Supply Chain Security
Supply chain security protects software from tampering and compromise as it is developed, built, distributed, and maintained. Risks can enter through vulnerable or malicious dependencies, stolen maintainer credentials, altered release packages, or insecure build systems. Security practices in this area help teams assess where software comes from, detect suspicious changes, verify integrity, and respond to incidents before they spread to users or production systems.
Open source tools include dependency scanners, package and release monitors, provenance and integrity verifiers, code analyzers, and systems for auditing build pipelines. When choosing one, consider which ecosystems and workflows it supports, how clearly it reports findings, its license and requirements, and the maturity and maintenance activity of the project. These tools are useful for developers, security teams, package maintainers, and organizations that rely on external software or publish their own.
4 repositories · updated September 11, 2026

SkillSpector: NVIDIA's Security Scanner for AI Agent Skills
SkillSpector is a critical security scanner developed by NVIDIA for AI agent skills. It identifies vulnerabilities, malicious patterns, and various security risks, including prompt injection and data exfiltration, in skills for platforms like Claude Code, Codex, and MCP. This tool empowers developers and users to ensure the safety and integrity of AI agent environments before skill installation.

Awesome AI Agent Attacks: A Curated Timeline of AI Security Incidents
The Awesome AI Agent Attacks repository provides a meticulously curated timeline of real-world AI agent security incidents, breaches, and vulnerabilities from 2024 to 2026. Each entry is thoroughly sourced and dated, offering a factual overview of the evolving threat landscape in agentic AI. It serves as an essential resource for understanding the practical implications of AI security.

Supply Chain Monitor: Automated Detection of Package Compromises
Supply Chain Monitor is a powerful tool by Elastic designed to automatically detect supply chain compromises in popular PyPI and npm packages. It polls registries for new releases, diffs them against predecessors, and uses an LLM via Cursor Agent CLI to classify changes as benign or malicious. Malicious findings trigger immediate Slack alerts, enhancing security for your software dependencies.

Hexora: Static Analysis Tool for Malicious Python Code
Hexora is a powerful static analysis tool, developed in Rust, designed to identify malicious and harmful patterns within Python code. It helps audit project dependencies, detect suspicious scripts, and analyze Indicators of Compromise (IoC) files. This tool is essential for enhancing software supply chain security and proactively identifying threats.