
Turn any codebase, with its docs, SQL schemas, configs, and PDFs, into a queryable knowledge graph. A /graphify skill for Claude Code, Cursor, Codex, and Gemini CLI: local deterministic AST parsing, every edge explained, no vector store.
SITF gives you a way to model attacks against software delivery systems, from endpoint and VCS through CI/CD, registries, and production. It uses `techniques.json` as the source of truth, then builds the docs and HTML explorers from that data.
Builders who use Claude Code to map supply chain incidents, red team reports, and SDLC attack paths.
You can turn incident writeups into structured attack flows and new technique proposals instead of starting from scratch.
Claude skills such as `/attack-flow` and `/red-team-flow` generate SITF-compliant flow files from incidents and engagement reports.
The `/technique-proposal` skill helps you draft new technique definitions when the library has gaps.
`app/visualizer.html` provides a drag-and-drop flow builder for mapping attack stages across SDLC components.
`app/techniques-library.html` and `TECHNIQUE_LIBRARY.md` present the catalog of techniques with search and filtering.
`techniques.json` stores the technique definitions that drive the documentation and web views.
A comprehensive framework for analyzing and defending against attacks targeting Software Development Lifecycle infrastructure.
Launch the Flow Builder - Interactive tool for mapping attack flows

Explore Techniques Visually - Interactive visual explorer with filtering and search

Automated Attack Flow Generation - Use Claude skills to automatically generate SITF-compliant attack flows and technique proposals:
| Skill | Purpose |
|---|---|
/attack-flow | Generate flows from public incidents and breach reports |
/red-team-flow | Generate flows from red team/pentest engagement reports |
/technique-proposal | Create new technique definitions when gaps are identified |
See SKILLS.md for detailed usage instructions and examples.
Launch builder locally - Download visualizer.html locally, open and build offline
Explore techniques - Download techniques-library.html locally, open and browse techniques offline
Read the Implementation Guide - Complete methodology, case studies, and usage instructions
SITF helps security teams analyze supply chain attacks by:
SITF includes Claude AI skills for automated attack flow generation. See SKILLS.md for complete documentation.
| Skill | Input | Output |
|---|---|---|
/attack-flow | Incident name, URL, or web search | sample-flows/<name>.json |
/red-team-flow | Engagement report (file/URL/text) | flows/red-team/<name>.json |
/technique-proposal | Gap description | technique-proposals/<id>.md |
Manual Method:
techniques.json - the source of truthpython3 build-techniques.py to regenerate documentation and web appAutomated Method (with Claude):
/technique-proposal to generate a complete technique definitiontechniques.jsonpython3 build-techniques.py to regenerate documentationThe build script generates:
TECHNIQUE_LIBRARY.md - Human-readable documentationapp/techniques-library.html - Visual technique explorer with filtering and searchapp/visualizer.html - Interactive attack flow builderManual Method:
Automated Method (with Claude):
/attack-flow <attack-name> websearch to automatically generate flows from incident reportsTarget Audience: Incident Response Teams, Security Architects, Threat Intelligence Teams, Security Engineers
Focus: Protecting producer organizations (software vendors, OSS maintainers) who create supply chain components
Starting April 14 2026, SITF is licensed under CC BY-NC 4.0. Versions prior to this date remain under CC BY-NC-ND 4.0.
Sign in to join the discussion.
No comments yet. Be the first to say what this is good for.

Turn any codebase, with its docs, SQL schemas, configs, and PDFs, into a queryable knowledge graph. A /graphify skill for Claude Code, Cursor, Codex, and Gemini CLI: local deterministic AST parsing, every edge explained, no vector store.
Open-source AI job search: scan job portals, evaluate listings into a structured A-H report with a global 1-5 score, tailor your CV, track applications — runs locally in your AI coding CLI (Claude Code, Codex, OpenCode, Antigravity…)
AI agent skill that researches any topic across Reddit, X, YouTube, HN, Polymarket, and the web - then synthesizes a grounded summary
Academic Research Skills for Claude Code: research → write → review → revise → finalize
817 structured cybersecurity skills for AI agents · Mapped to 6 frameworks: MITRE ATT&CK, NIST CSF 2.0, MITRE ATLAS, D3FEND, NIST AI RMF & MITRE F3 (Fight Fraud) · agentskills.io standard · Works with Claude Code, GitHub Copilot, Codex CLI, Cursor, Gemini CLI & 20+ platforms · 29 security domains · Apache 2.0
Distilly — Distill how they think into reusable Skills for any Agent or Bot. Formerly Colleague Skill(原同事 Skill).