supply-chain-risk-auditor
Maintained by trailofbits
Audits a project's dependencies for supply-chain risk: version-matched advisories for direct dependencies and the full lockfile tree, abandoned or archived upstreams, npm publisher concentration, and install-time script execution. Use when asked to audit dependencies, assess supply-chain or third-party package risk, or
- Current version
- Unknown
- License
- Unknown
- Network access
- Unknown / not assessed
- Review status
- Not verified
Problem it solves
This catalog entry helps users find and evaluate supply-chain-risk-auditor for the task described by its available catalog summary. Confirm the exact scope in the linked original source when one is available.
When to use it
Consider supply-chain-risk-auditor when its available catalog summary matches the task at hand. When available, review the linked original source before use for precise instructions, requirements, and limitations.
Installation and updates
These commands are displayed for copying only and are never executed on RefHub servers. Review the linked upstream source before running them.
npx skills add trailofbits/skills --skill supply-chain-risk-auditor -y
Agent compatibility
No compatibility test has been recorded
Do not assume agent compatibility until documented test evidence is available.