Agent skill

Package Security Check

by instructa in instructa/agent-skills

Run a reusable JavaScript supply-chain security baseline with pnpm-first hardening, release-age gating, lifecycle-script controls, exotic dependency checks, CI install checks, and optional incident…

No licenceAuto-check passedSecurity

Install Package Security Check

skills CLI
$ npx skills add instructa/agent-skills --skill package-security-check -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install instructa/agent-skills package-security-check --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/instructa/agent-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/security/package-security-check .claude/skills/package-security-check && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
package-security-check
GitHub stars
139
Token cost
~1.8k tokens
SKILL.md length
814 words
Files
5 (incl. scripts)
Skills in repo
17
Repo updated
First seen
Licence
None found

At a glance

Run a reusable JavaScript supply-chain security baseline with pnpm-first hardening, release-age gating, lifecycle-script controls, exotic dependency checks, CI install checks, and optional incident…

  • Works in 4 steps: Treat this as a base JS supply-chain… → Before running installs, package-manager… → After the traffic-light analysis, ask… → …
  • Tasks that involve Supply chain security
  • SKILL.md covers Workflow, Canonical Policy, Package Manager Posture and CI Rules, plus 1 more section
  • Runs Python scripts from its folder; calls npm, pnpm and python3

What it does

Package Security Check is an agent skill from instructa/agent-skills. Run a reusable JavaScript supply-chain security baseline with pnpm-first hardening, release-age gating, lifecycle-script controls, exotic dependency checks, CI install checks, and optional incident IOC profiles.

Its SKILL.md is about 1.8k tokens, which your agent loads only when the skill is triggered. The skill folder holds 8 other files, including scripts (for example `README.md`, `agents/openai.yaml` and `data/iocs/npm-supply-chain-2026-05.json`).

It sits in Security, covering Supply chain security. It works with pnpm and JavaScript. The repository describes itself as: A curated collection of agent-skills.

When your agent uses it

  • Tasks that involve Supply chain security

Example prompts

  • “/package-security-check”

Requirements

  • Python 3
  • Node.js

Workflow steps

4 steps, taken from the first numbered list in SKILL.md.

  1. Treat this as a base JS supply-chain check first. Do not force the result around one CVE, vendor, package family, or incident.
  2. Before running installs, package-manager mutation commands, or file edits, perform only read-only inspection and present a traffic-light…
  3. After the traffic-light analysis, ask for approval before changing files or executing package-manager operations that can install, update…
  4. From this skill directory, run the baseline scanner against the repo or workspace root

What it can do on your machine

Read from SKILL.md and the folder at commit d49c149. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (Python), which the agent can run.

    Shell commands in SKILL.md call:

    • npm
    • pnpm
    • python3
    • yarn
    • bun

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use npm, pnpm and yarn, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Package Security Check loads about 1.8k tokens when it runs. Until then it costs about 59 tokens; SKILL.md has 814 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~59
When it runs · the whole SKILL.md, loaded when a task matches
~1.8k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

Without a licence we can't republish the file, so here is its outline and opening line. It has 814 words (~1,834 tokens).

“Use --strict when the check should fail on hardening gaps. Use --json when another tool needs machine-readable output. Use --include-installed only when node_modules exists and installed package lifecycle metadata matters.”

— opening of SKILL.md by instructa
name
package-security-check

Read the full SKILL.md on GitHub

Files

SKILL.md and 4 other files (scripts) in skills/security/package-security-check of instructa/agent-skills.

  • SKILL.md
  • README.md
  • agents/openai.yaml
  • data/iocs/npm-supply-chain-2026-05.json
  • scripts/check_js_supply_chain.py

Open the folder on GitHubat commit d49c149

Compare with similar skills

Package Security Check next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Package Security Check compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Package Security Check this skillinstructa/agent-skills139—~1.8kAutomated safety check: PassNone
npm Supply Chain Securitybodadotsh/npm-security-best-practices859—~1kAutomated safety check: WarnMIT
Check npmgrafana/skills278—~1.3kAutomated safety check: WarnApache-2.0
npm Supply Chain Checkmajiayu000/spellbook286—~1.5kAutomated safety check: PassMIT
Interlinked Supply ChainQuentinCody/interlinked-cli178—~2.8kAutomated safety check: PassMIT
Memstack Security Dependency Auditcwinvestments/memstack423—~3.1kAutomated safety check: PassProprietary

Similar skills

  • npm Supply Chain Security

    bodadotsh/npm-security-best-practices

    Applies safer package manager defaults and dependency vetting to JavaScript and TypeScript projects to reduce supply-chain attack risk.

    859 GitHub stars~1k tokensUpdated 7 days ago
    SecurityAuto-check: warnings
  • Check npm

    grafana/skills

    Official

    Audit a JavaScript/TypeScript repo's npm, yarn, or pnpm configuration for supply-chain hardening: tool version, lifecycle scripts, unsafe dependency protocols, and minimum release age ≥3 days.

    278 GitHub stars~1.3k tokensUpdated yesterday
    DevOps & CloudAuto-check: warnings
  • npm Supply Chain Check

    majiayu000/spellbook

    Scans a repository, its lockfiles and node_modules for known malicious npm package versions and install-time indicators, using a read-only Python scanner.

