npm Supply Chain Security
bodadotsh/npm-security-best-practices
Applies safer package manager defaults and dependency vetting to JavaScript and TypeScript projects to reduce supply-chain attack risk.
Audits outdated npm and Bun packages for supply chain integrity before bumping them, deferring risky ones and logging every decision.
$ npx skills add backnotprop/plannotator --skill update-deps -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install backnotprop/plannotator update-deps --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/backnotprop/plannotator.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/update-deps .claude/skills/update-deps && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "update-deps" agent skill from https://github.com/backnotprop/plannotator/tree/main/.agents/skills/update-deps into .claude/skills/update-deps/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "update-deps", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/backnotprop/plannotator/tree/main/.agents/skills/update-depsType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add backnotprop/plannotator --skill update-deps -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install backnotprop/plannotator update-deps --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/backnotprop/plannotator.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.agents/skills/update-deps .agents/skills/update-deps && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "update-deps" agent skill from https://github.com/backnotprop/plannotator/tree/main/.agents/skills/update-deps into .agents/skills/update-deps/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "update-deps", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add backnotprop/plannotator --skill update-deps -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install backnotprop/plannotator update-deps --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/backnotprop/plannotator.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.agents/skills/update-deps .cursor/skills/update-deps && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "update-deps" agent skill from https://github.com/backnotprop/plannotator/tree/main/.agents/skills/update-deps into .cursor/skills/update-deps/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "update-deps", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/backnotprop/plannotator.git --path .agents/skills/update-deps--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add backnotprop/plannotator --skill update-deps -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install backnotprop/plannotator update-deps --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/backnotprop/plannotator.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.agents/skills/update-deps .gemini/skills/update-deps && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "update-deps" agent skill from https://github.com/backnotprop/plannotator/tree/main/.agents/skills/update-deps into .gemini/skills/update-deps/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "update-deps", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install backnotprop/plannotator update-depsInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add backnotprop/plannotator --skill update-deps -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/backnotprop/plannotator.git skills-src && mkdir -p .github/skills && cp -r skills-src/.agents/skills/update-deps .github/skills/update-deps && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "update-deps" agent skill from https://github.com/backnotprop/plannotator/tree/main/.agents/skills/update-deps into .github/skills/update-deps/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "update-deps", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add backnotprop/plannotator --skill update-deps -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install backnotprop/plannotator update-deps --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/backnotprop/plannotator.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.agents/skills/update-deps .opencode/skills/update-deps && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "update-deps" agent skill from https://github.com/backnotprop/plannotator/tree/main/.agents/skills/update-deps into .opencode/skills/update-deps/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "update-deps", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
update-depsAudits outdated npm and Bun packages for supply chain integrity before bumping them, deferring risky ones and logging every decision.
Work happens in three phases: discovery, integrity audit and execution. Discovery runs bun outdated and records each package's current and target versions, whether it is held back by the minimum release age gate, and whether it is a runtime, dev or peer dependency. Packages the gate blocks entirely are flagged, since they may need a minimumReleaseAgeExcludes entry in bunfig.toml.
The integrity audit is the core. One Sonnet sub-agent per package runs checks in parallel and returns a JSON report covering maintainers, publish age, tarball diffs and provenance, and a failed or timed-out audit is marked defer. Results are sorted into tiers, from runtime libraries with a large surface, which get provenance checks, diff review and tests, through service SDKs, which need changelog reading, to dev-only packages that can update freely. Risky packages are deferred with notes under ~/.supply-chain/notes/.
4 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 47486cd. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
npmbunghFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use npm and gh, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Dependency Update Audit loads about 1.8k tokens when it runs. Until then it costs about 54 tokens; SKILL.md has 555 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from backnotprop/plannotator at commit 47486cd, republished under its Apache-2.0 licence (© backnotprop). 555 words, ~1,818 tokens.
.claude/skills/update-deps/SKILL.md (or your agent's skills folder).Audit outdated packages, verify supply chain integrity, bump what's safe, defer what needs review, and log everything.
This process has three phases: discovery, integrity audit, and execution. The integrity audit is the most important — every package gets checked before it touches the lockfile.
Run bun outdated to get the full list of packages with available updates.
bun outdatedParse the output into a structured list. For each package, note:
* in the output — the footnote "The * indicates that version isn't true latest due to minimum release age" confirms this)Also check whether any packages are blocked entirely by the age gate (like @pierre/diffs was when its minimum semver range couldn't resolve). Flag these separately — they may need minimumReleaseAgeExcludes in bunfig.toml.
This is the core of the process. Spawn one Sonnet sub-agent per package to run the integrity check in parallel. Sonnet is used here because these are independent, structured verification tasks that don't need heavier reasoning.
Each sub-agent receives the package name, current version, and target version, and performs the following checks:
For each outdated package, spawn a Sonnet agent with this task:
You are auditing the npm package "{package}" for a version bump from {current} to {target}.
