nm-leyline-supply-chain-advisoryAudits dependency supply chains for bad versions, lockfile drift, and artifact integrity
Install via ClawdBot CLI:
clawdbot install athola/nm-leyline-supply-chain-advisoryGrade Fair — based on market validation, documentation quality, package completeness, maintenance status, and authenticity signals.
Calls external URL not in known-safe list
https://github.com/athola/claude-night-market/tree/master/plugins/leylineAudited Apr 17, 2026 · audit v1.0
Generated May 11, 2026
When a new advisory for a compromised Python package is published, use this skill to check lockfiles and installed packages for known-bad versions, quickly verifying if your projects are affected.
Integrate the lockfile scanning and artifact detection commands into your CI pipeline to automatically flag compromised dependencies before deployment, reducing the risk of supply chain attacks.
During a security incident where a dependency may have been tampered with, use the skill to search for malicious artifacts, check hashes, and identify affected versions across all projects.
When starting a new Python project, apply version exclusions and configure the SessionStart hook to ensure that known-bad versions are blocked from the outset.
Schedule regular scans of uv.lock files across repositories to verify hash integrity and catch any tampered re-published packages, maintaining a strong defense layer.
Offer a cloud-based service that continuously monitors customer repositories for known-bad dependencies, using the skill's patterns for automated scanning and alerting.
Provide expert consulting to help organizations implement supply chain security practices, including lockfile auditing and response playbooks based on this skill.
Package the skill as an open-source CLI tool with optional paid support, custom integrations, and advanced reporting for enterprise clients.
💬 Integration Tip
Integrate the lockfile scanning commands into your CI/CD pipeline as a pre-deploy gate, and configure the SessionStart hook in developer environments to warn instantly upon launch.
Scored Jul 14, 2026
Medical device risk management specialist implementing ISO 14971 throughout product lifecycle. Provides risk analysis, risk evaluation, risk control, and pos...
When the user wants to plan a product launch, feature announcement, or release strategy. Also use when the user mentions 'launch,' 'Product Hunt,' 'feature r...
AI project management powered by CellCog. Knowledge workspaces, document upload, AI-processed context trees, signed URL retrieval. Works standalone or as CellCog chat context.
When the user wants to build a free tool for marketing — lead generation, SEO value, or brand awareness. Use when they mention 'engineering as marketing,' 'f...
管理多类型项目看板,支持新增项目、变更状态与版本、分类管理及查看项目总览和变更日志。
Competitor Analysis — SEO/GEO Intelligence & Market Positioning. Analyze competitor SEO rankings, AI search citations, content strategy, and market posi...