mcpbeat Sign in

Supply Chain Advisory Skill for Claude

Audits dependency supply chains for bad versions, lockfile drift, and artifact integrity. Use when adding deps, handling incidents, or releasing a plugin.

2k tokens
context cost
the whole folder, loaded on every use
4
files
instructions only
0
copies elsewhere
how many repositories repackaged it
324
stars on the repo
on the repository, not the skill itself

Install

one command, takes just this skill from the repository
npx skills add https://github.com/athola/claude-night-market --skill supply-chain-advisory

The instruction itself

12 sections, as written by the author

Overview

Supply chain attacks bypass traditional code review by compromising upstream

dependencies. This skill provides patterns for detecting, preventing, and

responding to compromised packages in Python ecosystems.

When To Use

  • After a supply chain advisory is published
  • When auditing dependencies for a new or existing project
  • During incident response for a suspected compromise
  • When adding the SessionStart hook to a project

When NOT To Use

  • General CVE triage unrelated to dependency supply chain
  • Application-level vulnerability scanning (use a SAST tool)
  • License compliance audits (different concern)

Known-Bad Versions Blocklist

The blocklist is at ${CLAUDE_SKILL_DIR}/known-bad-versions.json.

It is consumed by:

  • SessionStart hook: warns per-session when compromised

versions detected

  • make supply-chain-scan: CI/local scanning target
  • This skill: manual audit guidance

Blocklist Format

{
  "package_name": [{
    "versions": ["x.y.z"],
    "date": "YYYY-MM-DD",
    "description": "What the attack did",
    "indicators": ["files or patterns to search for"],
    "source": "advisory URL",
    "severity": "critical|high|medium"
  }]
}

Adding a New Entry

  • Add the entry to ${CLAUDE_SKILL_DIR}/known-bad-versions.json
  • Add version exclusions (!=x.y.z) to affected pyproject.toml files
  • Document in docs/dependency-audit.md under Supply Chain Incidents
  • Run make supply-chain-scan to verify detection works

Quick Scan Commands

Check all lockfiles on machine for known-bad versions

# Scan uv.lock files for a specific compromised version
grep -r "package_name.*version" --include="uv.lock" /path/to/projects

# Search for malicious artifacts
find /path/to/projects -name "suspicious_file.pth" 2>/dev/null

# Check installed versions in virtualenvs
find /path/to/projects -path "*/.venv/lib/*/PACKAGE*/METADATA" \
  -exec grep "^Version:" {} +

Verify lockfile hash integrity

uv.lock includes SHA256 hashes for every package. If a package is

re-published with different content under the same version, uv sync

will fail with a hash mismatch. This is your strongest automatic defense.

Defense Layers

| Layer | Tool | Catches |

|-------|------|---------|

| Lockfile hashes | uv.lock SHA256 | Tampered re-published versions |

| Version exclusions | pyproject.toml != | Known-bad versions on fresh resolve |

| SessionStart hook | sanctum hook | Per-session warning for compromised deps |

| CI scanning | OSV, Safety | CVE database, and advisory matching |

| Artifact scanning | make supply-chain-scan | Malicious files (.pth, scripts) |

Limitations

  • Zero-day supply chain attacks have no prior advisory: lockfile hashes

are the only automatic defense during the attack window

  • Safety/CVE databases lag behind real-world compromises
  • OSV provides broader coverage but is still reactive

Exit Criteria

  • [ ] ${CLAUDE_SKILL_DIR}/known-bad-versions.json checked against

all lockfiles in scope; any match reported with package name,

bad version, severity, and advisory URL

  • [ ] When a new known-bad entry is added: version exclusion

(!=x.y.z) added to the affected pyproject.toml, entry

documented in docs/dependency-audit.md, and

make supply-chain-scan run to confirm detection works

  • [ ] uv.lock SHA256 hash integrity verified; uv sync failure

on hash mismatch surfaces as an explicit supply-chain warning

rather than a generic install error

  • [ ] Artifact scan checks for malicious file patterns (.pth

files, unexpected scripts) in virtualenv paths before the

session proceeds

Other skills for the same job

different authors, same section of the catalogue
MCP Builder
by anthropics
vendor ×13

Guide for creating high-quality MCP (Model Context Protocol) servers that enable LLMs to interact with external services through well-designed tools. Use when building MCP servers to integrate external APIs or services, whether in Python (FastMCP) or Node/TypeScript (MCP SDK).

30k tokens scripts
Changelog Generator
by frostant
×9

Automatically creates user-facing changelogs from git commits by analyzing commit history, categorizing changes, and transforming technical commits into clear, customer-friendly release notes. Turns hours of manual changelog writing into minutes of automated generation.

774 tokens
Finishing A Development Branch
by ZhanlinCui
×7

Use when implementation is complete, all tests pass, and you need to decide how to integrate the work - guides completion of development work by presenting structured options for merge, PR, or cleanup

1k tokens
MCP Builder
by JayZeeDesign
×7

Guide for creating high-quality MCP (Model Context Protocol) servers that enable LLMs to interact with external services through well-designed tools. Use when building MCP servers to integrate external APIs or services, whether in Python (FastMCP) or Node/TypeScript (MCP SDK).

37k tokens scripts
Vercel React Native Skills
by vercel-labs
vendor ×6

React Native and Expo best practices for building performant mobile apps. Use when building React Native components, optimizing list performance, implementing animations, or working with native modules. Triggers on tasks involving React Native, Expo, mobile performance, or native platform APIs.

39k tokens
Vercel React Best Practices
by ratacat
×5

React and Next.js performance optimization guidelines from Vercel Engineering. This skill should be used when writing, reviewing, or refactoring React/Next.js code to ensure optimal performance patterns. Triggers on tasks involving React components, Next.js pages, data fetching, bundle optimization, or performance improvements.

34k tokens
Next Best Practices
by vercel-labs
vendor ×4

Next.js best practices - file conventions, RSC boundaries, data patterns, async APIs, metadata, error handling, route handlers, image/font optimization, bundling

20k tokens
Using Git Worktrees
by ZhanlinCui
×4

Use when starting feature work that needs isolation from current workspace or before executing implementation plans - creates isolated git worktrees with smart directory selection and safety verification

1k tokens

How to use it

Copy the folder

Take athola/supply-chain-advisory from the repository into ~/.claude/skills for personal use, or into .claude/skills inside a project.

Check the name does not clash

The agent identifies a skill by the name field in its header. Two skills with the same name cannot sit side by side — one of them will be ignored.