supply-chain-threats

Identify software supply chain threat patterns and incidents for risk assessment.

15|5|Updated Apr 6, 2026
One-click install
npx skills add https://github.com/Liberty91LTD/cti-skills --skill supply-chain-threats
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: supply-chain-threats
Source: https://github.com/Liberty91LTD/cti-skills/tree/main/skills/supply-chain-threats
Command: npx skills add https://github.com/Liberty91LTD/cti-skills --skill supply-chain-threats

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Knowledge and context about software supply chain threats, curating incidents, actor mappings, and mitigations in a self-updating intelligence knowledge base for threat teams.

Core Features & Use Cases

  • Self-updating knowledge cell that aggregates major supply chain incidents (SolarWinds, MOVEit, XZ Utils) and actor mappings.
  • Provides historical context, risk assessments, and practical mitigations for security teams, procurement, and risk management.
  • Use Case: Threat intel analysts assess vendor risk, open-source dependencies, and incident response teams profile supply-chain campaigns across sectors.

Quick Start

Query the knowledge base to retrieve the latest supply chain threat summaries and recommended mitigations.

Frequently Asked Questions about supply-chain-threats

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
What are software supply chain threats and how do they impact vendor risk assessment?

Software supply chain threats are attack patterns targeting vendor dependencies and open-source components, impacting risk assessment by exposing procurement and incident response teams to compromise. This knowledge base maps incidents and actors to clarify those risks.

How do I assess open-source dependency risks using threat intelligence?

Assess open-source dependency risks by querying curated threat intelligence summaries of major incidents like XZ Utils. This maps threat actors and historical context to your dependencies, informing practical mitigations for your security teams.

Can I profile supply-chain campaigns across different tech sectors with this knowledge base?

Yes, you can profile supply-chain campaigns across tech sectors. The knowledge base aggregates incident summaries and actor mappings from events like SolarWinds and MOVEit, allowing incident response teams to analyze campaign patterns via natural language queries.

What is the best way to retrieve mitigations for historical supply chain incidents?

Retrieve mitigations for historical supply chain incidents by querying the self-updating knowledge base. It provides structured incident summaries, actor mappings, and best-practice mitigations curated for threat intel analysts and risk management teams.

Does this supply chain threat knowledge base require manual updates for new incidents?

No manual updates are required. The knowledge cell is self-updating, continuously aggregating major supply chain incidents and actor mappings to provide current threat intelligence and risk assessments for security teams.