recon-sseshachala
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: supply-chain-attack-recon
Source: https://github.com/sseshachala/Claude-BugHunter-archive/tree/main/skills/supply-chain-attack-recon
Command: npx skills add https://github.com/sseshachala/Claude-BugHunter-archive --skill supply-chain-attack-recon-sseshachala

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Public-facing software supply chains are often misunderstood and under-defended, leaving organizations exposed to dependencyconfusion, typosquats, and misconfigured CI/CD workflows. This skill helps security teams identify and map external supply-chain risk surfaces across GitHub orgs, SBOMs, container registries, and CI/CD configurations, enabling targeted risk assessment and remediation planning.

Core Features & Use Cases

  • External reconnaissance across public GitHub organizations to surface dependency-confusion signals, internal package-name leakage, SBOM exposure, and registry vulnerabilities.
  • CI/CD and container surface checks to identify GitHub Actions injection opportunities, misconfigurations, and exposed registries.
  • Evidence-driven prioritization with actionable remediation guidance for high-risk supply-chain patterns and public-facing risk scenarios.

Quick Start

Analyze a target's public GitHub org, SBOMs, and static/dynamic artifacts to surface actionable supply-chain risk patterns and mitigations.

Frequently Asked Questions about supply-chain-attack-recon

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I identify external software supply-chain risks in public GitHub organizations?

Supply-chain reconnaissance works by discovering public assets, mining SBOMs, and checking CI/CD workflow exposure to map dependency-confusion, typosquat, and registry exposure vulnerabilities. It coordinates asset discovery and risk prioritization to deliver evidence-backed findings and remediation recommendations.

What is the best way to detect dependency-confusion and typosquat vulnerabilities?

CI/CD workflow exposure checks identify GitHub Actions injection opportunities by analyzing visible CI/CD configurations across public repositories. These surface checks reveal misconfigurations and exposed registries that could allow unauthorized code execution or artifact tampering.

Can I assess public container registry exposure and SBOM risks without internal access?

This approach suits security teams assessing organizations with public GitHub organizations, publicly accessible SBOMs, and visible CI/CD configurations. It maps external supply-chain risk surfaces to deliver evidence-driven prioritization and actionable remediation guidance.

How do I prioritize supply-chain risks found through external reconnaissance?

Prioritize supply-chain risks by correlating discovered asset vulnerabilities like dependency-confusion and GitHub Actions injections with their public-facing exposure. This evidence-driven prioritization delivers actionable remediation guidance for high-risk patterns and public-facing risk scenarios.