scan-fulllisted
Install: claude install-skill DevInder1/supply-chain-scanner-public
# Full workspace scan
When the user wants comprehensive coverage — project + system + IDE — or mentions any of: *"my whole machine"*, *"my system"*, *"Homebrew"*, *"apt packages"*, *"VS Code extensions"*, *"JetBrains plugins"*, *"IDE security"*, *"audit everything"*:
1. Call the **tridentchain** MCP tool `scan_full` with:
- `project_path` = workspace root (absolute path)
- `output_dir` = `.tridentchain-out-full`
- `run_profile` = `"full"`
- `max_findings` = 30
2. **Report findings grouped by source** — this is the key value of `scan_full`:
- **Project** (npm/PyPI) — `raw_summary.vulnerability_breakdown_by_type.project`
- **System packages** (brew, apt) — `raw_summary.vulnerability_breakdown_by_type.system`
- **IDE extensions** (VS Code, JetBrains) — `raw_summary.vulnerability_breakdown_by_type.extension`
3. **Highlight critical system findings first.** A critical CVE in `git`, `openssl`, or `ffmpeg` on the user's machine outranks any project finding. Always surface these at the top with the exact upgrade command (`brew upgrade git`, etc.).
4. If any KEV-listed package is on the user's machine (system or project), call it out as URGENT.
5. Report runtime — `scan_full` is slower than `scan_project` (5–60 seconds depending on how many system components are installed).
## Why this matters
Project-only scanners miss the most impactful CVEs. A recent example: many systems shipped with `git 2.35.x` which has **3 critical CVEs** (CVE-2024-32002 and family). A