Secure Supply Chain Plan from PRD
Independent PiSkill directory guide. The original prompt remains hosted by Microsoft HVE Core.
What does this prompt do?
Derives software-supply-chain controls from product requirements, covering dependencies, provenance, builds, artifacts, releases, ownership, and verification.
Primary use case
Plan supply-chain security for a software product.
Expected output
A supply-chain security plan with controls and validation tasks.
Inputs or variables
- product requirements
- build pipeline
- release model
Related prompts
Vulnerability Exploitability Scan
Scans dependency and vulnerability evidence to determine which findings need exploitability analysis rather than treating every advisory as equally actionable.
Incident Response Plan
Structures an incident response workflow around evidence collection, containment, recovery and follow-up actions.
LLM Security Review
Reviews an LLM or agent solution for prompt injection, unsafe tool access, data exposure, trust-boundary failures, weak validation, and operational controls.
Responsible AI Evidence Capture
Captures responsible-AI requirements, stakeholders, harms, controls, evidence, ownership, and unresolved questions in a consistent planning artifact.
Responsible AI Plan from PRD
Turns a product requirements document into a responsible-AI plan covering likely harms, mitigations, validation, monitoring, governance, and accountable owners.
Responsible AI Plan from Security Plan
Extends an existing security plan with model-specific harms, misuse, data, evaluation, transparency, monitoring, and governance requirements.