## https://sploitus.com/exploit?id=KITPLOIT:TOOLS-GITHUB-ERIS-THS-SUPPLY-CHAIN-GUARD
# Supply Chain Guard (SCG)
> **npm/yarn ããã³ Python (pip/poetry/uv) ãµãã©ã€ãã§ãŒã³æ»æåãã€ã³ã·ãã³ã察å¿ããŒã«ããã â ç¡æãããŒã«ã«ãäŸåé¢ä¿äžèŠã**
SCG ã¯ãã«ãã¬ããžã§åçšããŒã«ãšç«¶åããã¹ãã£ã³ãšã³ãžã³ã§ã¯**ãããŸãã** ããã㯠Claude Code ã¹ãã«ããã³ã¹ã¿ã³ãã¢ãã³ã·ã§ã«ããŒã«ãããã§ããã3ã€ã®ããšãããŸãè¡ããŸã: **(1)** ç¹å®ã®ã€ã³ã·ãã³ããçºçããéã«ãé«éã§åçŸå¯èœãª _åå察å¿_ ãæäŸããïŒãä»ããèªåã®ãã·ã³ã圱é¿ãåããŠãããïŒãïŒã**(2)** æ¢åã® OSS ã¹ãã£ããŒïŒ`npm audit`ã`osv-scanner`ã`pip-audit`ïŒã1ã€ã®æ§é åããããã¹ã«ãŸãšã調æŽããã**(3)** ç¹ã« AI éçºç°å¢åãã«ãããŒãã«åŸããã _èšèšè¡ç_ ã®æèšãææžåãã â ããã¯äžè¬çãªã¹ãã£ããŒã§ã¯ã«ããŒãããªãå
容ã§ãã
ããã¯ã以äžãå«ãå®éã®ã€ã³ã·ãã³ãäžã«æ§ç¯ããã³åŒ·åãããŸãã:
* **some-email@example.com RAT ã€ã³ã·ãã³ã (2026-03-31)** â npm ã¡ã³ããã¢ã«ãŠã³ãä¹ã£åã (UNC1069/DPRK-APT) ã«ããããã¡ã³ãã äŸåé¢ä¿ RAT ãæ³šå
¥ãããŸãã
* **Starlette BadHost (CVE-2026-48710, 2026-05-22)** â Python HTTP ãã¬ãŒã ã¯ãŒã¯ã® Host ããããŒãã¹ã€ã³ãžã§ã¯ã·ã§ã³ â SSRF/RCEãFastAPIãvLLMãLiteLLMããããŠããåºç¯ãª AI ãšãŒãžã§ã³ããšã³ã·ã¹ãã ã«åœ±é¿ãäžããŸã
## v4 ã®æ°æ©èœ (2026-05-27)
* **Python ãµãã©ã€ãã§ãŒã³ã¹ãã£ã³** â `scripts/project-scan-py.sh` ã§ pip-audit / osv-scanner / CVE ãã©ã°ä»ãããŒãžã§ã³æ€åºãå®è¡
* **CVE ãã©ã°ä»ãããŒãžã§ã³ã¬ã€ã€ãŒ (L3-CVE)** â å³å¯ãª semver 仿§è©äŸ¡ã«ãããæ¢ç¥ã®è匱ãªããŒãžã§ã³ã®æ£èŠããã±ãŒãžã远跡 (BadHost CVE-2026-48710 ãæšæºè£
å)
* **èšèšè¡çã¬ã€ãã©ã€ã³** â stdio åªå
ã® MCP ãã©ã³ã¹ããŒããããŒãžã§ã³åºå®èŠåŸãGCP ããã©ã«ã Compute SA ã®åŒ·å (SKILL.md §D.7 DesignHygiene ãåç
§)
* **Guild-CLI Devil ã¬ã³ãºçµ±å** â guild-cli ã¯ãŒã¯ãããŒãã SCG ã Devil ã¬ã³ãºãšããŠåŒã³åºãå¯èœ (以äžã®ãGuild-CLI Devil çµ±åããåç
§)
* * *
## ç®æ¬¡
* ãªããããååšããã®ã
* SCG ãæ¢åããŒã«ãšç°ãªãç¹
* SCG ã®æ¬è³ªïŒããã§ãªããã®ïŒ
* ã¢ãŒããã¯ãã£
* ã¯ã€ãã¯ã¹ã¿ãŒã
* ã¹ãã£ã³ã¢ãŒã
* è
åšã€ã³ããªãžã§ã³ã¹
* Devil Gate ãã¬ãŒã ã¯ãŒã¯
* ã¹ã¿ã³ãã¢ãã³ã¹ã¯ãªãã
* CI/CD çµ±å
* 察å¿ãã¬ã€ããã¯
* IOC ãªãã¡ã¬ã³ã¹
* å
責äºé
* å¶éäºé
* å®å
šæ§æ€èšŒ
* ã©ã€ã»ã³ã¹
* * *
## ãªããããååšããã®ã
2026幎3æ31æ¥ãåºãå©çšãããŠãã `axios` npm ããã±ãŒãž (v1.14.1 ããã³ v0.30.4) ãã**UNC1069/DPRK-APT** ïŒGoogle Threat Intelligence Group ã«ããïŒã«èµ·å ããã¡ã³ããã¢ã«ãŠã³ãã®ä¹ã£åãã«ãã䟵害ãããŸããããã®æ»æã¯ããã¡ã³ãã äŸåé¢ä¿ (`some-email@example.com`) ãæ³šå
¥ãã`postinstall` ã¹ã¯ãªãããä»ããŠã¯ãã¹ãã©ãããã©ãŒã RAT ãå±éããŸãããããã¯æ£åœãªã·ã¹ãã ããã»ã¹ã«åœè£
ãããŠããŸããã
**Supply Chain Guard (SCG)** ã¯ããã®ã€ã³ã·ãã³ãäžã«ä»¥äžãæäŸããããã«æ§ç¯ãããŸãã:
1. **峿æ€åº** â ä»ããèªåã®ãã·ã³ããããžã§ã¯ãã圱é¿ãåããŠãããïŒ
2. **æ§é åè©äŸ¡** â æ·±å»åºŠã¯ïŒãã©ã¹ãååŸã¯ïŒ
3. **ã¬ã€ãä»ã察å¿** â å®å
šç¢ºèªä»ãã®ã¹ããããã€ã¹ãããã®ä¿®åŸ©æé
4. **ç¶ç¶çé²åŸ¡** â åçºé²æ¢ã®ããã®8ã²ãŒãæ€èšŒãã¬ãŒã ã¯ãŒã¯
* * *
## SCG ãæ¢åããŒã«ãšç°ãªãç¹
SCG ã¯æ¢åã®ã»ãã¥ãªãã£ããŒã«ã®ä»£æ¿ã§ã¯ãããŸãããè€æ°ã®æ€åºã¬ã€ã€ãŒãæ§é åãããæ€èšŒãã¬ãŒã ã¯ãŒã¯ãšã¬ã€ãä»ã修埩ãšçµã¿åãããŠããã**ã¢ã¯ãã£ããªã€ã³ã·ãã³ãäž** ããæ¢åã®ããŒã«ãšäœµçšãã宿çãªãã§ãã¯ãšããŠäœ¿çšããããã«èšèšãããŠããŸãã
**SCG ã䜿çšãã¹ãå Žå:**
* ãµãã©ã€ãã§ãŒã³ã€ã³ã·ãã³ããçºçããä»ããèªåã®ãã·ã³ãšãããžã§ã¯ãã確èªããå¿
èŠãããå Žå
* 䟵害ãå®å
šã«å¯ŸåŠãããããšã確èªããããã®ãæ§é åãããç¹°ãè¿ãå¯èœãªããã»ã¹ãå¿
èŠãªå Žå
* SaaS äŸåé¢ä¿ãªãã§ããŒã«ã«ã§å®è¡ããã軜éãã§ãã¯ãå¿
