supply-chain-risk-auditor

supply chain risk auditor

trailofbits 6.2k ↓ 5.2k CC-BY-SA-4.0 updated 28d ago
Claude Code
View source ↗

What it does

  • Assessing dependency risk before a security audit
  • Evaluating supply chain attack surface of a project
  • Identifying unmaintained or risky dependencies
  • Pre-engagement scoping for supply chain concerns
  • Active vulnerability scanning (use dedicated tools like npm audit, pip-audit)
  • Runtime dependency analysis
  • License compliance auditing

Requirements & configuration

Configuration: CONTRIBUTINGREADME

Derived from the skill's own SKILL.md documentation · extracted 2026-07-23

supply chain risk auditor

Source

Repository: https://github.com/trailofbits/skills

supply-chain-risk-auditor FAQ

What does the supply-chain-risk-auditor skill do?

Identifies dependencies at heightened risk of exploitation or takeover. Use when assessing supply chain attack surface, evaluating dependency health, or scoping security engagements. Assessing dependency risk before a security audit Evaluating supply chain attack surface of a project

What does supply-chain-risk-auditor require?

Configuration keys: CONTRIBUTING, README.

How do I install supply-chain-risk-auditor?

Run: npx -y skills add https://github.com/trailofbits/skills --skill supply-chain-risk-auditor --agent claude-code — the source lives at github.com/trailofbits/skills.

Maintain supply-chain-risk-auditor?

Let people know it's listed here — add the badge (live metrics, light/dark aware) or a plain link to your README or docs.

supply-chain-risk-auditor on getagentictools
[![supply-chain-risk-auditor on getagentictools](https://getagentictools.com/badge/skills/trailofbits-skills-supply-chain-risk-auditor.svg)](https://getagentictools.com/skills/trailofbits-skills-supply-chain-risk-auditor?ref=badge)
npx agentictools info skills/trailofbits-skills-supply-chain-risk-auditor

The second line is the CLI lookup for this page — handy in READMEs and docs.