Supply Chain Audit

Forensic scan for npm/PyPI supply-chain compromise (Shai-Hulud/TeamPCP campaigns) — checks persistence, hook injection, compromised packages, IOC strings, C2, dead-man switches. Use when auditing a machine or repo for malicious dependencies. Trigger on "supply chain audit", "check for compromised packages", "Shai-Hulud", "scan for malicious deps".

matteocervelli Updated

File contents

matteocervelli/llms commit 4cbbbf9e85

Frequently asked questions

npx skillmds@latest add matteocervelli/supply-chain-audit