More screenshots
Works with the AI tools you already use
Dependency & Supply Chain Security Gate
Dependency & Supply Chain Security Gate is a defensive release gate for software dependencies and build inputs.
$7
Dependency & Supply Chain Security Gate
Example session with this skill installed
Audit the attached package-lock.json and github-actions.yml for a production release. Check for mutable references and unauthorized lifecycle hooks. Is this safe to PASS?
- Read your context and instructions
- Compiled the dependency & supply
- Generated the document
DECISION — High Confidence — Sufficient Evidence
The supplied artifacts indicate a REVIEW decision is required due to mutable container tags and an unverified lifecycle script in a transitive dependency.
Supply Chain Audit Report
| ID | Finding | Category | Severity | Gate Effect |
|---|---|---|---|---|
| SC-001 | Mutable Container Reference | Build Integrity | Medium | REVIEW |
| SC-002 | Unverified Lifecycle Hook | Script Execution | High | BLOCK |
| SC-003 | Lockfile Integrity | Consistency | Low | PASS |
Executive Summary
The gate is currently at
BLOCK status. While package-lock.json shows consistent integrity hashes for direct dependencies, the github-actions.yml uses node:latest and actions/checkout@v3 (mutable) rather than immutable SHA-256 digests. Additionally, npm-shrinkwrap.json reveals a preinstall script in a transitive dependency that has no associated provenance or justification in the release notes.
Open Findings
SC-002 (High): Transitive dependency event-stream-parser@1.0.2 contains a preinstall hook. In a high-privilege CI environment, this poses an execution risk.
SC-001 (Medium): The production build workflow references docker.io/library/node:20. This tag is mutable and could lead to non-deterministic builds.
NOT_VERIFIED
- Registry Origin: Evidence of private registry scoping for the
@internalnamespace is missing. - Attestations: No SLSA provenance was supplied for the base image.
Next steps
- Pin all GitHub Actions and Docker base images to immutable SHA-256 digests.
- Audit the
preinstallscript inevent-stream-parseror override it using an ignore-scripts policy. - Provide registry configuration evidence to verify namespace scoping.
dependency-supply-chain-security-gate.pdf
PDF · document
Example file from a real run - the skill writes it into your workspace.
Connects securely to your tools. The creator never sees your data.
What you get
About this skill
Dependency & Supply Chain Security Gate is a defensive release gate for software dependencies and build inputs. It reviews supplied manifests, resolved lockfiles, SBOMs, registry configuration, CI/CD definitions, container or Git references, integrity metadata, signatures, attestations, provenance statements, and sanitized scanner evidence.
The skill traces trust from dependency declaration through resolution, source, acquisition evidence, build execution, privilege, artifact production, and release verification. It distinguishes evidence from assumptions, refuses to invent CVEs or package reputation, and does not treat a checksum, signature, SBOM, lockfile, or clean scan as stronger proof than it actually is.
Results use one gate decision:
- PASS — sufficient, completely accounted evidence with no unresolved material condition.
- REVIEW — a correctable Medium risk, control gap, stale/conflicting evidence, or material non-blocking unknown.
- BLOCK — a credible Critical/High supply-chain path, exposed secret, privileged untrusted-code execution, unauthorized source change, integrity/provenance mismatch, or blocking evidence gap.
Every formal finding includes stable identity, severity, confidence, component, location, evidence, assumptions, trust-chain trace, impact, prerequisites, remediation, safe test, retest condition, owner, and gate effect. Optional offline Python helpers provide deterministic IDs, conservative inventory, and JSON contract validation.
How to install
Works the same in every agent - Claude, Cursor, Codex, Copilot and 20+ more.
- 1
Download the ZIP
Free skills download straight away. Paid skills unlock right after purchase.
- 2
Unzip into your skills folder
Every agent reads skills from one folder on your machine. Drop the unzipped folder in there.
- 3
Ask your agent to use it
Restart the agent if it was already running. It picks the skill up automatically - no config needed.
Skills folder by agent
Click the path to copy it. Create the folder if it does not exist yet.
Reviews
No reviews yet
Be one of the first to try it. Every listed skill passes our trust checks below.
Security scanned
Passed our 8-point scan before listing
1 install
Downloaded by developers to date
30-day refund
Not a fit? Get your money back
Trust & safety
Security scanned
Verified clean 23 days ago
- Passed all security checks, Safe to install