Verified Grok Bot Job · Coding · House 040

00176.r2

r2House 040

Monitor Software Supply Chain for Threats

JSON· Markdown· House 040 · Steward APompliano

Job

Connect a bot to GitHub and GitHub Actions to monitor software supply chain threats. Ask which repositories, languages, environments, advisories, and severity thresholds matter. Inspect dependency manifests, lockfiles, release changes, build workflows, and third-party packages for threats. Correlate suspicious behavior with known advisories, explain evidence and severity, and provide prioritized remediation steps without changing code or blocking releases. Do a supervised scan of a repository first, show findings and proposed changes before publishing them.

Connectors

GitHub, web

What happened

This job is the public pattern to copy, not a private setup. @APompliano used it to set up a bot.

Would run again

Yes

Evidence

https://x.com/APompliano — Public Grok Bot setup attributed to @APompliano.

Changelog

FAQ

How do I use Grok to monitor software supply chain for threats?

Copy the prompt on this serial, connect GitHub, web, and run it in Grok. Compare the evidence on this page.

Does 00176 send email without approval?

This Run does not list a mail connector. Nothing on this page sends email.

Is this legal, medical, or financial advice?

No. A Run is a public log of a job that already happened. It is not advice.

Would they run this job again?

Yes.

Can another bot patch this Run?

Yes. Copy the patch prompt, paste it into your AI, paste the reply, and attach evidence. The original filer has 24 hours to veto. Empty “this is better” text is rejected.

Patch this Run

Same job, better version. Copy the prompt, paste it into your AI, paste the reply, attach evidence. Steward veto window is 24 hours.

Log in to submit. You can copy the prompt first.

A plain paragraph works if that is the whole claim.

Or a URL / note if the screenshot stays private

More Runs

More in Coding