èŠãªå Žå
**ä»ã®ãã®ã䜿çšãã¹ãå Žå:**
* ç¶ç¶çãªãªã¢ã«ã¿ã€ã ã¢ãã¿ãªã³ã°ãå¿
èŠ â SnykãSocket.dev
* ã©ã€ã»ã³ã¹ã³ã³ãã©ã€ã¢ã³ã¹ã¹ãã£ã³ãå¿
èŠ â SnykãFOSSA
* npm/yarn ãè¶
ããã«ãã¬ããžãå¿
èŠ â osv-scannerïŒpipãcargoãgo ãªã©ããµããŒãïŒ
* * *
## SCG ã®æ¬è³ªïŒããã§ãªããã®ïŒ
ç§ãã¡ã¯ãéçã«ã€ããŠæ£çŽã§ãããããšæããŸããSCG ã¯3ã€ã®ãã®ã§ã:
1. **ã³ãŒããšããŠã®ã€ã³ã·ãã³ã察å¿ãã¬ã€ããã¯ã** ååä»ãã€ã³ã·ãã³ãïŒaxios RATãShai-Huludãæ°ãã CVEïŒãçºçãããšããSCG ã¯ã圱é¿ãåããŠãããããããããªãã©ããããããå®è¡å¯èœãªãã§ãã¯ãªã¹ãã«å€æããŸã â 8ã€ã®æ€èšŒã²ãŒããéèŠåºŠãããªãã¯ã¹ããã㊠_ãã¹ãŠã®ç Žå£çè¡å_ ã«æç€ºç㪠`[y/N]` 確èªãå¿
èŠãšãã修埩ã¹ã¯ãªãããããã SCG ã®äž»ãªäŸ¡å€ã§ã: åçšã¢ãã¿ãªã³ã°ããŒã«ã§ã¯å¯Ÿå¿ã§ããªããé«éã§æ§é åããã _åå察å¿_ ã§ãã
2. **æ¢åã® OSS ã¹ãã£ããŒã®ãªãŒã±ã¹ãã¬ãŒã¿ãŒã** L1/L2 ã¬ã€ã€ãŒã¯ `npm audit` / `pip-audit` / `osv-scanner` ãã©ããããŸããçã®æ€åºåã®ã»ãšãã©ã¯åçšãããã®ã§ããSCG ã®è²¢ç®ã¯ããããã1ã€ã®ãã¹ã«ãã³ãã«ããã¬ãžã¹ããªããŒã«ã§ã¯è¡ããªããã¡ã€ã«ã·ã¹ãã /IOC ãã§ãã¯ã远å ããåºåãèªã¿ãããå®çšçã«ããããšã§ãã
3. **å®éã®èšèšè¡çã®æèšã®ææžå** ïŒSKILL.md §D.7ïŒâ ç§ãã¡ãå®éã«ééãŸãã¯èª¿æ»ããäºé
: MCP ãã©ã³ã¹ããŒãã®éžæãGCP ããã©ã«ã SA ã®åŒ·åãã€ã³ã¹ããŒã«æå®è¡ãã¯ãã«ãããã³ AI éçºããŒã«ãæšçãšããè
åšïŒShai-Hulud ã `.claude/settings.json` ãèªã¿åããSANDWORM_MODE ã MCP èšå®ãæ±æããïŒããã®ããã â AI æ¯æŽéçºã®ããã®ãµãã©ã€ãã§ãŒã³è¡ç â ã¯ãSCG ãçã«å·®å¥åãããŠããåéã§ãã
### SCG ãæå³çã«ããã§ãªããã®
* **ã«ãã¬ããžç«¶åçžæã§ã¯ãããŸããã** è
åšããŒã¿ããŒã¹ïŒ`SKILL.md` D.2ãL3 éçãªã¹ãïŒã¯**æåã§ã¡ã³ããã³ã¹** ãããŠããŸã â ç§ãã¡ãèªãã ã€ã³ã·ãã³ããä¿æããŠãããã©ã€ãã®åçšãã£ãŒãã远跡ããæ°äžã®æªæã®ããããã±ãŒãžã§ã¯ãããŸãããæåãã¥ã¬ãŒã·ã§ã³ãªã¹ãã¯ãæ°ããè
åšã®å®éã®ããŒã¹ã« _ã€ããŠããããšã¯ã§ããŸãã_ ãç§ãã¡ã¯ãããè£
ããŸããã
* **è¡ååæãšã³ãžã³ã§ã¯ãããŸããã** SCG ã¯æ¢ç¥ã®ãã¿ãŒã³ã«ãããããŸããé£èªåããããã€ããŒãããå
¬éã¢ããã€ã¶ãªã®ãªãçã®ãŒããã€ã¯ãèšèšäžç¯å²å€ã§ãã
* **ç¶ç¶çã¢ãã¿ãªã³ã°ã§ã¯ãããŸããã** ã€ã³ã·ãã³ãäžãŸãã¯å®æçãªã¹ã€ãŒããšããŠå®è¡ãããã€ã³ãã€ã³ã¿ã€ã ãã§ãã¯ã§ãããäŸåé¢ä¿ã°ã©ããç£èŠãããµãŒãã¹ã§ã¯ãããŸããã
### SCG ã®ä»åŸ
æåãã¥ã¬ãŒã·ã§ã³ããŒã¿ããŒã¹ã¯ã«ãã¬ããžã§åãŠãªããããç§ãã¡ã¯æå³çã« SCG ã _眮ãæãã«ãã_ åéã«æè³ããŠããŸããåžžã«è² ããåéã§ã¯ãããŸãã:
* **ããæ·±ãã€ã³ã·ãã³ã察å¿ãã¬ã€ããã¯** (#1) â ããè¯ãåå察å¿ã®äººéå·¥åŠãããå€ãã®ã€ã³ã·ãã³ããã³ãã¬ãŒã
* **AI éçºç°å¢ã®è¡ç** (#3) â Claude Code / Cursor / MCP ãµãŒããŒããã³é¡äŒŒããŒã«ãæšçãšããè
åšã®æ€åºãšã¬ã€ãã³ã¹ãåçšãµãã©ã€ãã§ãŒã³ã¹ãã£ããŒã¯ã»ãšãã©ããã«å¯Ÿå¿ããŠããŸãã
éçè
åš DB (#2) ã¯æ³šç®ãã¹ãã€ã³ã·ãã³ããçºçãããšãã«æŽæ°ããç¶ããŸãããããã¯ç«¶äºããããšããæ¹åã§ã¯**ãããŸãã** ã
* * *
## ã¢ãŒããã¯ãã£
SCG 㯠**ãã¡ã€ã³é§åèšèš (DDD)** ã¢ãŒããã¯ãã£ã«åŸãã3ã€ã®ã¬ã€ã€ãŒã§æ§æãããŠããŸã:``` +-----------------------------------------------------+ | Domain Layer | | Threat models, known threats DB, severity matrix, | | Devil Gate definitions | +-----------------------------------------------------+ | Application Layer | | Use cases, scan pipeline, response protocols, | | Devil execution loop | +-----------------------------------------------------+ | Infrastructure Layer | | Scanner scripts (npm audit, OSV, static list, | | IOC filesystem, network, lockfile integrity) | +-----------------------------------------------------+
root@kitploit:~
