Software supply-chain defensive security reference: SBOM generation and verification (SPDX / CycloneDX), dependency-confusion defense, malicious-package triage playbook, SLSA provenance levels, Sigstore / cosign signing and verification, package-registry hardening, typosquatting defense, and transitive-dependency auditing. Agent-extending skill that amplifies backend, security, and release-engineering work with production-grade defensive patterns for the software supply chain. NOT for: offensive techniques (dependency-confusion attack execution, malicious package authoring, registry exploitation), LLM/AI-specific security (see moai-ref-llm-security), web-app OWASP Top 10 (see moai-ref-owasp-checklist), or general API design (see moai-ref-api-patterns).
$npx -y skills add modu-ai/moai-adk --skill moai-ref-supply-chainInstalls into the current project.
Run `npx skills use "https://github.com/modu-ai/moai-adk" --skill "modu-ai/moai-adk/moai-ref-supply-chain"` and follow the generated skill instructions now. Read its complete output, redirecting it to a temporary file first if necessary. Resolve relative paths from the supporting-files directory it provides.
Use the skills in "https://github.com/modu-ai/moai-adk" that are relevant to the current task. Run `npx skills add "https://github.com/modu-ai/moai-adk"` and select the relevant skills, then follow their instructions.