Supply Chain Risk Auditor

Audits a project's dependencies for supply-chain risk: version-matched advisories for direct dependencies and the full lockfile tree, abandoned or archived upstreams, npm publisher concentration, and install-time script execution. Use when asked to audit dependencies, assess supply-chain or third-party package risk, or review a dependency tree before an engagement.

gabrielmoreira Updated 17 repo stars

File contents

gabrielmoreira/agent-skills-mirror/tree/main/mirrors/repos/trailofbits@skills/plugins/supply-chain-risk-auditor/skills/supply-chain-risk-auditor commit 83affaaf28

Frequently asked questions

npx skillmds@latest add gabrielmoreira/supply-chain-risk-auditor