supply-chain-risk-auditor

trailofbits/supply-chain-risk-auditor · Agent Skill (multi-file)

by Trail of Bits · bundle

Published · Last updated


Audits project dependencies for supply chain risks including single maintainers, unmaintained packages, low popularity, high-risk features, past CVEs, and missing security contacts.

SKILL.md

Files

This skill is a package of 3 files. Install with the command above, or download the folder.

  • 📄SKILL.md entry
  • 📁agents
  • openai.yaml 127 B
  • 📁resources
  • 📄results-template.md 1.1 KB

Related

  1. agent-supply-chain · github
    Verify supply chain integrity for AI agent plugins, tools, and dependencies by generating SHA-256 manifests, detecting tampered files, auditing dependency pinning, and enforcing promotion gates.
    36.2k
    repo stars
  2. security-review · github bundle
    Scans codebases for security vulnerabilities by reasoning about code context, data flow, and component interactions, covering injection flaws, secrets exposure, authentication issues, and weak cryptography across multiple languages.
    36.2k
    repo stars
  3. dependency-auditor · alirezarezvani bundle
    Audit and manage dependencies across multi-language projects by scanning for vulnerabilities, license conflicts, and transitive dependency risks, with safe-upgrade planning.
    20.4k
    repo stars
  4. skill-scanner · getsentry bundle
    Scans agent skills for security issues including prompt injection, malicious scripts, excessive permissions, secret exposure, and supply chain risks.
    845
    repo stars
  5. pr-review-expert · alirezarezvani
    Review GitHub PRs and GitLab MRs with structured analysis including blast radius, security scanning, test coverage delta, breaking change detection, and performance impact.
    20.4k
    repo stars
  6. bumblebee · antigravity bundle
    Run Bumblebee supply-chain inventory and exposure scans on macOS/Linux to detect compromised packages, extensions, and MCP host configs.
    42.4k
    repo stars

Frequently asked questions

How do I install the supply-chain-risk-auditor skill?

Run npx skillmds add trailofbits/supply-chain-risk-auditor in your terminal (requires Node.js), paste this page's agent-chat prompt into Claude, Cursor, or any MCP-connected agent, or download the SKILL.md file and copy it into your agent's skills directory.

What does the supply-chain-risk-auditor skill do?

Audits project dependencies for supply chain risks including single maintainers, unmaintained packages, low popularity, high-risk features, past CVEs, and missing security contacts. It is listed under Security, Vulnerability Scanning on SkillMD.

Is supply-chain-risk-auditor safe to use?

SkillMD's automated safety review verdict for this skill is CAUTION. Independent scanners report: SkillSpector: PASS, Skill Scanner: PASS. Capability flags: docs only. SkillMD never runs a skill's scripts for you; review the SKILL.md before installing.

Which AI agents work with supply-chain-risk-auditor?

This skill is tagged as working with Claude Code, Claude.ai, OpenAI Codex. SKILL.md is an open format, so most agents that read a skills directory can load it too.

Is supply-chain-risk-auditor free to use?

Yes. Installing skills from SkillMD is free, and the skill stays under its author's original license.

Who published supply-chain-risk-auditor?

Trail of Bits (@trailofbits) published this skill as a verified publisher. Their other Agent Skills are listed on their SkillMD profile.