Activate when reviewing or modifying dependency resolution, lockfile schema, package downloaders, signature/integrity checks, file integration cleanup, or anything that could expose APM to dependency confusion, typosquatting, malicious packages, or token leakage.
$npx -y skills add microsoft/apm --skill supply-chain-securityInstalls into the current project.
Run `npx skills use "https://github.com/microsoft/apm" --skill "microsoft/apm/supply-chain-security"` and follow the generated skill instructions now. Read its complete output, redirecting it to a temporary file first if necessary. Resolve relative paths from the supporting-files directory it provides.
Use the skills in "https://github.com/microsoft/apm" that are relevant to the current task. Run `npx skills add "https://github.com/microsoft/apm"` and select the relevant skills, then follow their instructions.