Run these checks and report back with a JSON object:
1. **Maintainer verification**: Check if maintainers changed between versions.
npm view {package}@{current} maintainers --json
npm view {package}@{target} maintainers --json
Compare the two lists. Flag any additions or removals.
2. **Publish date and age**: Get the publish timestamp.
npm view {package} time --json
Extract the date for version {target}. Calculate days since publication.
Flag if younger than 7 days.
3. **Provenance**: Check if the package has registry signatures or attestations.
npm audit signatures (if not already run this session)
Note whether the package has provenance attestations.
4. **Tarball diff**: Show what actually changed in the published package.
npm diff --diff={package}@{current} --diff={package}@{target}
Summarize the changes:
- How many files changed
- Are changes limited to version bumps, deps, and rebuilt dist? Or are there meaningful source changes?
- Any new runtime dependencies added?
- Any suspicious patterns (obfuscated code, eval(), network calls in unexpected places)
5. **Release notes**: Try to find what changed.
Check the package's repository for release notes or changelog:
npm view {package}@{target} repository.url
gh release view v{target} --repo <owner/repo> (try with and without v prefix)
Summarize the changelog if found.
Report your findings as JSON:
{{
"package": "{package}",
"from": "{current}",
"to": "{target}",
"age_days": <number>,
"maintainers_changed": <boolean>,
"maintainers_added": [],
"maintainers_removed": [],
"provenance": <boolean>,
"new_runtime_deps": [],
"files_changed": <number>,
"has_source_changes": <boolean>,
"changelog_summary": "<brief summary>",
"suspicious_patterns": [],
"verdict": "safe" | "review" | "defer",
"verdict_reason": "<one sentence explanation>"
}}
Verdict guidelines:
- "safe": Same maintainers, no new runtime deps, changes match what changelog describes, no suspicious patterns
- "review": Minor concerns (e.g., new maintainer who is clearly from the same org, small new dep from known publisher)
- "defer": Maintainer changes from unknown accounts, new runtime deps with unclear purpose, suspicious code patterns, substantive API changes that need integration testingAs sub-agents complete, collect their JSON reports. If a sub-agent fails or times out, mark that package as "defer" with reason "audit failed".
After collecting all results, classify packages into tiers. This helps the user understand the risk profile at a glance:
| Tier | Description | Typical action |
|---|---|---|
| Runtime, high surface | Libraries your code calls directly (parsers, diff engines, UI libs) | Check provenance, review diff, run tests |
| SDK/API deps | Third-party service SDKs (agent SDKs, platform integrations) | Read changelog for API changes, test integration |
| Dev-only | Type definitions, build tools, test frameworks | Update freely — these don't ship |
| Build toolchain | Bun itself, compilers, bundlers | Most caution — breakage affects all outputs |
For all packages with verdict "safe":
bun update pkg1@version1 pkg2@version2 ...If the update fails due to age gate conflicts (a package's minimum semver can't resolve), add it to minimumReleaseAgeExcludes in bunfig.toml and document why.
Write the full audit results to ~/.supply-chain/notes/<YYYY-MM-DD>.json:
{
"date": "YYYY-MM-DD",
"project": "plannotator",
"bumped": [
{
"package": "...",
"from": "...",
"to": "...",
"age_days": 0,
"maintainers_changed": false,
"provenance": false,
"notes": "..."
}
],
"deferred": [
{
"package": "...",
"current": "...",
"available": "...",
"age_days": 0,
"maintainers_changed": false,
"reason": "...",
"review_by": "YYYY-MM-DD"
}
],
"excluded_from_age_gate": [
{
"package": "...",
"reason": "..."
}
]
}Set review_by to 7 days from today for deferred packages.
Read all files in ~/.supply-chain/notes/ and collect any deferred packages from previous audits that are still at the same version in the current lockfile. These are packages that were deferred before and still haven't been updated.
To check: for each previously deferred entry, see if the current installed version matches the current field from the deferral note. If it does, the package is still deferred.
Present a clear summary to the user:
List each bumped package with version change and one-line reason it was safe.
List each deferred package with version change and reason for deferral.
List any packages that were deferred in previous audit sessions and still haven't been bumped. Include the original deferral date and reason. This is the "you've been putting this off" section — it keeps deferred packages from being forgotten.
If the still-deferred list is empty, say so — that's a good sign.
If any packages were added to minimumReleaseAgeExcludes, note them and why.
© backnotprop, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in .agents/skills/update-deps of backnotprop/plannotator.
