montimage/skills · Archived
supply-chain-audit
Audit npm/pip/Docker/GitHub Actions for supply chain risks; apply cooldown, lockfile, ignore-scripts, SHA pinning, scanning after approval. Use for 'supply…
Installation
npx skills add https://github.com/montimage/skills
Stronger alternatives
This repository is archived — consider an actively maintained alternative.
Analyze agent skills for security risks, malicious patterns, and potential dangers before insta…
42 installsPerform code reviews following best practices from Code Smells and The Pragmatic Programmer. Us…
15 installsImplement pre-commit hooks and GitHub Actions for quality assurance. Use when asked to "setup C…
11 installsAdd OSS-standard files (README, CONTRIBUTING, LICENSE, CODE_OF_CONDUCT, SECURITY, GitHub templa…
11 installsSimilar popular skills
Related neighbors and high-traction skills in the same topics — useful to compare before installing.
Verify supply chain integrity for AI agent plugins, tools, and dependencies. Use this skill whe…
1.1K installsAudits a project's dependencies for supply-chain risk: version-matched advisories for direct de…
6.6K installsUse for software supply-chain security assessment covering SBOM, SCA, CI/CD pipelines, containe…
12 installsIndustry supply-chain analysis via Longbridge Securities — maps upstream / midstream / downstre…
551 installsParses Software Bill of Materials (SBOM) in CycloneDX and SPDX JSON formats to identify supply …
408 installsSupply chain analysis, inventory optimization, logistics planning, vendor evaluation, and deman…
331 installsAlso in this package
Other skills from montimage/skills · top by installs.
npx skills add https://github.com/montimage/skills
More details
Agent compatibility
Declared targets from SKILL.md / docs. Unmarked agents are not listed — the skill may still install via the CLI.
Repository health
main
History
- First seen on skills.sh
- First recorded snapshot · 5 installs