# Supply Chain Hardening

> >

- **Type:** Skill
- **Install:** `agentstack add skill-latiotech-secure-supply-chain-skills-supply-chain-hardening`
- **Verified:** Yes — security-reviewed for prompt injection and unsafe behavior
- **Seller:** [latiotech](https://agentstack.voostack.com/s/latiotech)
- **Installs:** 0
- **Category:** [Agent Skills](https://agentstack.voostack.com/c/agent-skills)
- **Latest version:** 0.1.0
- **License:** MIT
- **Upstream author:** [latiotech](https://github.com/latiotech)
- **Source:** https://github.com/latiotech/secure-supply-chain-skills/tree/main/skills/supply-chain-hardening
- **Website:** https://www.latio.com/

## Install

```sh
agentstack add skill-latiotech-secure-supply-chain-skills-supply-chain-hardening
```

Requires the [AgentStack CLI](https://agentstack.voostack.com/docs/cli). Works with Claude Code, Cursor, and any MCP-compatible agent.

## About

# Supply Chain Security Hardening

Secure the software supply chain across seven domains: third-party packages, container images, GitHub Actions, infrastructure-as-code, AI/ML models, IDE extensions, and credentials/secrets.

## How to Use This Skill

This skill provides two modes of operation:

### Action Commands - Take Realistic Action by Default

These commands scan the codebase, make changes directly (pin hashes, fix configs, resolve SHAs), and explain each change. They are the default way to harden a project.

- `/audit-supply-chain` - Full audit with auto-fixes for critical items
- `/harden-packages` - Pin versions, disable scripts, secure registries
- `/harden-containers` - Pin digests, enforce non-root, add .dockerignore
- `/harden-actions` - Pin SHAs, set permissions, fix injection, add Dependabot
- `/harden-iac` - Pin modules/providers, generate lockfiles, flag provisioners
- `/harden-ai-ml` - Fix unsafe deserialization, pin model sources
- `/harden-ide-extensions` - Audit extensions, remove secrets, add devcontainer
- `/harden-credentials` - Scan for leaked secrets, set up pre-commit hooks, harden credential hygiene
- `/audit-credentials` - Find long-lived tokens, hardcoded secrets, credentials to rotate or replace
- `/update-pins` - Check all pinned deps/actions/images for newer versions and update them
- `/minimize` - Remove unused dependencies and convert Dockerfiles to multi-stage builds

### Walkthrough Commands - Guided Setup for Advanced Items

These commands are interactive walkthroughs for configurations that require steps outside the codebase (cloud provider setup, Kubernetes config, GitHub settings). They should be run separately.

- `/setup-oidc` - Replace cloud credentials with OIDC tokens
- `/setup-image-signing` - Sign images with Cosign/Sigstore
- `/setup-tag-rulesets` - Protect tags from force-push attacks
- `/setup-admission-control` - Enforce image policies in Kubernetes
- `/setup-sbom` - Generate SBOMs and provenance attestations
- `/setup-commit-signing` - Set up commit and tag signing (SSH, GPG, or gitsign)
- `/setup-runner-monitoring` - Add runtime detection to CI runners

## Reference Material

1. **Read the checklist** at `references/checklist.md` to understand what needs to be done
2. **Read the tool reference** at `references/tools.md` for open source and paid options
3. **Read the implementation configs** at `references/package-configs.md` for copy-paste configurations
4. **Read the container guidance** at `references/container-configs.md` for Dockerfile and image hardening
5. **Read the actions guidance** at `references/actions-configs.md` for GitHub Actions hardening
6. **Read the iac guidance** at `references/iac-configs.md` for Terraform/IaC hardening
7. **Read the credential guidance** at `references/credentials-configs.md` for secret scanning and credential hygiene
8. **Read the AI/ML guidance** at `references/ai-ml-configs.md` for model security configurations

