microsoft/supply-chain-security
Software supply chain security reference for OpenSSF Scorecard, SLSA, Sigstore, SBOM, and posture/backlog taxonomies.
npx skills add https://github.com/microsoft/hve-core --skill supply-chain-security
This skill packages the durable software supply chain security (SSSC) reference material: open-standard catalogs, the combined capabilities inventory, and the classification taxonomies used to assess a repository's posture and turn gaps into prioritized work items.
Use this skill when you need to:
Load the reference file for the topic you need. Each file holds the verbatim standard catalog or taxonomy.
| Reference | Topic |
|--------------------------------------------------------------------------------|-----------------------------------------------------------------|
| references/00-index.md | Navigation catalog for every reference in this skill |
| references/openssf-scorecard.md | OpenSSF Scorecard 20 checks with risk levels and score ranges |
| references/slsa-levels.md | SLSA v1.0 Build track levels L0 through L3 |
| references/best-practices-badge.md | OpenSSF Best Practices Badge Passing, Silver, and Gold criteria |
| references/sigstore-maturity.md | Sigstore (cosign) adoption maturity levels |
| references/sbom-elements.md | NTIA SBOM minimum elements and format guidance |
| references/capabilities-inventory.md | 27 combined capabilities across hve-core, PAT, and shared sets |
| references/adoption-categories.md | Six adoption categories, effort sizing, and concern levels |
| references/scorecard-check-mapping.md | Full 20-check implementation and adoption reference mapping |
| references/priority-derivation.md | Risk level to priority and execution order derivation |
Standard catalogs in this skill derive from their respective upstream projects. Per-reference attribution appears at the bottom of each reference file. See references/00-index.md for the consolidated attribution summary.
Take microsoft/supply-chain-security from the repository into ~/.claude/skills for personal
use, or into .claude/skills inside a project.
The agent identifies a skill by the name field in its header. Two skills with the
same name cannot sit side by side — one of them will be ignored.