# NPM Package Supply Chain Auditor

> Audits npm dependencies for supply chain risks using npm audit, Socket.dev API, and Snyk vulnerability database. Detects typosquatting, install scripts, and maintainer account takeovers.

- Skill: `agentskillexchange/npm-package-supply-chain-auditor` (Agent Skill)
- Install (CLI): `npx skillmds@latest add agentskillexchange/npm-package-supply-chain-auditor`
- Raw SKILL.md: https://api.skillmd.com/api/skills/agentskillexchange/npm-package-supply-chain-auditor/raw
- Safety review: pending (external: skill-scanner PASS, skillspector PASS)
- Works with: Claude Code, Claude.ai, OpenAI Codex
- Category: Security
- Author: agentskillexchange (https://skillmd.com/u/agentskillexchange)
- Updated: 2026-09-08
- Page: https://skillmd.com/skills/agentskillexchange/npm-package-supply-chain-auditor

---


# NPM Package Supply Chain Auditor

Audits npm dependencies for supply chain risks using npm audit, Socket.dev API, and Snyk vulnerability database. Detects typosquatting, install scripts, and maintainer account takeovers.

## Installation

Requirements and caveats from upstream:
- To use the CLI, you must install it and authenticate your machine. See [Install or update the Snyk CLI](https://docs.snyk.io/snyk-cli/install-or-update-the-snyk-cli) and [Authenticate the CLI with your account](https:...
- Before you can use the CLI for Open Source scanning, you must install your package manager. The needed third-party tools, such as Gradle or Maven, must be in the PATH.
- Before using the Snyk CLI to test your Open Source Project for vulnerabilities, with limited exceptions, you must build your Project. For details, see [Open Source Projects that must be built before testing](https://d...

Basic usage or getting-started notes:
- ## Introduction to the Snyk CLI
- Snyk is a developer-first, cloud-native security tool to scan and monitor your software development projects for security vulnerabilities. Snyk scans multiple content types for security issues:
- [Snyk Open Source](https://docs.snyk.io/scan-with-snyk/snyk-open-source): Find and automatically fix open-source vulnerabilities

- Source: https://github.com/snyk/cli
- Extracted from upstream docs: https://raw.githubusercontent.com/snyk/cli/HEAD/README.md

## Source

- [Agent Skill Exchange](https://agentskillexchange.com/skills/npm-package-supply-chain-auditor/)

