npm Supply Chain Security
bodadotsh/npm-security-best-practices
Applies safer package manager defaults and dependency vetting to JavaScript and TypeScript projects to reduce supply-chain attack risk.
Run a reusable JavaScript supply-chain security baseline with pnpm-first hardening, release-age gating, lifecycle-script controls, exotic dependency checks, CI install checks, and optional incident…
$ npx skills add instructa/agent-skills --skill package-security-check -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install instructa/agent-skills package-security-check --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/instructa/agent-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/security/package-security-check .claude/skills/package-security-check && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "package-security-check" agent skill from https://github.com/instructa/agent-skills/tree/main/skills/security/package-security-check into .claude/skills/package-security-check/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "package-security-check", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/instructa/agent-skills/tree/main/skills/security/package-security-checkType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add instructa/agent-skills --skill package-security-check -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install instructa/agent-skills package-security-check --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/instructa/agent-skills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/security/package-security-check .agents/skills/package-security-check && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "package-security-check" agent skill from https://github.com/instructa/agent-skills/tree/main/skills/security/package-security-check into .agents/skills/package-security-check/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "package-security-check", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add instructa/agent-skills --skill package-security-check -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install instructa/agent-skills package-security-check --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/instructa/agent-skills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/security/package-security-check .cursor/skills/package-security-check && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "package-security-check" agent skill from https://github.com/instructa/agent-skills/tree/main/skills/security/package-security-check into .cursor/skills/package-security-check/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "package-security-check", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/instructa/agent-skills.git --path skills/security/package-security-check--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add instructa/agent-skills --skill package-security-check -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install instructa/agent-skills package-security-check --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/instructa/agent-skills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/security/package-security-check .gemini/skills/package-security-check && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "package-security-check" agent skill from https://github.com/instructa/agent-skills/tree/main/skills/security/package-security-check into .gemini/skills/package-security-check/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "package-security-check", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install instructa/agent-skills package-security-checkInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add instructa/agent-skills --skill package-security-check -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/instructa/agent-skills.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/security/package-security-check .github/skills/package-security-check && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "package-security-check" agent skill from https://github.com/instructa/agent-skills/tree/main/skills/security/package-security-check into .github/skills/package-security-check/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "package-security-check", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add instructa/agent-skills --skill package-security-check -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install instructa/agent-skills package-security-check --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/instructa/agent-skills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/security/package-security-check .opencode/skills/package-security-check && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "package-security-check" agent skill from https://github.com/instructa/agent-skills/tree/main/skills/security/package-security-check into .opencode/skills/package-security-check/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "package-security-check", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
package-security-checkRun a reusable JavaScript supply-chain security baseline with pnpm-first hardening, release-age gating, lifecycle-script controls, exotic dependency checks, CI install checks, and optional incident…
Package Security Check is an agent skill from instructa/agent-skills. Run a reusable JavaScript supply-chain security baseline with pnpm-first hardening, release-age gating, lifecycle-script controls, exotic dependency checks, CI install checks, and optional incident IOC profiles.
Its SKILL.md is about 1.8k tokens, which your agent loads only when the skill is triggered. The skill folder holds 8 other files, including scripts (for example `README.md`, `agents/openai.yaml` and `data/iocs/npm-supply-chain-2026-05.json`).
It sits in Security, covering Supply chain security. It works with pnpm and JavaScript. The repository describes itself as: A curated collection of agent-skills.
4 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit d49c149. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Ships 1 file in scripts/ (Python), which the agent can run.
Shell commands in SKILL.md call:
npmpnpmpython3yarnbunFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use npm, pnpm and yarn, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Package Security Check loads about 1.8k tokens when it runs. Until then it costs about 59 tokens; SKILL.md has 814 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.
Without a licence we can't republish the file, so here is its outline and opening line. It has 814 words (~1,834 tokens).
“Use --strict when the check should fail on hardening gaps. Use --json when another tool needs machine-readable output. Use --include-installed only when node_modules exists and installed package lifecycle metadata matters.”
SKILL.md and 4 other files (scripts) in skills/security/package-security-check of instructa/agent-skills.
