feat: enrich 209 skills with MITRE ATLAS, D3FEND, and NIST AI RMF frontmatter

Added structured security framework mappings to SKILL.md frontmatter across all applicable skills:
- atlas_techniques: MITRE ATLAS v5.5 AML.TXXXX IDs (81 skills, AI-targeted attack techniques)
- d3fend_techniques: MITRE D3FEND v1.3 defensive technique labels (139 skills, mapped from ATT&CK IDs)
- nist_ai_rmf: NIST AI RMF 1.0 subcategory IDs (85 skills, AI risk management functions)

Also updates ATTACK_COVERAGE.md with coverage statistics for all three frameworks.
This commit is contained in:
mukul975
2026-04-06 01:56:17 +02:00
parent c15f73db46
commit ef27f026cb
209 changed files with 3959 additions and 3379 deletions
@@ -1,16 +1,27 @@
---
name: detecting-supply-chain-attacks-in-ci-cd
description: >
Scans GitHub Actions workflows and CI/CD pipeline configurations for supply chain
attack vectors including unpinned actions, script injection via expressions, dependency
confusion, and secrets exposure. Uses PyGithub and YAML parsing for automated audit.
Use when hardening CI/CD pipelines or investigating compromised build systems.
description: 'Scans GitHub Actions workflows and CI/CD pipeline configurations for supply chain attack vectors including unpinned
actions, script injection via expressions, dependency confusion, and secrets exposure. Uses PyGithub and YAML parsing for
automated audit. Use when hardening CI/CD pipelines or investigating compromised build systems.
'
domain: cybersecurity
subdomain: security-operations
tags: [detecting, supply, chain, attacks]
version: "1.0"
tags:
- detecting
- supply
- chain
- attacks
version: '1.0'
author: mahipal
license: Apache-2.0
atlas_techniques:
- AML.T0010
- AML.T0104
nist_ai_rmf:
- GOVERN-5.2
- MAP-1.6
- MANAGE-2.2
---
# Detecting Supply Chain Attacks in CI/CD