supply-chain-security
The Supply Chain Security plugin equips Claude Code with specialized agents and skills to identify vulnerabilities, license risks, typosquatting, dependency confusion, and compromised packages across software dependencies, while generating SBOMs in SPDX and CycloneDX formats. It operates within NIST SP 800-161r1 and SLSA frameworks to provide proactive defense across the full dependency lifecycle from selection through integrity verification.
Install
Source: https://github.com/HermeticOrmus/LibreSecOps-Claude-Code/tree/HEAD/plugins/supply-chain-security
What it's made of
1 command · 2 agents · 2 skills
- Commands
- 1
- Agents
- 2
- Skills
- 2
- MCP servers
- 0
- Hooks
- 0
What it needs & plugs into
- API keys
- none
- Paid services
- none detected
- External tools
- none
- Talks to
- nothing external detected
Analyzed . Facts extracted from the plugin's files. Prose generated by claude-haiku-4-5-20251001.
Is this your plugin?
Claim it to keep the card accurate and enter the weekly contest. Requires signing in as the GitHub owner (HermeticOrmus).