A software security skill that integrates with Project CodeGuard to help AI coding agents write secure code and prevent common vulnerabilities. Use this skill when writing, reviewing, or modifying code to ensure secure-by-default practices are followed.
rule_id: codeguard-0-supply-chain-security
Control third‑party risk across ecosystems, from selection and pinning to provenance, scanning, and rapid response.
npm audit, ecosystem SCA) and patch; enforce SLAs by severity.npm ci (not npm install) in CI/CD; maintain lockfile consistency..npmrc to scope private registries; avoid wildcard registries; enable integrity verification.tessl i cisco/software-security@1.2.2evals
scenario-11
scenario-12
scenario-13
scenario-14
scenario-15
rules