Orca Supply Chain Exposure

Supply chain exposure check — given a list of suspect packages (e.g. an MDR advisory like the @antv/* npm campaign), find which versions are deployed across the environment, which match the vulnerable range, and which assets carry them. Use when user asks about supply chain risk, package exposure, IOC package check, malicious package, or "are we running X" (e.g., "are we exposed to the @antv attack", "any assets with left-pad", "check these npm packages", "supply chain check").

orcasecurity Updated

File contents

orcasecurity/orca-skills/tree/main/skills/orca-supply-chain-exposure commit 56b4454403

Frequently asked questions

npx skillmds@latest add orcasecurity/orca-supply-chain-exposure