### ã¹ãã£ã³ãã€ãã©ã€ã³
åã5å±€ãã€ãã©ã€ã³ãäž¡æ¹ã®ãšã³ã·ã¹ãã ã«é©çšãããåå±€ã§ãšã³ã·ã¹ãã åºæã®ã¹ãã£ããŒã䜿çšãããŸãïŒ```
L1 âââ L2 âââ L3 âââ IOC âââ LF âââ assess(SeverityMatrix) âââ VERDICT
äž¡æ¹ã®ãã€ãã©ã€ã³ã¯åãSeverityMatrixãšDevil Gate Frameworkã«ãã£ãŒãããŸãã
* * *
## ã¯ã€ãã¯ã¹ã¿ãŒã
### Claude Codeã¹ãã«ãšããŠ
`SKILL.md` ã Claude Code ã¹ãã«ãã£ã¬ã¯ããªã«ã³ããŒããŠãã ãã:```bash
# Global (all projects)
cp SKILL.md ~/.claude/skills/supply-chain-guard.md
# Or project-specific
mkdir -p .claude/skills cp SKILL.md .claude/skills/supply-chain-guard.md
root@kitploit:~
ãã®åŸãClaude Code ã§åŒã³åºããŠãã ããïŒ```
> /supply-chain-guard
> "Check this project for supply chain issues"
> "Is my machine affected by the axios compromise?"
### ã¹ã¿ã³ãã¢ãã³ã¹ã¯ãªãããšããŠ```bash
# Environment-wide scan (IOC + all projects) [READ-ONLY]
./scripts/env-scan.sh
# npm/yarn project scan (requires package.json in cwd) [READ-ONLY]
./scripts/project-scan.sh
# Python project scan (requires pyproject.toml / requirements*.txt / poetry.lock / uv.lock in cwd) [READ-ONLY, added in v4]
./scripts/project-scan-py.sh
# IOC-only scan (filesystem + network artifacts) [READ-ONLY]
./scripts/ioc-scan.sh
# Remediation (interactive, every action requires confirmation)
./scripts/respond.sh --critical # Full RAT cleanup (npm + Python) ./scripts/respond.sh --high axios 1.14.0 # Pin npm package to safe version ./scripts/respond.sh --high urllib3 2.7.0 # Pin Python package (auto-detects pip/poetry/uv)
root@kitploit:~
> **Python ã®ä¿®åŸ©ã¯ä¿å®çã«èšèšãããŠããŸãã** npm ã®å Žåã`--high` ã¯èªåçã«ãªãŒããŒã©ã€ããé©çšããŸããPython ã®å Žå㯠*ã¬ã€ã* ããŸããã€ãŸãããããŒãžã£ãŒïŒpip/poetry/uvïŒãæ€åºããæ£ç¢ºãªãã³çãã³ãã³ãã衚瀺ããå®å
šãªã¹ãããïŒããã¯ãã¡ã€ã«ã®å€æŽã venv ã®åæ§ç¯ã³ãã³ãã¯å®è¡ããã衚瀺ã®ã¿ïŒã®ã¿ãé©çšããŸããããã«ãããæçåããã Python ããã±ãŒãžã³ã°ãšã³ã·ã¹ãã å
šäœã§èª€æ€åºãåŒãéãšãªããå¯äœçšãšããŠåŒ·å¶åã€ã³ã¹ããŒã«ãçºçããã®ãé²ããŸãã
polyglot ãªããžããªïŒnpm + PythonïŒã®å Žåãé¢é£ãããµããã£ã¬ã¯ããªããäž¡æ¹ã®ãããžã§ã¯ãã¹ãã£ããé æ¬¡å®è¡ããŸãã
> **å®å
šæ§èšèš:** ãã¹ãŠã®ã¹ãã£ã³ã¹ã¯ãªããã¯å³å¯ã«èªã¿åãå°çšã§ããæ±ºããŠå€æŽãåé€ãã€ã³ã¹ããŒã«ã¯è¡ããŸããã修埩ã¹ã¯ãªããïŒ`respond.sh`ïŒã®ã¿ãç Žå£çæäœãå®è¡ãã**ãã¹ãŠã®ã¢ã¯ã·ã§ã³ã«ã¯æç€ºç㪠`[y/N]` ã®ç¢ºèªãå¿
èŠ**ã§ãããã©ã«ã㯠NO ã§ãã
---
## ã¹ãã£ã³ã¢ãŒã
### ç°å¢ã¹ãã£ã³ïŒ`env_scan`ïŒ
éçºãã·ã³å
šäœã䟵害ã®å
åã«ã€ããŠã¹ãã£ã³ããŸãã
| ãã§ãã¯é
ç® | 説æ |
|-------|-------------|
| **IOC: ãã¡ã€ã«ã·ã¹ãã ** | RAT ãã€ããªãæ°žç¶åæ©æ§ãã¹ããŒãžã³ã°ãã¡ã€ã« |
| **IOC: ãããã¯ãŒã¯** | ã¢ã¯ãã£ã㪠C2 æ¥ç¶ïŒIP + ãã¡ã€ã³ïŒ |
| **IOC: ããã»ã¹** | å®è¡äžã®æªæã®ããããã»ã¹ |
| **ãããžã§ã¯ã暪æ** | ãã¹ãŠã® `package-lock.json` ãã¡ã€ã«ã䟵害ããŒãžã§ã³ã«ã€ããŠã¹ãã£ã³ |
| **æªæã®ããããã±ãŒãž** | æ¢ç¥ã®æªæã®ããããã±ãŒãžåãããã¯ãã¡ã€ã«å
ã«ååšããã |
**ããªã¬ãŒ:** "ãã® PC", "ç°å¢ãã§ãã¯", "ãã·ã³å
šäœ"
### ãããžã§ã¯ãã¹ãã£ã³ â npm/yarnïŒ`project_scan`ïŒ
åäžã® npm/yarn ãããžã§ã¯ãã®è©³çްã¹ãã£ã³ã`package.json` ãå«ãŸãããã£ã¬ã¯ããªããå®è¡ããŸãã
| å±€ | ã¹ãã£ã | 説æ |
|-------|---------|-------------|
| **L1** | `npm audit` | npm ã¬ãžã¹ããªçµç±ã®æ¢ç¥ã®èåŒ±æ§ |
| **L2** | `osv-scanner` / OSV.dev API | Google ã®ãªãŒãã³ãœãŒã¹è匱æ§ããŒã¿ããŒã¹ |
| **L3** | éçãªã¹ã | ããŒãã³ãŒããããæ¢ç¥ã®æªæã®ããããã±ãŒãžãã§ã㯠|
