More screenshots

    Works with the AI tools you already use

    Claude CodeClaude CodeCursorCursorCodex CLICodex CLIMuseMuseDotsDots+22 more

    Dependency & Supply Chain Security Gate

    1

    Dependency & Supply Chain Security Gate is a defensive release gate for software dependencies and build inputs.

    $7

    Secure checkout via Stripe

    30-day refund guarantee

    Converts to your local currency at checkout

    1 installSecurity scanned
    Dependency & Supply Chain Security Gate

    Dependency & Supply Chain Security Gate

    Example session with this skill installed

    Audit the attached package-lock.json and github-actions.yml for a production release. Check for mutable references and unauthorized lifecycle hooks. Is this safe to PASS?

    • Read your context and instructions
    • Compiled the dependency & supply
    • Generated the document

    DECISION — High Confidence — Sufficient Evidence

    The supplied artifacts indicate a REVIEW decision is required due to mutable container tags and an unverified lifecycle script in a transitive dependency.

    Supply Chain Audit Report

    IDFindingCategorySeverityGate Effect
    SC-001Mutable Container ReferenceBuild IntegrityMediumREVIEW
    SC-002Unverified Lifecycle HookScript ExecutionHighBLOCK
    SC-003Lockfile IntegrityConsistencyLowPASS

    Executive Summary

    The gate is currently at

    BLOCK status. While package-lock.json shows consistent integrity hashes for direct dependencies, the github-actions.yml uses node:latest and actions/checkout@v3 (mutable) rather than immutable SHA-256 digests. Additionally, npm-shrinkwrap.json reveals a preinstall script in a transitive dependency that has no associated provenance or justification in the release notes.

    Open Findings

    SC-002 (High): Transitive dependency event-stream-parser@1.0.2 contains a preinstall hook. In a high-privilege CI environment, this poses an execution risk.

    SC-001 (Medium): The production build workflow references docker.io/library/node:20. This tag is mutable and could lead to non-deterministic builds.

    NOT_VERIFIED

    • Registry Origin: Evidence of private registry scoping for the @internal namespace is missing.
    • Attestations: No SLSA provenance was supplied for the base image.

    Next steps

    1. Pin all GitHub Actions and Docker base images to immutable SHA-256 digests.
    2. Audit the preinstall script in event-stream-parser or override it using an ignore-scripts policy.
    3. Provide registry configuration evidence to verify namespace scoping.

    dependency-supply-chain-security-gate.pdf

    PDF · document

    Generated

    Example file from a real run - the skill writes it into your workspace.

    Connects securely to your tools. The creator never sees your data.

    What you get

    Gate production releases based on dependency integrity and provenance.Validate SBOM completeness and trace trust across the build pipeline.Identify mutable references in CI/CD workflows and container definitions.Detect risky lifecycle hooks and suspicious install scripts in package manifests and dependency metadata.Gate dependency upgrades before merge or release.Reconcile manifests, lockfiles, SBOMs, and resolved component counts.Review mutable Git refs, CI actions, container tags, build plugins, lifecycle hooks, and privileged runners.Check supplied checksums, signatures, attestations, provenance, builder identity, and artifact-digest binding.Correlate supplied advisory/scanner evidence by exact ecosystem, identity, version, source, configuration, and timestamp.Detect registry ambiguity, dependency-confusion exposure, local/path overrides, patches, aliases, and source drift.Verify remediation and produce machine-readable PASS, REVIEW, or BLOCK evidence.

    About this skill

    Dependency & Supply Chain Security Gate is a defensive release gate for software dependencies and build inputs. It reviews supplied manifests, resolved lockfiles, SBOMs, registry configuration, CI/CD definitions, container or Git references, integrity metadata, signatures, attestations, provenance statements, and sanitized scanner evidence.

    The skill traces trust from dependency declaration through resolution, source, acquisition evidence, build execution, privilege, artifact production, and release verification. It distinguishes evidence from assumptions, refuses to invent CVEs or package reputation, and does not treat a checksum, signature, SBOM, lockfile, or clean scan as stronger proof than it actually is.

    Results use one gate decision:

    • PASS — sufficient, completely accounted evidence with no unresolved material condition.
    • REVIEW — a correctable Medium risk, control gap, stale/conflicting evidence, or material non-blocking unknown.
    • BLOCK — a credible Critical/High supply-chain path, exposed secret, privileged untrusted-code execution, unauthorized source change, integrity/provenance mismatch, or blocking evidence gap.

    Every formal finding includes stable identity, severity, confidence, component, location, evidence, assumptions, trust-chain trace, impact, prerequisites, remediation, safe test, retest condition, owner, and gate effect. Optional offline Python helpers provide deterministic IDs, conservative inventory, and JSON contract validation.

    How to install

    Works the same in every agent - Claude, Cursor, Codex, Copilot and 20+ more.

    ~30 seconds
    1. 1

      Download the ZIP

      Free skills download straight away. Paid skills unlock right after purchase.

    2. 2

      Unzip into your skills folder

      Every agent reads skills from one folder on your machine. Drop the unzipped folder in there.

    3. 3

      Ask your agent to use it

      Restart the agent if it was already running. It picks the skill up automatically - no config needed.

    Skills folder by agent

    Click the path to copy it. Create the folder if it does not exist yet.

    Reviews

    No reviews yet

    Be one of the first to try it. Every listed skill passes our trust checks below.

    Security scanned

    Passed our 8-point scan before listing

    1 install

    Downloaded by developers to date

    30-day refund

    Not a fit? Get your money back

    Trust & safety

    Security scanned

    Verified clean 23 days ago

    • Passed all security checks, Safe to install

    Listed23 days ago
    Updated15 days ago

    What's inside

    Frequently Asked Questions