{
  "id": "composer-audit-supply-chain-review",
  "name": "Composer Audit & Supply-Chain Review",
  "type": "skill",
  "provider": "php",
  "harnesses": ["claude-code", "cursor", "codex", "gemini", "kiro", "other"],
  "summary": "Skill for reviewing Composer dependency supply-chain posture: composer audit advisory scanning and CI exit-code gating, config.policy advisory/abandoned settings, and composer.lock integrity and drift, so a vulnerable or abandoned Packagist dependency cannot reach production ungated.",
  "source_type": "original",
  "official_docs": [
    "https://getcomposer.org/doc/03-cli.md",
    "https://getcomposer.org/doc/06-config.md",
    "https://getcomposer.org/doc/01-basic-usage.md",
    "https://owasp.org/www-project-top-ten/"
  ],
  "security_notes": "Static-review-only skill: Read/Grep/Glob, no execution and no network mutation. Never installs, updates, or requires packages. Reports composer audit posture from configuration and lockfile evidence, never fabricates advisory identifiers, and treats any credential in auth.json or configuration as a redact-and-flag finding.",
  "last_verified": "2026-07-16",
  "path": "skills/php/composer-audit-supply-chain-review",
  "author": "github: VincentChuWaiChow",
  "version": "0.1.0"
}
