wgpsec/aboutsecurity
supply-chain-attack
软件供应链攻击方法论。当目标使用 npm/PyPI/Maven 等包管理器、有私有仓库、使用 CI/CD Pipeline 时使用。覆盖 Dependency Confusion、Typosquatting、恶意包发布、CI/CD 投毒、构建服务器攻击
Installation
npx skills add https://github.com/wgpsec/aboutsecurity
Similar popular skills
Related neighbors and high-traction skills in the same topics — useful to compare before installing.
Verify supply chain integrity for AI agent plugins, tools, and dependencies. Use this skill whe…
1.1K installsAudits a project's dependencies for supply-chain risk: version-matched advisories for direct de…
6.6K installsUse for software supply-chain security assessment covering SBOM, SCA, CI/CD pipelines, containe…
12 installsIndustry supply-chain analysis via Longbridge Securities — maps upstream / midstream / downstre…
551 installsParses Software Bill of Materials (SBOM) in CycloneDX and SPDX JSON formats to identify supply …
408 installsSupply chain analysis, inventory optimization, logistics planning, vendor evaluation, and deman…
331 installsAlso in this package
Other skills from wgpsec/aboutsecurity · top by installs.
npx skills add https://github.com/wgpsec/aboutsecurity
More details
Agent compatibility
Declared targets from SKILL.md / docs. Unmarked agents are not listed — the skill may still install via the CLI.
Repository health
master
History
- First seen on skills.sh
- First recorded snapshot · 16 installs