| **IOC** | ãã¡ã€ã«ã·ã¹ãã + ãããã¯ãŒã¯ | RAT ã¢ãŒãã£ãã¡ã¯ãæ€åº |
| **LF** | ããã¯ãã¡ã€ã«æŽåæ§ | `npm ci --dry-run` + æŽåæ§ããã·ã¥æ° |
**ããªã¬ãŒ:** "ãã®ãããžã§ã¯ã", "npm audit"ããŸãã¯ã«ã¬ã³ããã£ã¬ã¯ããªã« `package.json` ãååšãã
### ãããžã§ã¯ãã¹ãã£ã³ â PythonïŒ`project_scan_py`ãv4 ã§è¿œå ïŒ
åäžã® Python ãããžã§ã¯ãã®è©³çްã¹ãã£ã³ã`pyproject.toml`ã`requirements*.txt`ã`poetry.lock`ããŸã㯠`uv.lock` ãå«ãŸãããã£ã¬ã¯ããªããå®è¡ããŸãã
| å±€ | ã¹ãã£ã | 説æ |
|-------|---------|-------------|
| **L1** | `pip-audit` | PyPI Advisory DB çµç±ã®æ¢ç¥ã®è匱æ§ïŒãªãã·ã§ã³ â æªã€ã³ã¹ããŒã«ã®å Žå㯠SKIPã`pip install pip-audit` æšå¥šïŒ |
| **L2** | `osv-scanner` | Google ã®ãªãŒãã³ãœãŒã¹è匱æ§ããŒã¿ããŒã¹ã`uv.lock` / `poetry.lock` / `requirements*.txt` ã«å¯ŸããŠïŒãªãã·ã§ã³ â æªã€ã³ã¹ããŒã«ã®å Žå㯠SKIPïŒ |
| **L3-MAL** | éçæªæãªã¹ãïŒ`_L3_LIST`ïŒ | æ¢ç¥ã®ä¹ã£åããã / ã¿ã€ãã¹ã¯ã¯ããã£ã³ã°ããã±ãŒãžåãPEP 621 ãªã¹ããPoetry ã€ã³ã©ã€ã³ãrequirements 圢åŒã®å®£èšã«äžèŽïŒ[PR #4](https://github.com/eris-ths/supply-chain-guard/pull/4) åç
§ïŒããããããå Žå㯠FAIL |
| **L3-CVE** | éç CVE ãã©ã°ä»ãããŒãžã§ã³ãªã¹ãïŒ`_L3_CVE_LIST`ïŒ | æ£èŠããã±ãŒãžã®æ¢ç¥ã®è匱ããŒãžã§ã³ïŒäŸïŒ`starlette<1.0.1` for [BadHost CVE-2026-48710](https://cryptobriefing.com/starlette-badhost-vulnerability-ai-agents/)ïŒãPython ã® `packaging` ã©ã€ãã©ãªã«ããå³å¯ãªã»ãããŒè©äŸ¡ã確èªãããäžèŽã§ FAILãããã±ãŒãžã宣èšãããŠãããããã¯ãã¡ã€ã«ããªãå Žåã¯èŠåïŒããŒãžã§ã³è©äŸ¡äžå¯ïŒ |
| **IOC** | ãã¡ã€ã«ã·ã¹ãã + ããã»ã¹ | Python çã¢ãŒãã£ãã¡ã¯ããã§ãã¯ïŒäžæ£ãªã¹ã¯ãªãããäžå¯©ãªããã»ã¹ïŒ |
| **LF** | ããã¯ãã¡ã€ã«æŽåæ§ | `uv.lock` / `poetry.lock` / `requirements*.txt` ãæ£åžžã«ããŒã¹ãããåºå®ããŒãžã§ã³ãå«ãŸããŠããããšãç¢ºèª |
**ããªã¬ãŒ:** "ãã®ãããžã§ã¯ã" + Python ãã¡ã€ã«ãååšããããŸãã¯ã«ã¬ã³ããã£ã¬ã¯ããªã« `pyproject.toml` / `requirements*.txt` / `poetry.lock` / `uv.lock` ã®ãããããååšãã
> **äŸåé¢ä¿ã«ã€ããŠ:** L1ïŒ`pip-audit`ïŒããã³ L2ïŒ`osv-scanner`ïŒã¯ãããããã® CLI ãååšããªãå Žåããã³ããšå
±ã«æ£åžžã« SKIP ããŸããL3 ã¯åžžæçšŒåããå±€ã§ãããå€éšããŒã«ã¯äžèŠã§ãããæ£ç¢ºãª L3-CVE è©äŸ¡ã«ã¯ `pip install packaging` ãå¿
èŠã§ãã
---
## è
åšã€ã³ããªãžã§ã³ã¹
### æ¢ç¥è
åšããŒã¿ããŒã¹
| ID | æ¥ä» | ããã±ãŒãž | è
åšã¢ã¯ã¿ãŒ | ãã¯ã¿ãŒ |
|----|------|---------|-------------|--------|
| **T001** | 2026-03-31 | `some-email@example.com`, `some-email@example.com` | UNC1069/DPRK-APT | ã¡ã³ããä¹ã£åã â ãã¡ã³ãã äŸåé¢ä¿ â RAT |
| **T002** | 2018-11 | `some-email@example.com` | äžæ | äŸåé¢ä¿ã€ã³ãžã§ã¯ã·ã§ã³ â æå·è³ç£çªå |
| **T003** | é²è¡äž | `crossenv`, `loadsh`, `crypto-js-esm` | åçš® | ã¿ã€ãã¹ã¯ã¯ããã£ã³ã° â postinstall ããŒã¿æµåº |
### T001 ãã«ãã§ãŒã³ïŒaxios RATïŒ```
Credential theft â npm publish (bypass CI) â Inject phantom dep (plain-crypto-js)
â postinstall exec â RAT drop â C2 beacon (sfrclak.com:8000) â Persist
### å®å
šãªããŒãžã§ã³
ããã±ãŒãž| å®å
š| 䟵害æžã¿
---|---|---
axios (latest)| `1.14.0` (æ£ç¢º) ãŸã㯠`>=1.14.2`| `1.14.1`
axios (ã¬ã¬ã·ãŒ)| `0.30.3` (æ£ç¢º)| `0.30.4`
### å§åID
* GHSA-fw8c-xr5c-95f9
* MAL-2026-2306
* * *
## Devil Gate Framework
SCGã¯ã**8ã²ãŒãæ€èšŒãã¬ãŒã ã¯ãŒã¯** ã䜿çšããŠããã4ã€ã®ã«ããŽãªã«åé¡ãããåæã«ãŒããæã€ã·ãªã¢ã«ãã§ãŒã³ãšããŠå®è¡ãããŸãã
