SkillAgentSearch skills...

supply-chain-attack-response

Detect, respond to, and prevent software supply chain attacks on package registries, container images, and CI/CD pipelines with lockfile auditing, provenance verification, and emergency response playbooks.

Install / Use

npx skills add BagelHole/DevOps-Security-Agent-Skills --skill supply-chain-attack-response

Installs into whichever agent you are using.

About this skill
📄

SKILL.md

Installable skill definition

Quality Score

80/100

Category

Automation

Supported Platforms

Universal

Our assessment of supply-chain-attack-response

supply-chain-attack-response scores 80/100 on our quality scale, 2224th of 2,987 Automation skills we index.

We have not analysed the SKILL.md file itself yet, so the content part of this score is an estimate until our crawler reaches it.

With 1,113 GitHub stars, it is one of the more widely adopted skills in the catalogue.

Maintenance, license and trust

  • The repository was last updated about 4 months ago. That is recent enough to be usable, but agent tooling moves fast, so check the instructions against your agent's current version.
  • It is released under the MIT license, a permissive license that allows use, modification and commercial use with attribution.
  • Its trust signals score 98/100, with no cautions. These come from repository metadata, not a code audit — read the skill file before letting an agent act on it.

supply-chain-attack-response compared with similar skills

All 4 of these similar skills score higher than supply-chain-attack-response; compare them before choosing.

SkillScoreStarsUpdatedFormat
supply-chain-attack-response (this skill)by BagelHole801.1k4mo agoSKILL.md
Agent-Reachby Panniantong10087.6k16d agoCLAUDE.md
rufloby ruvnet10073.7ktodayCLAUDE.md
Scraplingby D4Vinci10085.0k1d agoMCP Server
LocalAIby mudler10049.4ktodayMCP Server

Frequently asked questions

How do I install supply-chain-attack-response?
Run npx skills add BagelHole/DevOps-Security-Agent-Skills --skill supply-chain-attack-response. The install tabs above show the steps for each supported agent.
Which AI agents does supply-chain-attack-response work with?
It is written for Universal, as a SKILL.md file. Other agents that read the same format can often use it too.
Is supply-chain-attack-response safe to use?
It is MIT-licensed and scores 98/100 on trust signals. Skills are instructions an agent will follow, so read the file before installing it and do not approve commands you do not understand.
Is supply-chain-attack-response still maintained?
The repository was last updated about 4 months ago. That is recent enough to be usable, but agent tooling moves fast, so check the instructions against your agent's current version.

Related Skills

View on GitHub
GitHub Stars1.1k
CategoryAutomation
Updated4mo ago
Forks158

Languages

Shell

Trust signals

98/100

From repository metadata: license, adoption, age and documentation. Not a code audit — see the Safety scan above for what the skill file itself contains.

1 info