Stash Supply Chain Security
cipherstash/stack
Supply-chain security controls for the @cipherstash/stack monorepo.
Dependency gatekeeper. An agent skill from ccplugins/awesome-claude-code-plugins.
$ npx skills add ccplugins/awesome-claude-code-plugins --skill doorman -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install ccplugins/awesome-claude-code-plugins doorman --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/ccplugins/awesome-claude-code-plugins.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/bullpen/skills/doorman .claude/skills/doorman && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "doorman" agent skill from https://github.com/ccplugins/awesome-claude-code-plugins/tree/main/plugins/bullpen/skills/doorman into .claude/skills/doorman/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "doorman", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/ccplugins/awesome-claude-code-plugins/tree/main/plugins/bullpen/skills/doormanType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add ccplugins/awesome-claude-code-plugins --skill doorman -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install ccplugins/awesome-claude-code-plugins doorman --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/ccplugins/awesome-claude-code-plugins.git skills-src && mkdir -p .agents/skills && cp -r skills-src/plugins/bullpen/skills/doorman .agents/skills/doorman && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "doorman" agent skill from https://github.com/ccplugins/awesome-claude-code-plugins/tree/main/plugins/bullpen/skills/doorman into .agents/skills/doorman/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "doorman", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add ccplugins/awesome-claude-code-plugins --skill doorman -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install ccplugins/awesome-claude-code-plugins doorman --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/ccplugins/awesome-claude-code-plugins.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/plugins/bullpen/skills/doorman .cursor/skills/doorman && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "doorman" agent skill from https://github.com/ccplugins/awesome-claude-code-plugins/tree/main/plugins/bullpen/skills/doorman into .cursor/skills/doorman/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "doorman", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/ccplugins/awesome-claude-code-plugins.git --path plugins/bullpen/skills/doorman--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add ccplugins/awesome-claude-code-plugins --skill doorman -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install ccplugins/awesome-claude-code-plugins doorman --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/ccplugins/awesome-claude-code-plugins.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/plugins/bullpen/skills/doorman .gemini/skills/doorman && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "doorman" agent skill from https://github.com/ccplugins/awesome-claude-code-plugins/tree/main/plugins/bullpen/skills/doorman into .gemini/skills/doorman/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "doorman", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install ccplugins/awesome-claude-code-plugins doormanInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add ccplugins/awesome-claude-code-plugins --skill doorman -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/ccplugins/awesome-claude-code-plugins.git skills-src && mkdir -p .github/skills && cp -r skills-src/plugins/bullpen/skills/doorman .github/skills/doorman && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "doorman" agent skill from https://github.com/ccplugins/awesome-claude-code-plugins/tree/main/plugins/bullpen/skills/doorman into .github/skills/doorman/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "doorman", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add ccplugins/awesome-claude-code-plugins --skill doorman -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install ccplugins/awesome-claude-code-plugins doorman --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/ccplugins/awesome-claude-code-plugins.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/plugins/bullpen/skills/doorman .opencode/skills/doorman && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "doorman" agent skill from https://github.com/ccplugins/awesome-claude-code-plugins/tree/main/plugins/bullpen/skills/doorman into .opencode/skills/doorman/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "doorman", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
doormanDependency gatekeeper. An agent skill from ccplugins/awesome-claude-code-plugins.
Doorman is an agent skill from ccplugins/awesome-claude-code-plugins. Dependency gatekeeper. Before you add any new package — npm install, pip install, go get, a new import of something not already in the lockfile — stop at the door and make it earn entry. Ask whether the stdlib, the runtime/platform, or a dep already installed does the job, and whether a few lines would too. A dependency is a permanent cost: maintenance, supply chain, bundle weight, breakage on someone else's schedule. Weigh size, last release, and transitive deps — not just "does it work." Supports intensity…
Its SKILL.md is about 1.5k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Development, covering Dependency management and Supply chain security. It works with npm. The repository describes itself as: Awesome Claude Code plugins — a curated list of slash commands, subagents, MCP servers, and hooks for Claude Code. The licence is MIT.
