supply-chain-guard
Detect and remediate supply-chain attacks in npm, PyPI, crates.io, and CI/CD.
🛡️ AgentReady threat assessment
MAESTRO 7-layer threat model + OWASP AIVSS risk score for supply-chain-guard, derived from its capabilities.
These scores are auto-generated from public information (the agent's own listing, docs, and repository) using the canonical OWASP AIVSS formula and the MAESTRO framework — an estimate for guidance, not a penetration test, audit, or certification. See the scoring methodology — every score is re-derived by the same automated method as an agent's public evidence changes.
Overview
An Agent Skill (author dan-avila) that scans npm, PyPI, crates.io, GitHub Actions, and CI/CD pipelines for known compromised packages, malicious versions, filesystem IOCs, C2 indicators, and CI/CD misconfigurations, then remediates. It ships a real-world IOC database (dated 2026-03-31) the agent matches against dependency trees.
Key features and capabilities
- Known-compromised package detection
- Filesystem IOC and C2 indicator scanning
- CI/CD misconfiguration remediation
Use cases
- Auditing dependencies for supply-chain attacks
- Hardening CI/CD against compromise