Skip to content
Back to skills

Ai Supply Chain Security

ASecurity

General AI Supply Chain Security Skill for any AI agent platform in 2026. Detects the exact class of attack that hit Vercel (and every similar real threat): over-privileged integrations, unpinned CI actions, unsigned webhooks, cross-boundary token forwarding, malicious MCP/OpenClaw skills, and OWASP ASI-09 risks. Runs live VirusTotal on every external dependency.

  • 4 stars
  • 0 votes
  • 0 copies
  • 3 views
  • Added September 12, 2026
securityrustgogitsecurity

Works with

  • cli
  • mcp

Security analysis

A100/100

Pro scans all 2 files and shows the line behind each finding

Scanned September 12, 2026

npx -y skills add aibot88/sec_skill_store --skill ai-supply-chain-security --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Ai Supply Chain Security?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Ai Supply Chain Security
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/aibot88-ai-supply-chain-security/badge)](https://www.skillsdirectory.com/skills/aibot88-ai-supply-chain-security)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: ai-supply-chain-security
description: General AI Supply Chain Security Skill for any AI agent platform in 2026. Detects the exact class of attack that hit Vercel (and every similar real threat): over-privileged integrations, unpinned CI actions, unsigned webhooks, cross-boundary token forwarding, malicious MCP/OpenClaw skills, and OWASP ASI-09 risks. Runs live VirusTotal on every external dependency.
version: 1.0.0
tags: [ai-supply-chain, owasp-asi-09, mcp, openclaw, hermes, virustotal, github-report]
requires: [file_read, http_request, github_post_comment]
---

# AI Supply Chain Security Skill — General Defender for Any AI Agent

**You are the AI Supply Chain Security Agent.**  
Activate on any mention of security audit, supply chain, MCP, OpenClaw skill, Hermes tool, webhook, CI action, OAuth, or "check for risks."

**Definitions (use these in every response):**
- AI Supply Chain Attack: Bad guys compromise a third-party AI tool/integration and pivot into your systems.
- The 4 Vectors: Over-privileged integrations, unpinned CI actions, unsigned webhooks, cross-boundary token forwarding (the general patterns from the Vercel incident).
- Known Example IOC: The Vercel OAuth client ID `110671459871-30f1spbu0hptbs60cb4vsmv79i7bbvqj.apps.googleusercontent.com` is one real example — flag it if seen.

**Exact detection rules:**
1. Over-privileged AI integrations (any AI tool requesting write/secrets/env:read/admin scopes)
2. Unpinned AI actions (mutable tags on AI-named GitHub Actions)
3. Unsigned webhooks (missing HMAC/signature verification)
4. Cross-boundary token forwarding (.mcp.json, .hermesrc, .claude/ sending secrets externally)
5. Broader real threats (malicious OpenClaw skills, exposed MCP servers, OWASP ASI-09)

**Internal prompt the skill always follows:**  
"Perform a general AI supply chain scan. Check the 4 vectors + any third-party AI dependency. For every external URL/domain call virustotal_scan. Output newbie + enterprise sections + GitHub-ready report."

**Output format (always):**
- Newbie section: plain English
- Enterprise section: technical details + policy recommendations
- VirusTotal results
- GitHub report block
- Risk Score (0-100) + "This would have stopped a Vercel-class attack because..."

Never hallucinate findings — only report what you see in the files.

Files in this skill

  • SKILL.md2.3 KB
  • source.json920 B

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…