From cybersec-toolkit
Hardens software supply chain with SBOM, SLSA, provenance attestation, dependency pinning, artifact signing, and CI/CD controls.
How this skill is triggered — by the user, by Claude, or both
Slash command
/cybersec-toolkit:supply-chain-prodsec-hardeningThe summary Claude sees in its skill listing — used to decide when to auto-load this skill
Use this skill for SDLC, build/release pipelines, dependency trust, artifact provenance, product security, and supply-chain risk reduction.
Use this skill for SDLC, build/release pipelines, dependency trust, artifact provenance, product security, and supply-chain risk reduction.
| Stage | Weakness | Attack path | Control | Evidence | Owner | Priority |
|---|
Prefer controls that are enforceable in CI/CD or registry policy over wiki-only process.
npx claudepluginhub 26zl/cybersec-toolkit --plugin cybersec-toolkitDesigns software supply chain security controls including SBOM generation, artifact signing, dependency management, and build pipeline integrity per NIST SP 800-161r1 and SLSA.
Audits dependency configs for supply chain risks like unpinned versions, missing lockfiles, postinstall scripts in package.json, requirements.txt, Gemfile, go.mod, Cargo.toml, pom.xml. Hardens with pinning, SBOM, signing best practices.
Use this skill when the user asks to "harden supply chain", "secure dependencies", "pin versions", "audit packages", "secure GitHub Actions", "harden containers", "secure IaC", "audit extensions", "secure AI models", "audit pickle files", "scan for secrets", "harden credentials", "rotate tokens", "audit credentials", "sign commits", "commit signing", "signed commits", "gitsign", or needs guidance on software supply chain security, dependency management, credential hygiene, secret scanning, or preventing supply chain attacks. Also trigger when the user mentions tools like Grype, Cosign, Sigstore, Checkov, Hadolint, Zizmor, ModelScan, SafeTensors, Betterleaks, gitsign, or references SLSA.