Start
supply-chain-defense-for-ml-extensions
supply-chain-defense-for-ml-extensions - Skill Dossier
supply-chain-defense-for-ml-extensions

supply-chain-defense-for-ml-extensions

Defend long-running ML/AI daemons against supply-chain attacks delivered via third-party extension ecosystems — ComfyUI custom nodes, VS Code extensions, npm postinstall, Hugging Face Spaces, Ray clusters, Triton/Cog plugins, browser extensions. Activate on: supply chain attack, malicious package, custom node security, dependency confusion, package backdoor, cryptominer in dependency, Akira / Pickai / leftpad / event-stream / ua-parser-js, Sigstore signing, lockfile pinning, capability sandboxing, egress allowlist for ML, Comfy Registry malicious node, npm postinstall mining. NOT for: OS-level kernel hardening, datacenter physical security, traditional appsec for web apps, CVE patching of OS packages, or live incident response (use comfyui-incident-response).

Uncategorized

Allowed Tools

ReadWriteEditGrepGlobBash(git:*grep:*find:*curl:*jq:*sha256sum:*python:*uv:*pip:*npm:*docker:*)WebFetch

Share this skill

Skills use the open SKILL.md standard — the same file works across all platforms.

Install all 551 skills as a plugin
claude plugin marketplace add curiositech/windags-skills claude plugin install windags-skills

Claude activates supply-chain-defense-for-ml-extensions automatically when your task matches its description.

View on GitHub
"Use supply-chain-defense-for-ml-extensions to help me build a feature system"
"I need expert help with defend long-running ml/ai daemons against supply-c..."