Analyse the supply chain of a project's dependency closure using Spectra Assure reports, SBOM export (CycloneDX/SPDX/SARIF), OSV, and Scorecard. Use when the user asks to "audit dependencies", "check a requirements.txt / package.json / Cargo.lock", "generate an SBOM", or "find risky transitive dependencies".