supply-chain-risk-auditorby Trail of BitsDevelopmentGitHub stars: 7.3k
Supply Chain Risk Auditor skill: what it does and how to install it
Audits a project's dependencies for supply-chain risk: advisories, abandoned upstreams and install-time scripts.
Install
$ npx skills add trailofbits/skills --skill supply-chain-risk-auditorRun it in a terminal. If your agent is already running, start a new session so it picks the skill up.
About this skill
Audits a project's dependencies for supply-chain risk: advisories, abandoned upstreams and install-time scripts.
Similar skills
- Agentic Actions AuditorAudits GitHub Actions workflows for vulnerabilities in AI agent integrations such as Claude Code Action and Codex.
- Domain ModelingBuilds and sharpens a project's domain model through a glossary and ADRs.
- To SpecTurns the current conversation into a spec and publishes it to the project's issue tracker, without a further interview.