Supply Chain Audit

Pre-install and post-install security audit for npm packages, GitHub repos, VS Code extensions, and OpenClaw skills. Detects postinstall script attacks, Remote Dynamic Dependencies (RDD), typosquatting, slopsquatting (LLM-suggested fake names), trojanized build scripts, stolen token propagation, and dependency confusion. Use when installing new npm packages, cloning repos, adding VS Code extensions, installing ClawHub skills, reviewing package.json changes in PRs, or auditing existing node_modules. Covers the PhantomRaven, CanisterWorm, GlassWorm, and malicious Next.js repo campaigns of 2025-2026.

nickgallick 47ec805 3 files · 19.9 KB Updated 0 repo stars

File contents

nickgallick/perlantir-fleet/tree/main/workspace-forge/skills/supply-chain-audit commit 47ec8054d1

Frequently asked questions

npx skillmds add nickgallick/supply-chain-audit