Loading

supply-chain-risk-auditor

Maintained by trailofbits

Audits a project's dependencies for supply-chain risk: version-matched advisories for direct dependencies and the full lockfile tree, abandoned or archived upstreams, npm publisher concentration, and install-time script execution. Use when asked to audit dependencies, assess supply-chain or third-party package risk, or

Current version
Unknown
License
Unknown
Network access
Unknown / not assessed
Review status
Not verified

Problem it solves

This catalog entry helps users find and evaluate supply-chain-risk-auditor for the task described by its available catalog summary. Confirm the exact scope in the linked original source when one is available.

When to use it

Consider supply-chain-risk-auditor when its available catalog summary matches the task at hand. When available, review the linked original source before use for precise instructions, requirements, and limitations.

supply-chain-risk-auditor is listed as an agent skill in RefHub. The listed maintainer is trailofbits. The available catalog summary is: Audits a project's dependencies for supply-chain risk: version-matched advisories for direct dependencies and the full lockfile tree, abandoned or archived upstreams, npm publisher concentration, and install-time script execution. Use when asked to audit dependencies, assess supply-chain or third-party package risk, or When available, review the linked original source for exact usage instructions, required tools, and limitations.

Installation and updates

These commands are displayed for copying only and are never executed on RefHub servers. Review the linked upstream source before running them.

Install command
npx skills add trailofbits/skills --skill supply-chain-risk-auditor -y

Agent compatibility

No compatibility test has been recorded

Do not assume agent compatibility until documented test evidence is available.

Source information and review status

The overview above is structured catalog copy and has no recorded editorial review; technical facts and verification status are shown separately.

Source last reviewed
Not recorded
Catalog source
Open catalog source