Open the folder on GitHubat commit 47486cd
Dependency Update Audit next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Dependency Update Audit this skillbacknotprop/plannotator | 9.2k | — | ~1.8k | Automated safety check: Pass | Apache-2.0 | |
| npm Supply Chain Securitybodadotsh/npm-security-best-practices | 859 | — | ~1k | Automated safety check: Warn | MIT | |
| Detecting Typosquatting Packagesmukul975/Anthropic-Cybersecurity-Skills | 34k | — | ~3k | Automated safety check: Pass | Apache-2.0 | |
| npm Supply Chain Checkmajiayu000/spellbook | 286 | — | ~1.5k | Automated safety check: Pass | MIT | |
| Supply Chain Risk Auditortrailofbits/skills | 7.4k | — | ~1.7k | Automated safety check: Notes | CC-BY-SA-4.0 | |
| Stash Supply Chain Securitycipherstash/stack | 157 | — | ~5.2k | Automated safety check: Warn | MIT |
bodadotsh/npm-security-best-practices
Applies safer package manager defaults and dependency vetting to JavaScript and TypeScript projects to reduce supply-chain attack risk.
mukul975/Anthropic-Cybersecurity-Skills
Flag misspelled, brandjacked, and typosquatted package names across npm, PyPI, and crates.io before installation, using edit-distance, keyboard-proximity, and known-target corpus matching with…
majiayu000/spellbook
Scans a repository, its lockfiles and node_modules for known malicious npm package versions and install-time indicators, using a read-only Python scanner.
trailofbits/skills
Audits a project's dependencies for supply-chain risk: version-matched advisories for direct dependencies and the full lockfile tree, abandoned or archived upstreams, npm publisher concentration…
cipherstash/stack
Supply-chain security controls for the @cipherstash/stack monorepo.
dralgorhythm/claude-agentic-framework
Sequences safe dependency upgrades: read the changelog, verify the version exists upstream, pin it, and keep major bumps in separate commits behind a full gate run.
backnotprop/plannotator
Builds self-contained HTML explainers for plans, pull requests and technical concepts in Plannotator's theme, then opens them in its annotation view.
backnotprop/plannotator
Drafts Plannotator release notes with full contributor credit, bumps versions in dependency order, builds, and starts the tag-driven release pipeline, in four reviewed phases.
backnotprop/plannotator
Mines a Plannotator archive of denied plans for feedback patterns and prompt improvements, then writes an HTML dashboard report, with a Claude Code fallback.
backnotprop/plannotator
Reviews Renovate pull requests that bump GitHub Actions by checking pinned SHAs against upstream tags, scanning changelogs and confirming workflows stay compatible.
backnotprop/plannotator
Guides the agent from a vague objective to a written goal package under goals/, using a confirmed restatement, a browser interview, a fact sheet and a codebase pass.
backnotprop/plannotator
Opens Plannotator's browser annotation view for a markdown, config, HTML, URL or folder target and acts on the feedback you leave, with an optional approval gate.
Works with
Categories
Audits outdated npm and Bun packages for supply chain integrity before bumping them, deferring risky ones and logging every decision. Work happens in three phases: discovery, integrity audit and execution. Discovery runs bun outdated and records each package's current and target versions, whether it is held back by the minimum release age gate, and whether it is a runtime, dev or peer dependency.
Dependency Update Audit fits situations like: updating dependencies in a Bun or npm project with provenance checks; deciding which outdated packages are safe to bump now; logging deferred packages with the reason for review; spotting packages blocked by a minimum release age.
Run `npx skills add backnotprop/plannotator --skill update-deps -a claude-code`. Or copy the skill folder (.agents/skills/update-deps in backnotprop/plannotator) into .claude/skills/update-deps in your project. Claude Code loads it when a task matches its description.
Run `npx skills add backnotprop/plannotator --skill update-deps -a codex`. Or copy the skill folder (.agents/skills/update-deps in backnotprop/plannotator) into .agents/skills/update-deps in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add backnotprop/plannotator --skill update-deps -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/update-deps, .gemini/skills/update-deps, .github/skills/update-deps and .opencode/skills/update-deps in your project.
Going by SKILL.md and its folder, Dependency Update Audit needs the command-line tools its instructions call (npm, bun and gh). Our summary lists: Bun, for bun outdated; Network access to the npm registry for maintainer and provenance checks.
SKILL.md contains no URLs. Its commands use npm and gh, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Dependency Update Audit is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 1.8k tokens (SKILL.md is roughly 7.3k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Dependency Update Audit: npm Supply Chain Security (bodadotsh/npm-security-best-practices, 859 stars), Detecting Typosquatting Packages (mukul975/Anthropic-Cybersecurity-Skills, 34k stars), npm Supply Chain Check (majiayu000/spellbook, 286 stars) and Supply Chain Risk Auditor (trailofbits/skills, 7.4k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
backnotprop (a GitHub user) maintains it in backnotprop/plannotator, which has 9,205 GitHub stars. The repository holds 13 skills in this directory. The repository was last updated on October 8, 2026.
Source: backnotprop/plannotator on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.