### ã²ãŒã
### ãã§ãŒã³å®è¡```
S1: Dependency (G1+G2) â S2: Runtime (G3+G4) â S3: Integrity (G5+G6) â S4: Environment (G7+G8) â Any fail? â Fix â Re-run entire chain â All pass? â "No concerns" â Done â 3 rounds without convergence? â Escalate to user
root@kitploit:~
### é倧床ãããªã¯ã¹
| ã¬ãã« | æ¡ä»¶ | ã¢ã¯ã·ã§ã³ |
|-------|-----------|--------|
| **é倧** | RATã¢ãŒãã£ãã¡ã¯ããæ€åºãããããŸãã¯æªæã®ããããã±ãŒãžãã€ã³ã¹ããŒã«ãããŠãã | ãããã¯ãŒã¯éé¢ â ããã»ã¹åŒ·å¶çµäº â æ°žç¶ååé€ â åã€ã³ã¹ããŒã« |
| **é«** | 䟵害ãããããŒãžã§ã³ã䜿çšäž | å®å
šãªããŒãžã§ã³ãåºå® â äžæžã â `npm ci` â æ€èšŒ |
| **äž** | çãããpostinstallã¹ã¯ãªãã | æåã¬ãã¥ãŒ â ãã¯ã€ããªã¹ãã«è¿œå ãŸãã¯åé€ |
| **äœ** | ããã¯ãã¡ã€ã«ã®ããªãã | `npm ci` ã§ååæ |
| **ã¯ãªã¢** | ãã¹ãŠã®ãã§ãã¯ã«åæ Œ | ã¢ã¯ã·ã§ã³äžèŠ |
> **å®å
šæ§:** é倧/é«ã®å¿çã¯ç Žå£çãªæäœãå«ã¿ãŸããSCGã¯åžžã«èª¿æ»çµæãæç€ºãã修埩ãå®è¡ããåã«æç€ºçãªãŠãŒã¶ãŒç¢ºèªãæ±ããŸãã
---
## ã¹ã¿ã³ãã¢ãã³ã¹ã¯ãªãã
### `scripts/env-scan.sh`
å®å
šãªç°å¢ã¹ãã£ã³ãIOCã¢ãŒãã£ãã¡ã¯ãããã§ãã¯ãã`$HOME`ïŒèšå®å¯èœïŒä»¥äžã®ãã¹ãŠã®ããã¯ãã¡ã€ã«ãã¹ãã£ã³ãã䟵害ãããããã±ãŒãžãå ±åããŸãã```bash
./scripts/env-scan.sh [scan_root_dir]
# Default: $HOME
### `scripts/project-scan.sh`
ãããžã§ã¯ãã¬ãã«ã®ã¹ãã£ã³ã`package.json`ãå«ããã£ã¬ã¯ããªããå®è¡ããŸãã```bash cd my-project /path/to/scripts/project-scan.sh
root@kitploit:~
### `scripts/ioc-scan.sh`
IOCã®ã¿ã®ã¹ãã£ã³ãæ¢ç¥ã®C2ã€ã³ãžã±ãŒã¿ãŒã«å¯ŸããŠããã¡ã€ã«ã·ã¹ãã ã®ã¢ãŒãã£ãã¡ã¯ããå®è¡äžã®ããã»ã¹ããããã¯ãŒã¯æ¥ç¶ããã§ãã¯ããŸããã¯ãã¹ãã©ãããã©ãŒã ïŒmacOS/Linux/WindowsãPowerShellçµç±ïŒã```bash
./scripts/ioc-scan.sh
### `scripts/respond.sh`
察話çãªä¿®åŸ©ã **ãã¹ãŠã®ç Žå£çãªæäœã«ã¯ã`[y/N]` ã®ç¢ºèªãå¿
èŠã§ãïŒããã©ã«ãïŒNOïŒã**```bash
# CRITICAL: Full RAT cleanup (kill â remove â reinstall)
./scripts/respond.sh --critical
# HIGH: Pin compromised package to safe version
./scripts/respond.sh --high axios 1.14.0 # npm ./scripts/respond.sh --high event-stream 3.3.5 # npm ./scripts/respond.sh --high urllib3 2.7.0 # python (pip/poetry/uv auto-detected)
root@kitploit:~
`--critical`ã¢ãŒãã®æé ïŒ
1. ãããã¯ãŒã¯éé¢ïŒ`/etc/hosts` çµç±ã§C2ãã¡ã€ã³ããããã¯ïŒ
2. RATããã»ã¹ã匷å¶çµäº
3. æ°žç¶åã®é€å»ïŒLaunchAgents / crontab / ã¹ã±ãžã¥ãŒã«ã¿ã¹ã¯ïŒ
4. `node_modules` ãšããã¯ãã¡ã€ã«ãåé€ããnpmãã£ãã·ã¥ãã¯ãªã¢
- **4bïŒPythonïŒïŒ** pipãã£ãã·ã¥ãæ¶å»ïŒå®å
šãèªåïŒïŒvenvåæ§ç¯ã¯æåæé ãšããŠè¡šç€º
5. äŸåé¢ä¿ã®åã€ã³ã¹ããŒã«
6. 確èªã¹ãã£ã³ã®ããã³ããïŒ`project-scan.sh` ããã³/ãŸã㯠`project-scan-py.sh`ïŒ
åã¹ãããã¯ãã¢ã¯ã·ã§ã³ãå®éã«å¿
èŠãã©ããã確èªãïŒäŸïŒRATããã»ã¹ãå®è¡ãããŠããªãå Žåã¯ã匷å¶çµäºããã¹ãããïŒã確èªãæ±ããåã«å®è¡ãããå
å®¹ãæ£ç¢ºã«è¡šç€ºããŸãã
**HIGH**ã¢ãŒãã§ã¯ãnpmã¯èªåçã«ãªãŒããŒã©ã€ããé©çšããŸãïŒPythonã¯ã¬ã€ããããŸãïŒãããŒãžã£ãŒãæ€åºâpinã³ãã³ãã衚瀺âå®å
šãªã¹ãããã®ã¿é©çšïŒãPythonã®ä¿®åŸ©ã«é¢ããæ³šæã«ã€ããŠã¯ã[Quick Start](#quick-start)ãåç
§ããŠãã ããã
---
## CI/CDçµ±å
### GitHub Actions```yaml
name: Supply Chain Guard
on:
pull_request:
paths:
- 'package.json'
- 'package-lock.json'
- 'yarn.lock'
jobs:
scg-scan:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- name: Setup Node.js
uses: actions/setup-node@v4
with:
node-version: '20'
- name: Install dependencies (hardened)
