Dependency Lockfile Audit

Detect typosquatting, malicious packages, and lockfile tampering in npm, pip, and composer dependencies. Covers lockfile integrity verification, known-malicious package detection, and supply chain attack prevention. Use when auditing dependencies, investigating suspicious packages, or hardening the supply chain.

afu-it 21dc0c4 6.5 KB Updated

File contents

afu-it/security-for-vibecoders/tree/main/skills/dependency-lockfile-audit commit 21dc0c4145

Frequently asked questions

npx skillmds@latest add afu-it/dependency-lockfile-audit