/security-supply-chain
Unified supply-chain audit. Checks GitHub Actions SHA-pinning (`sha-pin:check`), package.json git+https deps (per `no-gitlab-megabytelabs-deps` semgrep), gitleaks scan, and trufflehog verified-only sweep. Surfaces any tag-mutable, git-URL, or secret-exposed surface. Per
$ npx -y skills add heymegabyte/claude-skills --agent claude-codeShips with claude-skills. Installing the plugin gets this command.
How it fires
How this command gets triggered: by you, by Claude, or both.
- Fires itselfClaude auto-loads it when your prompt matches the work.
- You can call itInvoke it directly when you want it.
- Slash command
/security-supply-chain
Context preview
What this command does when you run it.
Unified supply-chain audit. Checks GitHub Actions SHA-pinning (`sha-pin:check`), package.json git+https deps (per `no-gitlab-megabytelabs-deps` semgrep), gitleaks scan, and trufflehog verified-only sweep. Surfaces any tag-mutable, git-URL, or secret-exposed surface. Per
14-category autonomous product-building OS for 32+ AI coding tools. One-line prompts โ deployed products.
Repo: heymegabyte/claude-skills
Other commands on claude-skills.
- /agent-audit
Audit agents spawned in the current/last run against the agent-selection taxonomy
Open command - /agent-diversity-review
Run the Agent Diversity Review gate and emit the result table
Open command - /audit-cron-arc
Meta-analyze the effectiveness of a /loop arc โ per-iteration metrics, LOC delta trend, saturation detection, and a keep/lengthen/delete recommendation.
Open command - /audit-doctrine
Audit the rules/ directory for missing foundational principles; output gap list with priority and justification
Open command - /audit-hook-wiring
Validate ~/.claude/settings.json hooks block โ event names, file existence, executability, matcher syntax; --fix repairs common issues
Open command - /audit-mcp-error-semantics
Catch Resend-class bug (isError: false on HTTP 4xx/5xx) across all MCP server tool handlers
Open command