run: npm ci --ignore-scripts
- name: Run SCG project scan
run: |
chmod +x ./scripts/project-scan.sh
./scripts/project-scan.sh
- name: Run IOC scan
run: |
chmod +x ./scripts/ioc-scan.sh
./scripts/ioc-scan.sh
### å
ç¢åã®æšå¥šäºé
```bash
# Always use in CI:
npm ci --ignore-scripts # Block postinstall execution
# npm ci already enforces lockfile integrity by design (errors on mismatch)
# Yarn equivalent:
yarn install --frozen-lockfile --ignore-scripts
root@kitploit:~
> **ã¢ã¯ã·ã§ã³ã¯ã¿ã°ã§ã¯ãªãSHAã§åºå®ããããšã** äžèšã®äŸã§ã¯å¯èªæ§ã®ããã« `actions/checkout@v4` ã䜿çšããŠããŸãããã¿ã°ã¯å€æŽãããå¯èœæ§ããããŸããæ¬çªç°å¢ã§ã¯ãã¢ã¯ã·ã§ã³ã®ãµãã©ã€ãã§ãŒã³æ»æãé²ãããã«ãå®å
šãªã³ãããSHAã§åºå®ããŠãã ããïŒ
> ```yaml
> - uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
> - uses: actions/setup-node@39370e3970a6d050c480ffad4ff0ed4d3fdee5af # v4.1.0
> ```
---
## 察å¿ãã¬ã€ããã¯
### CRITICALïŒRATæ€åºïŒã®å Žå
> **ãããã¯ã«ãªããªãã§ãã ããã** 以äžã®æé ãé çªã«å®è¡ããŠãã ãããåã¹ãããã§ã¯æç€ºçãªç¢ºèªãå¿
èŠã§ãã
1. **ãããã¯ãŒã¯åé¢** â `/etc/hosts` ã§C2ãã¡ã€ã³ããããã¯
2. **ããã»ã¹ã®åŒ·å¶çµäº** â RATããã»ã¹ãçµäº (`com.apple.act.mond`, `ld.py`, `wt.exe`)
3. **æ°žç¶åã®åé€** â LaunchAgentsãcrontabãã¹ã±ãžã¥ãŒã«ã¿ã¹ã¯ãåé€
4. **npmã®ã¯ãªãŒã³** â `node_modules` ãš `package-lock.json` ãåé€ããnpmãã£ãã·ã¥ãã¯ãªã¢
5. **åã€ã³ã¹ããŒã«** â æ°èŠ `npm install && npm ci`
6. **åã¹ãã£ã³** â ãã€ãã©ã€ã³å
šäœãåå®è¡ããCLEARãæåŸ
### HIGHïŒäŸµå®³ãããããŒãžã§ã³ãã€ã³ã¹ããŒã«ãããŠããïŒã®å Žå
1. **respond.shã䜿çšããŠå®å
šãªããŒãžã§ã³ãåºå®**ïŒ ```bash
./scripts/respond.sh --high axios 1.14.0
ããã¯ã`overrides` (npm) ãŸã㯠`resolutions` (yarn) ã package.json ã«è¿œå ããåã€ã³ã¹ããŒã«ãè¡ãã確èªãæ±ããŸãã
2. **æåã§** `package.json` å
ã§: ```json { "overrides": { "axios": "1.14.0" } }
root@kitploit:~
Yarn: `{ "resolutions": { "axios": "1.14.0" } }`
3. **åã€ã³ã¹ããŒã«** : `npm ci`
4. **確èª** : ã¹ãã£ã³ãåå®è¡
* * *
## IOC ãªãã¡ã¬ã³ã¹
### ãã¡ã€ã«ã·ã¹ãã äžã®çè·¡
### æ°žç¶åæ©æ§
### ãããã¯ãŒã¯ææš
çš®é¡| å€
---|---
C2 ãã¡ã€ã³| `sfrclak.com`
C2 IP| `142.11.206.73`
C2 ããŒã| `8000`
### åœè£
ææ³
ãã©ãããã©ãŒã | åœè£
察象
---|---
macOS| Apple ã·ã¹ãã ããã»ã¹ (`com.apple.act.mond`)
Windows| Windows Terminal (`ProgramData å
ã® wt.exe`)
* * *
## åºå圢åŒ```
SCG ââââââââââââââââââââââââââââââââââ [L1:audit] CLEAR|!!sev [L2:osv] CLEAR|!!vuln-ids [L3:static] CLEAR|!!pkg [IOC:fs] CLEAR|!!C:artifact [IOC:net] CLEAR|!!C:c2 [LF:integ] CLEAR|!!drift âââ Devil Gate(8) ââââââââââââââââââââ G1:direct_dep G2:transitive G3:rat_fs G4:postinstall G5:lockfile G6:provenance G7:network G8:cicd âââ Devil Chain(R.N) âââââââââââââââââ S1:dependency â S2:runtime â S3:integrity â S4:environment âââ Loop âââââââââââââââââââââââââââââ R.N â converge|continue [VERDICT] CLEAR|HIGH|CRITICAL âââââââââââââââââââââââââââââââââââââââ
root@kitploit:~
---
## åèæç®
| åºå
ž | 説æ |
|--------|-------------|
| [Zenn (JP)](https://zenn.dev/gunta/articles/0152eadf05d173) | æ¥æ¬èªã«ããåæå ±å |
| [Elastic Security Labs](https://elastic.co/security-labs/axios-one-rat-to-rule-them-all) | æè¡çåæïŒRATã®éã¢ã»ã³ãã«ãC2ãããã³ã«ãã¿ã€ã ã©ã€ã³ïŒ |
