Login
Download
Skill UI
Browse and discover
11149+
curated skills
All
Development
Artificial Intelligence
Design & Creative
Product & Business
Data Science
Marketing
Soft Skills
Productivity
Engineering
Languages
Search
Dependency-Confusion
, found
4
results
Default
Newest
Most Downloaded
Detecting Supply Chain Attacks In CI/CD
detecting-supply-chain-attacks-in-ci-cd
mukul975/Anthropic-Cybersecurity-Skills
379
This tool scans GitHub Actions workflows and CI/CD configurations to identify critical supply chain attack vectors. It specifically checks for unpinned actions, risks from script injection using expressions, dependency confusion, and secrets exposure, helping organizations harden their build systems against sophisticated threats.
View Details
Detecting Supply Chain Security Vulnerabilities
performing-supply-chain-attack-simulation
mukul975/Anthropic-Cybersecurity-Skills
301
This skill simulates and detects critical software supply chain attacks, including typosquatting via Levenshtein distance, dependency confusion detection against private registries, and package integrity verification using SHA-256 hashing. It also performs comprehensive vulnerability scanning against known CVEs using pip-audit. It is essential for security assessments, compliance audits, and incident response when validating software component trustworthiness.
View Details
Dependency Confusion Supply Chain Attacks
dependency-confusion
yaklang/hack-skills
225
An expert playbook for identifying and simulating dependency confusion attacks in software supply chains. It comprehensively covers how internal package names can be squatted on public registries, leading to malicious code execution via package manager lifecycle hooks (e.g., npm, pip, Maven). Use this guide for authorized red-team exercises and deep vulnerability assessment of build processes.
View Details
Detect Dependency Confusion Attacks
detecting-dependency-confusion
mukul975/Anthropic-Cybersecurity-Skills
377
A comprehensive tool and methodology for identifying and preventing dependency confusion attacks across major package ecosystems (npm, PyPI, Maven). It detects instances where internal, private package names are leaked and subsequently published publicly by attackers. The skill provides both detection (enumerating claimable internal names) and prevention strategies (enforcing registry pinning and scope restrictions) to secure the software supply chain.
View Details
1
Language
简体中文
English