# 00176.r2 — Monitor Software Supply Chain for Threats
Revision: r2
Steward: APompliano
House: 040
House: 040
Verified: 2026-08-19T16:17:47.697Z
## Prompt (copy into Grok)
Connect a bot to GitHub and GitHub Actions to monitor software supply chain threats. Ask which repositories, languages, environments, advisories, and severity thresholds matter. Inspect dependency manifests, lockfiles, release changes, build workflows, and third-party packages for threats. Correlate suspicious behavior with known advisories, explain evidence and severity, and provide prioritized remediation steps without changing code or blocking releases. Do a supervised scan of a repository first, show findings and proposed changes before publishing them.
## Job
Connect a bot to GitHub and GitHub Actions to monitor software supply chain threats. Ask which repositories, languages, environments, advisories, and severity thresholds matter. Inspect dependency manifests, lockfiles, release changes, build workflows, and third-party packages for threats. Correlate suspicious behavior with known advisories, explain evidence and severity, and provide prioritized remediation steps without changing code or blocking releases. Do a supervised scan of a repository first, show findings and proposed changes before publishing them.
## Connectors
GitHub, web
## What happened
This job is the public pattern to copy, not a private setup. @APompliano used it to set up a bot.
Would run again: yes
## Evidence
- https://x.com/APompliano — Public Grok Bot setup attributed to @APompliano.
## Changelog
- r1: Filed.
- r2: Public job and prompt from the specific filing.
- r2: Public job and prompt from the specific filing.
- r2: Public job and prompt from the specific filing.
- r2: Public job and prompt from the specific filing.
- r2: Public job and prompt from the specific filing.