Open the folder on GitHubat commit d49c149
Package Security Check next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Package Security Check this skillinstructa/agent-skills | 139 | — | ~1.8k | Automated safety check: Pass | None | |
| npm Supply Chain Securitybodadotsh/npm-security-best-practices | 859 | — | ~1k | Automated safety check: Warn | MIT | |
| Check npmgrafana/skills | 278 | — | ~1.3k | Automated safety check: Warn | Apache-2.0 | |
| npm Supply Chain Checkmajiayu000/spellbook | 286 | — | ~1.5k | Automated safety check: Pass | MIT | |
| Interlinked Supply ChainQuentinCody/interlinked-cli | 178 | — | ~2.8k | Automated safety check: Pass | MIT | |
| Memstack Security Dependency Auditcwinvestments/memstack | 423 | — | ~3.1k | Automated safety check: Pass | Proprietary |
bodadotsh/npm-security-best-practices
Applies safer package manager defaults and dependency vetting to JavaScript and TypeScript projects to reduce supply-chain attack risk.
grafana/skills
Audit a JavaScript/TypeScript repo's npm, yarn, or pnpm configuration for supply-chain hardening: tool version, lifecycle scripts, unsafe dependency protocols, and minimum release age ≥3 days.
majiayu000/spellbook
Scans a repository, its lockfiles and node_modules for known malicious npm package versions and install-time indicators, using a read-only Python scanner.
QuentinCody/interlinked-cli
Respond to blocked package installs and manage the Interlinked supply-chain allowlist.
cwinvestments/memstack
A skill your agent uses when the user says 'dependency audit', 'npm audit', 'pip audit', 'cargo audit', 'security vulnerabilities', 'outdated packages', 'supply chain', or needs to scan project…
Goldziher/ai-rulez
Per-language dependency vulnerability audit tool reference (cargo audit/deny, pip-audit, npm/pnpm audit, govulncheck, bundler-audit, composer audit, OWASP dependency-check, dotnet vulnerable…
instructa/agent-skills
A skill your agent uses when the user wants to turn an application, product, startup idea, SaaS, mobile app, web app, API, AI product, or internal tool into a production-ready Markdown specification…
instructa/agent-skills
Have Codex review a feature or change from Claude Code, then let Claude address the findings and request verification.
instructa/agent-skills
Find, clone, inspect, and summarize high-quality GitHub reference repositories for coding agents.
instructa/agent-skills
Run or install repo security leak checks with BetterLeaks and Trivy.
instructa/agent-skills
Delegate a bounded task from a Codex session to a Fable-powered Cursor Agent in the same Herdr workspace, then wait for and collect the result.
instructa/agent-skills
Delegate a bounded task from a Codex session to Grok 4.6 with xhigh reasoning in the same Herdr workspace, then wait for and collect the result.
Works with
Categories
Run a reusable JavaScript supply-chain security baseline with pnpm-first hardening, release-age gating, lifecycle-script controls, exotic dependency checks, CI install checks, and optional incident…. Package Security Check is an agent skill from instructa/agent-skills. Run a reusable JavaScript supply-chain security baseline with pnpm-first hardening, release-age gating, lifecycle-script controls, exotic dependency checks, CI install checks, and optional incident IOC profiles.
Package Security Check fits situations like: tasks that involve Supply chain security.
Run `npx skills add instructa/agent-skills --skill package-security-check -a claude-code`. Or copy the skill folder (skills/security/package-security-check in instructa/agent-skills) into .claude/skills/package-security-check in your project. Claude Code loads it when a task matches its description.
Run `npx skills add instructa/agent-skills --skill package-security-check -a codex`. Or copy the skill folder (skills/security/package-security-check in instructa/agent-skills) into .agents/skills/package-security-check in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add instructa/agent-skills --skill package-security-check -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/package-security-check, .gemini/skills/package-security-check, .github/skills/package-security-check and .opencode/skills/package-security-check in your project.
Going by SKILL.md and its folder, Package Security Check needs Python for the scripts in its folder and the command-line tools its instructions call (npm, pnpm, python3, yarn and bun). Our summary lists: Python 3; Node.js.
SKILL.md contains no URLs. Its commands use npm, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.
No licence was found for Package Security Check or its repository. Without one, default copyright applies: ask the author before reusing or redistributing it.
About 1.8k tokens (SKILL.md is roughly 7.3k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Package Security Check: npm Supply Chain Security (bodadotsh/npm-security-best-practices, 859 stars), Check npm (grafana/skills, 278 stars), npm Supply Chain Check (majiayu000/spellbook, 286 stars) and Interlinked Supply Chain (QuentinCody/interlinked-cli, 178 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
instructa (a GitHub organization) maintains it in instructa/agent-skills, which has 139 GitHub stars. The repository holds 17 skills in this directory. The repository was last updated on September 28, 2026.
Source: instructa/agent-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.