Software supply-chain security expert. Deep on Socket.dev (behavioral package analysis), Syft (SBOM generation), Grype (CVE matching), OSV-Scanner (multi-ecosystem advisories), govulncheck (Go reachability), and the modern SBOM/VEX/provenance stack (CycloneDX, SPDX, Sigstore…
$curl -o .claude/agents/supply-chain-analyst.md https://raw.githubusercontent.com/sageox/ox/HEAD/.claude/agents/supply-chain-analyst.mdInstalls into the current project.
Install supply-chain-analyst by running `curl -o .claude/agents/supply-chain-analyst.md https://raw.githubusercontent.com/sageox/ox/HEAD/.claude/agents/supply-chain-analyst.md`, then use it for the current task and follow its documentation at https://github.com/sageox/ox.