Detect vulnerable, outdated, or malicious packages in the project dependency tree. Use this skill whenever the user mentions supply chain security, sbom, dependency scan, malicious package, typosquat, transitive dependency, slsa, or is working with Syft, OSV-Scanner, Sigstore, even if they never say "software supply chain security" explicitly. Routes live lookups through the Supply-Chain-Sentinel-Plugin endpoint. Do not use it for unrelated application feature work or general coding questions.