    286 GitHub stars~1.5k tokensUpdated yesterday
    SecurityAuto-check passed
  • Interlinked Supply Chain

    QuentinCody/interlinked-cli

    Respond to blocked package installs and manage the Interlinked supply-chain allowlist.

    178 GitHub stars~2.8k tokensUpdated 5 days ago
    SecurityAuto-check passed
  • A skill your agent uses when the user says 'dependency audit', 'npm audit', 'pip audit', 'cargo audit', 'security vulnerabilities', 'outdated packages', 'supply chain', or needs to scan project…

    423 GitHub stars~3.1k tokensUpdated 11 days ago
    SecurityAuto-check passed
  • Dependency Awareness

    Goldziher/ai-rulez

    Per-language dependency vulnerability audit tool reference (cargo audit/deny, pip-audit, npm/pnpm audit, govulncheck, bundler-audit, composer audit, OWASP dependency-check, dotnet vulnerable…

    153 GitHub stars~250 tokensUpdated today
    SecurityAuto-check passed

More from instructa/agent-skills

All 17 skills in this repo
  • App Spec Packager

    instructa/agent-skills

    A skill your agent uses when the user wants to turn an application, product, startup idea, SaaS, mobile app, web app, API, AI product, or internal tool into a production-ready Markdown specification…

    139 GitHub stars~1.5k tokensUpdated 9 days ago
    Auto-check passed
  • Codex Reviewer

    instructa/agent-skills

    Have Codex review a feature or change from Claude Code, then let Claude address the findings and request verification.

    139 GitHub stars~1.6k tokensUpdated 9 days ago
    Auto-check passed
  • Search Context

    instructa/agent-skills

    Find, clone, inspect, and summarize high-quality GitHub reference repositories for coding agents.

    139 GitHub stars~2.1k tokensUpdated 9 days ago
    Auto-check passed
  • Secleak Check

    instructa/agent-skills

    Run or install repo security leak checks with BetterLeaks and Trivy.

    139 GitHub stars~557 tokensUpdated 9 days ago
    Auto-check passed
  • Delegate Fable

    instructa/agent-skills

    Delegate a bounded task from a Codex session to a Fable-powered Cursor Agent in the same Herdr workspace, then wait for and collect the result.

    139 GitHub stars~925 tokensUpdated 9 days ago
    Auto-check passed
  • Delegate Grok

    instructa/agent-skills

    Delegate a bounded task from a Codex session to Grok 4.6 with xhigh reasoning in the same Herdr workspace, then wait for and collect the result.

    139 GitHub stars~951 tokensUpdated 9 days ago
    Auto-check passed

Works with

Categories

Questions about Package Security Check

What does Package Security Check do?

Run a reusable JavaScript supply-chain security baseline with pnpm-first hardening, release-age gating, lifecycle-script controls, exotic dependency checks, CI install checks, and optional incident…. Package Security Check is an agent skill from instructa/agent-skills. Run a reusable JavaScript supply-chain security baseline with pnpm-first hardening, release-age gating, lifecycle-script controls, exotic dependency checks, CI install checks, and optional incident IOC profiles.

When should I use Package Security Check?

Package Security Check fits situations like: tasks that involve Supply chain security.

How do I install Package Security Check in Claude Code?

Run `npx skills add instructa/agent-skills --skill package-security-check -a claude-code`. Or copy the skill folder (skills/security/package-security-check in instructa/agent-skills) into .claude/skills/package-security-check in your project. Claude Code loads it when a task matches its description.

How do I install Package Security Check in Codex?

Run `npx skills add instructa/agent-skills --skill package-security-check -a codex`. Or copy the skill folder (skills/security/package-security-check in instructa/agent-skills) into .agents/skills/package-security-check in your project. Codex loads it when a task matches its description.

Can I use Package Security Check in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add instructa/agent-skills --skill package-security-check -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/package-security-check, .gemini/skills/package-security-check, .github/skills/package-security-check and .opencode/skills/package-security-check in your project.

What does Package Security Check need to run?

Going by SKILL.md and its folder, Package Security Check needs Python for the scripts in its folder and the command-line tools its instructions call (npm, pnpm, python3, yarn and bun). Our summary lists: Python 3; Node.js.

Does Package Security Check access the network?

SKILL.md contains no URLs. Its commands use npm, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Package Security Check safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Package Security Check use?

No licence was found for Package Security Check or its repository. Without one, default copyright applies: ask the author before reusing or redistributing it.

How many tokens does Package Security Check use?

About 1.8k tokens (SKILL.md is roughly 7.3k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Package Security Check?

Skills that share tags, products or a category with Package Security Check: npm Supply Chain Security (bodadotsh/npm-security-best-practices, 859 stars), Check npm (grafana/skills, 278 stars), npm Supply Chain Check (majiayu000/spellbook, 286 stars) and Interlinked Supply Chain (QuentinCody/interlinked-cli, 178 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Package Security Check?

instructa (a GitHub organization) maintains it in instructa/agent-skills, which has 139 GitHub stars. The repository holds 17 skills in this directory. The repository was last updated on September 28, 2026.

Source: instructa/agent-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.