Technology Supply Chain Security Auditor
Paste the following prompt into your AI chat to install this skill:
Please follow https://skillhub.cn/install/skillhub.md to install @user_d277dc19/technology-supply-chain-security-auditor.
About this skill
Problem
When assessing a tech company's supply-chain security, the key question is not whether it uses imported parts, but whether critical nodes create fatal dependencies: EDA/IP, advanced process, packaging, equipment/materials, and software ecosystems. This skill turns scattered news, filings, teardown reports, and broker research into comparable risk judgments.
How It Works
The workflow is:
- Dependency mapping: identify technology layers, supplier concentration, and substitutability across design tools, components, manufacturing/packaging, and ecosystems.
- Quantified scoring: assign 1-5 risk scores to each node, and evaluate domestic alternatives by TRL, performance gap, ecosystem compatibility, capacity, and switching cycle.
- Scenario simulation: under basic or comprehensive depth, model partial and full supply cutoffs, estimate buffer time, performance degradation, recovery time, and survival probability.
- Breakout paths: identify rerouting, technology-route switches, ecosystem building, and policy-supported actions across near-, mid-, and long-term horizons.
Boundaries
The skill relies on public, verifiable information and is suited to technical security audits, sanctions screening, and supply-chain resilience reviews. Inferred scenarios should be separated from facts; if supplier relationships, domestic production capacity, or customer ecosystems lack public data, confidence in the conclusion decreases and primary verification is needed.
Use Cases
- Evaluate an AI chip firm's Entity List exposure by mapping design, manufacturing, and packaging dependencies.
- Audit a high-end CNC firm's domestic substitution maturity and identify its weakest technology nodes.
- Assess a drone flight-control firm's direct-product-rule risk and simulate supply-cutoff impact after new rules.
- Run technology-security due diligence on an M&A target and compare its autonomy against peers.
Best For
- Equity analysts tracking tech sanctions need to judge a firm's core technology dependencies and autonomy.
- Corporate risk managers need to check critical component cutoff exposure when export controls change.
- M&A strategic advisors need to compare a target's domestic substitution maturity with industry peers.
- Technology consultants need to estimate survival probability and breakout paths under supply-cutoff scenarios.
Related Skills
Switch AI from a polite executor into a skeptical thinking partner, using assumption checks, pre-mortems, and evidence gates to expose weak ideas early.
Applies research discipline, data lookup, evidence grading, red-team checks, and structured reporting to analyze AI company investment logic.
Uses Qichacha or Tianyancha MCP data and public information to score corporate credit across 12 dimensions and output a Markdown risk report.
Calculates personal injury compensation via CLI and outputs case summary, standards, line items, sources, and risk notes.