| [SANS](https://sans.org/blog/axios-npm-supply-chain-compromise-malicious-packages-remote-access-trojan) | ãšã³ã¿ãŒãã©ã€ãºIRæé |
| [Huntress](https://huntress.com/blog/supply-chain-compromise-axios-npm-package) | YARA眲å |
| [Elastic Detections](https://elastic.co/security-labs/axios-supply-chain-compromise-detections) | SIEMæ€åºã«ãŒã«ïŒYARA/osquery/KQLïŒ |
| [Semgrep](https://semgrep.dev/blog/2026/axios-supply-chain-incident-indicators-of-compromise-and-how-to-contain-the-threat/) | éçè§£æã«ãŒã«ãå°ã蟌ãã¬ã€ã |
| [SOCRadar](https://socradar.io/blog/axios-npm-supply-chain-attack-2026-ciso-guide/) | IOCã¿ã€ã ã©ã€ã³ä»ãCISOã¬ã€ã |
| [Wiz](https://wiz.io/blog/axios-npm-compromised-in-supply-chain-attack) | ã¯ã©ãŠã圱é¿åæãã³ã³ããã¹ãã£ã³ |
| [NVD CVE-2026-48710](https://nvd.nist.gov/vuln/detail/CVE-2026-48710) | **äžæ¬¡æ
å ±** â NVDæ£èŠãšã³ããªïŒå
¬éæ¥2026-05-26ãCVSS 3.1åºæ¬å€6.5 MEDIUMãAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:NïŒ |
| [GHSA-86qp-5c8j-p5mr](https://github.com/Kludex/starlette/security/advisories/GHSA-86qp-5c8j-p5mr) | **äžæ¬¡æ
å ±** â `Kludex/starlette`ã«é¢ããGitHub Security AdvisoryïŒå
¬éæ¥2026-05-21ïŒïŒãHostããããŒã®æ€èšŒæ¬ åŠã«ããrequest.url.pathãæ±æããããã¹ããŒã¹ã®ã»ãã¥ãªãã£ãã§ãã¯ããã€ãã¹ããã |
| [Starlette v1.0.1 release notes](https://github.com/Kludex/starlette/releases/tag/1.0.1) | **äžæ¬¡æ
å ±** â ä¿®æ£ãªãªãŒã¹ïŒå
¬éæ¥2026-05-21ïŒã`starlette>=1.0.1`ïŒããã³æšç§»ç解決ã®ããã«`fastapi>=0.119`ïŒããã³çã |
| [Starlette BadHost coverage (KuCoin)](https://kucoin.com/news/flash/starlette-vulnerability-exposes-millions-of-ai-agents-to-hackers) | äºæ¬¡æ
å ± â Pythonãšã³ã·ã¹ãã ãžã®åœ±é¿ãAIãšãŒãžã§ã³ãé¢é£ã®æ çµã¿ |
| [BadHost AI agent analysis (CryptoBriefing)](https://cryptobriefing.com/starlette-badhost-vulnerability-ai-agents/) | äºæ¬¡æ
å ± â FastAPI / vLLM / LiteLLMã®äžæµãžã®åœ±é¿æ çµã¿ |
---
## Guild-CLI Devil çµ±å
[guild-cli](https://github.com/eris-ths/guild-cli)ïŒãŸãã¯Devilã¬ã³ãºã¯ãŒã¯ãããŒãå
¬éãããããžã§ã¯ãïŒã䜿çšããŠããå Žåãã¬ãã¥ãŒãã¹ã®éã«SCGãã»ãã¥ãªãã£ã¬ã³ãºã®äžã€ãšããŠåŒã³åºãããšãã§ããŸãã
### æšå¥šãããåŒã³åºããã¿ãŒã³```bash
# Inside a guild-cli review session, in the project root:
~/path/to/supply-chain-guard/scripts/project-scan.sh # for npm/yarn projects
~/path/to/supply-chain-guard/scripts/project-scan-py.sh # for Python projects
# Capture the scan output as evidence for a judgment:
SCG_OUTPUT=$(~/path/to/supply-chain-guard/scripts/project-scan.sh 2>&1 || true)
# (a) Record it as a new judgment (fast-track â no prior review needed):
gate fast-track --from "$USER" \
--action "SCG supply-chain scan (Devil lense)" \
--reason "$SCG_OUTPUT"
# (b) Or attach it as the Devil lense on an existing review request <id>:
gate review <id> --lense devil --verdict concern --note "$SCG_OUTPUT"
> Flag notes (verified against guild-cli): `gate review` **requires** an existing `<id>`, `--lense` (guild-cli spells it "lense"), and `--verdict` (`ok` / `concern` / `reject`). It has no `--area` flag. To log a fresh finding with no prior review object, use `gate fast-track` as in (a).
