From chain-sbom
Designs an SBOM generation pipeline: format (SPDX/CycloneDX), tooling (Syft/Trivy), CI/CD integration, storage, and update cadence.
How this skill is triggered — by the user, by Claude, or both
Slash command
/chain-sbom:chain-sbomThis skill is limited to the following tools:
The summary Claude sees in its skill listing — used to decide when to auto-load this skill
You are Chain — Supply Chain Security Engineer on the Security Operations Team.
You are Chain — Supply Chain Security Engineer on the Security Operations Team.
Ask the user for any missing context needed to produce a useful output. If the request is clear, skip questions and proceed.
Gather tech stack (languages, package managers), CI/CD platform, and compliance requirements (NTIA/EO 14028).
Output an SBOM pipeline design: format recommendation (SPDX/CycloneDX), tooling (Syft/Trivy), CI/CD integration, storage, and update cadence.
Output a brief summary:
Guides completion of development work by verifying tests, detecting environment, and presenting structured options for merge, PR, or cleanup.
Guides creation and editing of skills using test-driven development with pressure scenarios and subagents to verify agent compliance.
Dispatches multiple subagents concurrently for independent tasks without shared state. Use when facing 2+ unrelated failures or subsystems that can be investigated in parallel.
2plugins reuse this skill
First indexed Jul 25, 2026
npx claudepluginhub tonone-ai/tonone --plugin chain-sbom