canon-supply-chain-analysis

Compose a governed supply-chain packet with SBOM, vulnerability, license, and legacy evidence.

1|Updated Mar 26, 2026
One-click install
npx skills add https://github.com/apply-the/canon --skill canon-supply-chain-analysis
Or copy as Structured Prompt for Agent▼
Please help me install this Agent Skill.
Skill: canon-supply-chain-analysis
Source: https://github.com/apply-the/canon/tree/main/.agents/skills/canon-supply-chain-analysis
Command: npx skills add https://github.com/apply-the/canon --skill canon-supply-chain-analysis

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Use when you need a governed supply-chain-analysis packet for an existing repository with explicit SBOM, vulnerability, license, and legacy posture evidence.

Core Features & Use Cases

  • Bounded governance: create auditable packets that document dependency posture, licensing, SBOMs, and legacy risks.
  • Evidence integration: collate vulnerability triage notes, license compliance, and modernization pressure into a single packet.
  • Stakeholder-ready outputs: generate a portable, reviewable artifact set for approvals and publishing.

Quick Start

Trigger a governed supply-chain-analysis run for the currently bounded repository surface.

Frequently Asked Questions about canon-supply-chain-analysis

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I generate a governed supply-chain analysis packet for a repository?▼

Generate a governed supply-chain analysis packet by triggering an automated run that binds context to the local Canon installation and composes SBOM, vulnerability, license, and legacy posture evidence into a single reviewable artifact.

What is a supply-chain posture packet used for?▼

A supply-chain posture packet is used to document dependency, licensing, SBOM, and legacy risks in an auditable format, providing stakeholder-ready artifacts for formal approvals and publishing.

How do I automate SBOM and license compliance reporting for bounded code bases?▼

Automate SBOM and license compliance reporting by triggering a governed run that collates vulnerability triage notes and modernization pressure into a portable, bounded packet for the specified code base.

Do I need explicit inputs to document vulnerability and legacy posture risks?▼

Yes, documenting vulnerability and legacy posture risks requires explicit inputs such as RISK, ZONE, and authored inputs to accurately bind context and formalize the governance packet.

Can I capture dependency posture and modernization pressure in a single artifact?▼

Yes, you can capture dependency posture and modernization pressure in a single artifact by composing a bound packet that integrates vulnerability, license, and legacy evidence for stakeholder review.

When do I need a formal packet for repository supply-chain governance?▼

You need a formal packet for repository supply-chain governance when dependency posture, licensing compliance, and legacy risk must be captured as auditable evidence for bounded code bases requiring approvals.