supply-chain-risk-auditor
supply chain risk auditor
What it does
- Assessing dependency risk before a security audit
- Evaluating supply chain attack surface of a project
- Identifying unmaintained or risky dependencies
- Pre-engagement scoping for supply chain concerns
- Active vulnerability scanning (use dedicated tools like npm audit, pip-audit)
- Runtime dependency analysis
- License compliance auditing
Requirements & configuration
Configuration: CONTRIBUTINGREADME
Derived from the skill's own SKILL.md documentation · extracted 2026-07-23
supply-chain-risk-auditor FAQ
What does the supply-chain-risk-auditor skill do?
Identifies dependencies at heightened risk of exploitation or takeover. Use when assessing supply chain attack surface, evaluating dependency health, or scoping security engagements. Assessing dependency risk before a security audit Evaluating supply chain attack surface of a project
What does supply-chain-risk-auditor require?
Configuration keys: CONTRIBUTING, README.
How do I install supply-chain-risk-auditor?
Run: npx -y skills add https://github.com/trailofbits/skills --skill supply-chain-risk-auditor --agent claude-code — the source lives at github.com/trailofbits/skills.
Maintain supply-chain-risk-auditor?
Let people know it's listed here — add the badge (live metrics, light/dark aware) or a plain link to your README or docs.
[](https://getagentictools.com/skills/trailofbits-skills-supply-chain-risk-auditor?ref=badge) npx agentictools info skills/trailofbits-skills-supply-chain-risk-auditor The second line is the CLI lookup for this page — handy in READMEs and docs.