4 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit 5bd4f16. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
npmpipgocargogemFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use npm and pip, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Doorman loads about 1.5k tokens when it runs. Until then it costs about 196 tokens; SKILL.md has 810 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from ccplugins/awesome-claude-code-plugins at commit 5bd4f16, republished under its MIT licence (© ccplugins). 810 words, ~1,497 tokens.
.claude/skills/doorman/SKILL.md (or your agent's skills folder).You are the bouncer at the door of the lockfile. Every package wants in, and most of them are trouble you'll be babysitting long after the person who added them has moved on. You've been paged at 2am by a transitive dependency three levels down that you never chose and can't name. So you check IDs at the door.
A dependency isn't code you get for free. It's code you adopt forever.
Not every install is a fight. The door stays shut on new dependencies — anything not already in the lockfile. That's where the reflex fires:
npm install, pip install, go get, cargo add, gem installAlready in the lockfile, or the task explicitly names the package? Wave it through — one line, move on. YAGNI applies to gatekeeping too; don't relitigate what's already load-bearing.
Before the package crosses the threshold, make it answer:
Intl, crypto.subtle, fetch,
structuredClone are already in the box you're running in.Only when all four say no does the package earn its keep — and then you still weigh what it drags in: install size, last release date (abandoned?), transitive dep count, license, maintainer count. "It works in the demo" is not entry.
Do NOT push hand-rolling crypto, authentication, or parsing of hostile
formats. Home-grown JWT validation, a bespoke password hash, a hand-written
XML/PDF/ZIP/image parser fed untrusted bytes — these are exactly where a vetted,
widely-audited dependency is the lazy AND correct call. The stdlib heuristic
inverts here: reaching for libsodium, the platform's crypto, or the
maintained parser is good laziness. Rolling your own is not thrift, it's a CVE
with your name on it. Name this exception out loud when it applies.
The working code first — using the stdlib/native/existing path when one wins. Then a short Doorman: note: what was proposed, what replaced it, or why the dep earned entry. One or two lines. If the note outruns the fix, cut it.
Pattern: [code] → Doorman: [proposed X] → [replaced with native/stdlib Y] · or [X earns it: reason]
| Level | What change |
|---|---|
| lite | Add the dep the task reached for, but name the stdlib/native one-liner that avoids it — one line. User decides. |
| full | Run the four questions; use the no-dep path when it wins, add the package only when it earns entry, and say why. Default. |
| ultra | Refuse the dep unless it clears the bar: prove stdlib/native can't do it, and audit what it drags in (size, last release, transitive count) before it enters. |
Example — "install moment to format a date":
Intl.DateTimeFormat ships in the runtime and covers this — moment is ~300KB you don't need."new Intl.DateTimeFormat('en-US', {…}).format(d) does the formatting natively — no dependency added."Intl covers the locale/timezone cases in use, and left the one-line helper so nothing reaches for moment again.Skip it when the dep is already in the lockfile, when the task explicitly names the package, or when told to stop. And honor the carve-out: never talk someone out of a vetted crypto/auth/hostile-parser dependency in the name of thrift — that's the one door you hold open. The human's explicit call wins; push once, then comply.
The Doorman governs what enters your dependency tree, not how much you build — pair it with Ponytail, which keeps the code lazy, and the Doorman keeps lazy from meaning "just npm install it." "stop doorman" / "normal mode": revert. Level persists until changed or session end.
The cheapest dependency is the one you never let in.
© ccplugins, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in plugins/bullpen/skills/doorman of ccplugins/awesome-claude-code-plugins.
Open the folder on GitHubat commit 5bd4f16
Doorman next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Doorman this skillccplugins/awesome-claude-code-plugins | 967 | — | ~1.5k | Automated safety check: Pass | MIT | |
| Stash Supply Chain Securitycipherstash/stack | 157 | — | ~5.2k | Automated safety check: Warn | MIT | |
| Dependency Upgrade Protocoldralgorhythm/claude-agentic-framework | 124 | — | ~1.5k | Automated safety check: Pass | None | |
| Detecting Malicious npm Packagesmukul975/Anthropic-Cybersecurity-Skills | 34k | — | ~2.6k | Automated safety check: Warn | Apache-2.0 | |
| npm Supply Chain Securitybodadotsh/npm-security-best-practices | 859 | — | ~1k | Automated safety check: Warn | MIT | |
| Dependency Update Auditbacknotprop/plannotator | 9.2k | — | ~1.8k | Automated safety check: Pass | Apache-2.0 |
cipherstash/stack
Supply-chain security controls for the @cipherstash/stack monorepo.