## Core Principles

1. **Pin everything.** Versions, digests, commit SHAs. Floating references are attack surface.
2. **Never fabricate pins. Resolve deterministically.** Always resolve versions, SHAs, and digests from live sources. Use methods that produce the same result regardless of local platform or environment: `docker buildx imagetools inspect` for multi-arch manifest digests (not `docker pull`/`docker inspect` which are platform-specific), `git ls-remote refs/tags/{tag}^{}` to dereference annotated tags to commit SHAs (not the tag object SHA). If resolution fails, add a `# TODO: pin` comment with the exact command the user should run — never guess a value.
3. **Least privilege everywhere.** Tokens, permissions, workflow scopes, container users.
4. **Verify provenance.** Sign artifacts, check signatures, require attestations.
5. **Detect at runtime.** Scanning at build time isn't enough - monitor what actually runs.
6. **Plan for cascading compromise.** One stolen token can hit npm, PyPI, Docker Hub, and extension marketplaces simultaneously.

## Domain Quick Reference

### Third-Party Packages
Pin versions. Require cooldown periods. Disable install scripts. Use a registry proxy/firewall. Scan for malware. Generate SBOMs. See `references/package-configs.md` for language-specific configurations.

### Container Images
Pin by digest. Run as non-root. Use minimal base images. Sign with Cosign. Scan continuously. Use admission controllers. See `references/container-configs.md`.

### GitHub Actions
Pin to commit SHAs. Set explicit permissions. Audit for `pull_request_target`. Enable tag protection rules. Monitor runner activity. See `references/actions-configs.md`.

### Infrastructure-as-Code
Pin module versions. Scan with Checkov/tflint. Enforce policy with OPA/Sentinel. Lock down provisioners. Require signed commits. See `references/iac-configs.md`.

### AI/ML Models
Never load untrusted pickles. Use SafeTensors/ONNX. Verify model hashes. Scan with Picklescan/ModelScan. Sandbox model loading.

### IDE Extensions
Audit installed extensions. Use osquery for fleet visibility. Enforce allowlists. Use VS Code Profiles. Run dev environments in containers.

### Credentials & Secrets
Scan for leaked secrets with Betterleaks. Set up pre-commit hooks to prevent future leaks. Harden .gitignore. Rotate compromised credentials. Replace long-lived tokens with OIDC where possible. Sign commits to prevent impersonation. See `references/credentials-configs.md`.

## When Making Changes

Action commands follow these principles:

1. **Make changes by default** - pin versions, resolve SHAs, fix configs directly
2. **Explain each change** as it's made - what was changed and why
3. **Don't break existing functionality** - test after changes
4. **Prioritize "Do Right Now" items** from the checklist before "Do Eventually" items
5. **Flag items that need manual attention** separately from automated fixes
6. **Point users to walkthrough commands** for advanced items that require external configuration

## Source & license

This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.

- **Author:** [latiotech](https://github.com/latiotech)
- **Source:** [latiotech/secure-supply-chain-skills](https://github.com/latiotech/secure-supply-chain-skills)
- **License:** MIT
- **Homepage:** https://www.latio.com/

Install and usage instructions live in the source repository linked above.

## Pricing

- **Free** — Free

## Security capabilities

Automated source analysis of v0.1.0 — what this tool can access:

- **Network access:** no
- **Filesystem access:** no
- **Shell / process execution:** no
- **Environment & secrets:** no
- **Dynamic code execution:** no

*"Yes" means the capability is present in the source — more access means more to trust, not that it is unsafe.*


## Versions

- **0.1.0** — security scan: passed — Imported from the upstream source.

## Links

- Listing page: https://agentstack.voostack.com/l/skill-latiotech-secure-supply-chain-skills-supply-chain-hardening
- Seller: https://agentstack.voostack.com/s/latiotech
- Browse the marketplace: https://agentstack.voostack.com/browse

---
Listed on AgentStack — the marketplace for AI agent skills and MCP servers. Every listing is security-reviewed. Creators keep 70%.
