agentic/code/frameworks/security-engineering/skills/supply-chain-hardening-quickstart/SKILL.md
Orchestrate a pragmatic npm supply-chain hardening pass: dependency-source audit, release-age gate, lifecycle-script review, trusted publishing, signed releases, SBOM, and user verification docs.
npx skillsauth add jmagly/aiwg supply-chain-hardening-quickstartInstall this skill globally with one command. Works with Claude Code, Cursor, and Windsurf.
3 of 9 scanners reported clean
Some scanners were skipped, did not run, or reported a non-clean status. Review each row below.
Use this skill when a user asks to harden an npm project after a supply-chain incident, prepare a release pipeline for trusted publishing, or give their users verification instructions.
npm-supply-chain-audit to find the current exposure.npm-release-age-gate to configure the 7-day default and
10-day high-sensitivity profile.supply-chain-trust for broader release evidence: signed tags,
provenance, cosign signatures, SBOM, and reproducible-build tradeoffs.File or verify issues for:
file:, and link: dep
sources outside an allowlist..npmrc min-release-age=7.data-ai
Report which research-corpus radar sidecars are overdue for refresh. Computes staleness (days since last refresh vs the cadence window) for every radar, sorted most-overdue-first. Runs via `aiwg corpus radar-status`.
data-ai
Aggregate research-corpus radar sidecars into a corpus or per-cluster freshness report — totals, overdue count, per-cluster / per-GRADE / per-trajectory breakdowns, an overdue table, and per-radar rationale snippets. Runs via `aiwg corpus radar-report`.
testing
Scaffold radar/freshness sidecars for research-corpus REFs. Pulls title/authors from the citation sidecar and GRADE from the analysis doc, defaults the refresh cadence from GRADE and the cluster from a corpus-local map, and stamps documentation/radar/REF-XXX-radar.md. Runs via `aiwg corpus radar-init`.
data-ai
Compute an entity's publication trajectory — per-year paper counts, topic drift, hot-streak detection (≥3 consecutive A-grade years), and career phase. Runs via `aiwg corpus profile-temporal`.