supply-chain
4 resources across 2 kinds
Tools
- Open ↗Skill Security Checkpassive
Claude Code skill and CLI scanner that audits community skill files across 26 detection categories (prompt injection, exfiltration, permission bypass), with runtime hooks that block dangerous commands and inspect MCP responses.
- Open ↗is-maliciouscloud costpassive
MIT-licensed Node CLI that sends a project's selected source, config, build, and CI files to TypeSafe Jev and reports suspicious files and line ranges with probabilities; needs a TypeSafe API key and spends paid input tokens.
- Open ↗Jev Security Scancloud costhostedopt-inpassive
MIT-licensed Python CLI and Claude Code/Codex skill that reviews Agent Skills, MCP config and source code for suspicious behavior before installation: offline by default, or nine-category Jev triage with a TypeSafe API key.
References
- Open ↗
RSAC 2025 deck by Ian Brelinsky (OpenAI) and Josiah Hagen (Trend Micro) summarising CoSAI's four workstreams - AI supply chain, preparing defenders, risk governance, agentic AI - and mapping ten job roles to existing frameworks.