supply-chain-risk-auditorby Trail of BitsDevelopmentGitHub stars: 7.3k
Supply Chain Risk Auditor skill: what it does and how to install it
Audits a project's dependencies for supply-chain risk: advisories, abandoned upstreams and install-time scripts.
Install
$ npx skills add trailofbits/skills --skill supply-chain-risk-auditorRun it in a terminal. If your agent is already running, start a new session so it picks the skill up.
About this skill
Audits a project's dependencies for supply-chain risk: advisories, abandoned upstreams and install-time scripts.
History
Repo stars
7.3kAbout +166 since 9 Jul 2026
Before 1 Oct 2026 the curve is estimated from public event data.
Stars are counted for the whole repository, which holds 23 skills.
Show as a table
| Date | Repo stars |
|---|---|
| 1 Oct 2026 | 7,320 |
| 24 Sept 2026 (estimated) | 7,310 |
| 17 Sept 2026 (estimated) | 7,305 |
| 10 Sept 2026 (estimated) | 7,239 |
| 3 Sept 2026 (estimated) | 7,179 |
| 27 Aug 2026 (estimated) | 7,174 |
| 20 Aug 2026 (estimated) | 7,174 |
| 13 Aug 2026 (estimated) | 7,169 |
| 6 Aug 2026 (estimated) | 7,164 |
| 30 Jul 2026 (estimated) | 7,164 |
| 23 Jul 2026 (estimated) | 7,164 |
| 16 Jul 2026 (estimated) | 7,164 |
| 9 Jul 2026 (estimated) | 7,154 |
Installs
7.2k
Tracking since . A chart appears once there are 7 days of data.
Installs via skills.sh
Similar skills
- Agentic Actions AuditorAudits GitHub Actions workflows for vulnerabilities in AI agent integrations such as Claude Code Action and Codex.
- Domain ModelingBuilds and sharpens a project's domain model through a glossary and ADRs.
- To SpecTurns the current conversation into a spec and publishes it to the project's issue tracker, without a further interview.