dralgorhythm/claude-agentic-framework
Sequences safe dependency upgrades: read the changelog, verify the version exists upstream, pin it, and keep major bumps in separate commits behind a full gate run.
mukul975/Anthropic-Cybersecurity-Skills
Triage npm packages and lockfiles for install-script malware, credential exfiltration, and worming behavior using GuardDog, manual tarball inspection, and dynamic detonation with network/filesystem…
bodadotsh/npm-security-best-practices
Applies safer package manager defaults and dependency vetting to JavaScript and TypeScript projects to reduce supply-chain attack risk.
backnotprop/plannotator
Audits outdated npm and Bun packages for supply chain integrity before bumping them, deferring risky ones and logging every decision.
mukul975/Anthropic-Cybersecurity-Skills
Flag misspelled, brandjacked, and typosquatted package names across npm, PyPI, and crates.io before installation, using edit-distance, keyboard-proximity, and known-target corpus matching with…
ccplugins/awesome-claude-code-plugins
Run structured AI meetings for plans, product ideas, technical designs, business decisions, feature proposals, and strategy choices.
ccplugins/awesome-claude-code-plugins
Bootstrap a new FastAPI backend with async SQLAlchemy 2.0, asyncpg, Alembic, Pydantic v2, and no deprecated APIs.
ccplugins/awesome-claude-code-plugins
Bootstrap a new Flutter mobile app with clean architecture, Riverpod, FVM-pinned SDK, current packages, and no deprecated APIs.
ccplugins/awesome-claude-code-plugins
Bootstrap a new Next.js (App Router, TypeScript) web app with current packages and no deprecated APIs.
ccplugins/awesome-claude-code-plugins
Write up a coding session for a non-technical stakeholder — the context, what was built, and the engineering reasoning behind it — the way a senior engineer briefs a product manager who does not…
ccplugins/awesome-claude-code-plugins
Aggiunge a un sito/app un agente di difesa che rileva e blocca richieste malevole (SQL injection, XSS, path traversal, brute force, bot) con rate limiting, blocklist IP e modalità lockdown che…
Works with
Categories
Dependency gatekeeper. An agent skill from ccplugins/awesome-claude-code-plugins. Doorman is an agent skill from ccplugins/awesome-claude-code-plugins. Dependency gatekeeper.
Doorman fits situations like: the user says doorman; do we need this dep; vet this package; can we avoid the dependency.
Run `npx skills add ccplugins/awesome-claude-code-plugins --skill doorman -a claude-code`. Or copy the skill folder (plugins/bullpen/skills/doorman in ccplugins/awesome-claude-code-plugins) into .claude/skills/doorman in your project. Claude Code loads it when a task matches its description.
Run `npx skills add ccplugins/awesome-claude-code-plugins --skill doorman -a codex`. Or copy the skill folder (plugins/bullpen/skills/doorman in ccplugins/awesome-claude-code-plugins) into .agents/skills/doorman in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add ccplugins/awesome-claude-code-plugins --skill doorman -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/doorman, .gemini/skills/doorman, .github/skills/doorman and .opencode/skills/doorman in your project.
Going by SKILL.md and its folder, Doorman needs the command-line tools its instructions call (npm, pip, go, cargo and gem). Our summary lists: Python 3; Node.js.
SKILL.md contains no URLs. Its commands use npm and pip, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Doorman is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.
About 1.5k tokens (SKILL.md is roughly 6k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Doorman: Stash Supply Chain Security (cipherstash/stack, 157 stars), Dependency Upgrade Protocol (dralgorhythm/claude-agentic-framework, 124 stars), Detecting Malicious npm Packages (mukul975/Anthropic-Cybersecurity-Skills, 34k stars) and npm Supply Chain Security (bodadotsh/npm-security-best-practices, 859 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
ccplugins (a GitHub organization) maintains it in ccplugins/awesome-claude-code-plugins, which has 967 GitHub stars. The repository holds 68 skills in this directory. The repository was last updated on August 12, 2026.
Source: ccplugins/awesome-claude-code-plugins on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.