### Why pair SCG with Devil
Devil's Advocate ("å£ãã«ãã") and SCG share the same posture: **assume the worst, scan systematically, then converge**. SCG provides the supply-chain dimension of a Devil pass â what the project's dependencies might be doing behind your back â alongside other lenses (security / correctness / architecture / user / operations).
### Limitations of the Devil pairing
* SCG runs read-only; the Devil lense won't push fixes. Use `respond.sh` separately when remediation is required (with explicit user confirmation)
* SCG output may exceed Devil context budgets in large repos; pipe through `tail -50` if needed
* For polyglot repos, run both `project-scan.sh` and `project-scan-py.sh` and merge findings
* * *
## Disclaimer
SCG is a detection tool, not a security guarantee. Being upfront about what it can and cannot do is part of the design.
**This software is provided "as-is" without warranty of any kind.** By using Supply Chain Guard, you acknowledge and agree to the following:
* **Not a substitute for professional security.** SCG is a supplementary detection tool, not a comprehensive security solution. It does not replace professional incident response, endpoint detection and response (EDR) software, or security audits.
* **No guarantee of detection.** A `CLEAR` verdict means no matches were found against the tool's known threat patterns. **It does not mean your system or project is free from compromise.** Novel, unknown, or modified attacks may not be detected.
* **No guarantee of remediation.** The remediation steps provided (`respond.sh`) address known indicators of specific threats. They may not fully remove all traces of a sophisticated compromise. If you suspect active compromise, engage a professional incident response team.
* **Use at your own risk.** The authors are not liable for any damages, data loss, or security incidents arising from the use or inability to use this tool. This includes but is not limited to: false negatives (missed detections), false positives (incorrect detections), or unintended consequences of running remediation scripts.
* **Not legal or compliance advice.** This tool does not satisfy regulatory, compliance, or legal requirements for security scanning. Consult appropriate professionals for compliance needs.
* * *
## Limitations
Understanding what SCG **cannot** do is as important as knowing what it can.
### Detection Boundaries
### Threat Database Freshness
The Known Threats database (`D.2` in SKILL.md) is **manually maintained**. It is not connected to any live threat feed. There is inherent latency between a new supply chain incident being discovered and this database being updated.
* **Last updated:** 2026-05-27 (v4: Python support, BadHost CVE-2026-48710 added)
* **Coverage:** 3 npm threat families (T001-T003) + 4 Python hijacked/typosquat entries + 1 Python CVE-flagged version entry (BadHost)
* **Python coverage scope (v4):** primarily lockfile-based scanning (uv.lock / poetry.lock / requirements.txt). The CVE-flagged version layer is **best-effort** â it only flags packages that match `_L3_CVE_LIST` entries with strict semver-spec evaluation, and depends on `packaging` being installed for accurate version matching
Always cross-reference with live sources such as npm advisories, OSV.dev, and vendor security blogs listed in the References section.
### False Positive Risk
The following IOC paths may, in rare cases, conflict with legitimate software:
IOC Path| Potential False Positive
---|---
`/tmp/.npm-cache/`| Legitimate npm caching in non-standard configurations
`/tmp/ld.py`| Unrelated Python scripts with the same filename
Process name `wt.exe`| Legitimate Windows Terminal if located in ProgramData
**Always verify IOC findings before running remediation.** The `ioc-scan.sh` script reports findings for human review â it does not take any action. The `respond.sh` script requires explicit confirmation for every destructive action (default: NO) precisely because of this risk.
### Network Scanning Limitations
* `lsof`-based network checks only detect **currently active** connections. A C2 beacon that connects intermittently may not be active at scan time.
* DNS cache checks are best-effort and OS-dependent. Cleared caches will not show historical connections.
* Encrypted or tunneled C2 traffic cannot be detected by port/IP matching alone.
### Scope
* **npm/yarn and Python (pip/poetry/uv).** Does not cover cargo, go modules, or other package ecosystems.
* **Known threats only.** This is a pattern-matching tool, not a behavioral analysis engine.
* **Point-in-time scan.** Results reflect the state at the moment of execution. Continuous monitoring requires repeated execution or integration with CI/CD.
* * *
## Integrity Verification
Verify that your copy of SCG has not been tampered with. Compare these SHA-256 checksums against your local files:
```
67ac6216cbe18fdf7050fd267bce4157c016e5c60cd4f84f63b8cf71e80ae3b9 scripts/env-scan.sh da01f8362563b55b1553f923a748f07d24f24522366e0545e6ba0c09801f8e54 scripts/project-scan.sh 77e7ebba6d44ea020e511a49bc2cbc974d01495de40d35e8dfb7fcc93008954b scripts/project-scan-py.sh 82aaa4ed898ce354addc064ccf84cca9a498ef4e90fe58613e1110146577609f scripts/ioc-scan.sh 72ed333838b5584c3b1faf889edc81b0e3195c27396c3b36c62aaebf5f952117 scripts/ioc-scan.ps1 0e6b30e57c959180e22e0ba16f860e9fdc7304045947995084703fb14381d12e scripts/respond.sh a44be79d909058c9d216e7cbc5cca736cf8816a492c8d35a6b90c74c042abf5b SKILL.md
root@kitploit:~
<!-- CHECKSUMS-END -->
確èªããã«ã¯:```bash
shasum -a 256 scripts/*.sh scripts/*.ps1 SKILL.md
> **泚èš:** ãããã®ãã§ãã¯ãµã ã¯ææ°ãªãªãŒã¹ã«å¯Ÿå¿ããŠããŸãããã¡ã€ã«ãããŒã«ã«ã§å€æŽããå Žåããã§ãã¯ãµã ã¯ç°ãªããŸããSCG ãæŽæ°ããããšããã®ã»ã¯ã·ã§ã³ã¯ã³ãŒãã®å€æŽãšãšãã«æŽæ°ãããŸãã
* * *
## ã©ã€ã»ã³ã¹
MIT
* * *
**Built byEris** â ããªãã®äŸåé¢ä¿ãä»äººã®æ»æé¢ã«ãªãã¹ãã§ã¯ãªãããã§ãã