What problem does it solve?
This Skill protects your organization from sophisticated supply chain attacks by rigorously evaluating software dependencies, build pipelines, and vendor components for malicious code and vulnerabilities.
Core Features & Use Cases
- Dependency Analysis: Detects risks like dependency confusion, typosquatting, and malicious maintainer takeovers in package ecosystems (npm, PyPI, etc.).
- Build Integrity Assessment: Evaluates your CI/CD pipelines against the SLSA framework to prevent build system compromises.
- SBOM Generation & Auditing: Provides detailed Software Bill of Materials analysis, including CVEs, CISA KEVs, and license risk.
- Use Case: When a new CVE is disclosed for a critical library your application uses, this Skill automatically assesses the risk, identifies if it's a CISA KEV, and recommends immediate actions like updating or blocking the package.
Quick Start
Analyze the supply chain risks for the 'event-stream' npm package at version '3.3.6'.