Agent skill

Supply Chain Hardening

by jamditis in jamditis/claude-skills-journalism

Install-time cooldowns for npm/bun plus a sandboxed pre-install scan for bypasses.

MITAuto-check: warningsSecurity

Install Supply Chain Hardening

The automated check flagged lines worth reading first. See the safety section below.

skills CLI
$ npx skills add jamditis/claude-skills-journalism --skill supply-chain-hardening -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install jamditis/claude-skills-journalism supply-chain-hardening --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/jamditis/claude-skills-journalism.git skills-src && mkdir -p .claude/skills && cp -r skills-src/security-toolkit/skills/supply-chain-hardening .claude/skills/supply-chain-hardening && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
supply-chain-hardening
GitHub stars
416
Token cost
~2k tokens
SKILL.md length
928 words
Files
2
Skills in repo
53
Repo updated
First seen
Licence
MIT

At a glance

Install-time cooldowns for npm/bun plus a sandboxed pre-install scan for bypasses.

  • Works in 3 steps: Install-time cooldown, only install… → Sandboxed pre-install scan, when the… → ignore-scripts at install, postinstall…
  • Supply-chain attacks
  • SKILL.md covers Configure the cooldown, Per-command bypass, When to scan before bypassing and What the cooldown does not catch, plus 3 more sections
  • Calls npm, bun and jq; needs GITHUB_TOKEN and AWS_SECRET

What it does

Supply Chain Hardening is an agent skill from jamditis/claude-skills-journalism. Install-time cooldowns for npm/bun plus a sandboxed pre-install scan for bypasses. Use for supply-chain attacks or npm security.

Its SKILL.md is about 2k tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files (for example `agents/openai.yaml`).

It sits in Security, covering Supply chain security. It works with npm and TanStack. The repository describes itself as: Claude Code skills for journalism, media, and academia - verification, FOIA, data journalism, academic writing, and more. The licence is MIT.

When your agent uses it

  • Supply-chain attacks
  • Tasks that involve Supply chain security

Example prompts

  • “/supply-chain-hardening”

Requirements

  • Node.js
  • A credential in GITHUB_TOKEN
  • A credential in AWS_SECRET

Workflow steps

3 steps, taken from the first numbered list in SKILL.md.

  1. Install-time cooldown, only install package versions older than N days (default 7). This is the primary defense. By the time the cooldown…
  2. Sandboxed pre-install scan, when the cooldown has to be bypassed (CVE patch, fresh dep, urgent install), run the candidate tarball through…
  3. ignore-scripts at install, postinstall is the #1 attack vector. Skip lifecycle scripts on every cooldown-bypass install.

What it can do on your machine

Read from SKILL.md and the folder at commit e3e2172. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • npm
    • bun
    • jq

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • github.com
    • stepsecurity.io
    • docs.npmjs.com
    • bun.com
    • osv.dev

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • GITHUB_TOKEN
    • AWS_SECRET

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Supply Chain Hardening loads about 2k tokens when it runs. Until then it costs about 38 tokens; SKILL.md has 928 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~38
When it runs · the whole SKILL.md, loaded when a task matches
~2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: warnings

The automated check found patterns that need a careful read before installing.

  • WarningMentions a credentials file (SSH keys, cloud or package-manager tokens)SKILL.md:24
    | npm | `~/.npmrc` (or project `.npmrc`) | `min-release-age` | days | none yet, proposed in [npm/cli#8994](https://githu
  • WarningMentions a credentials file (SSH keys, cloud or package-manager tokens)SKILL.md:30
    # ~/.npmrc
  • WarningMentions a credentials file (SSH keys, cloud or package-manager tokens)SKILL.md:74
    JS files referencing `.ssh/`, `.aws/`, `.npmrc`, `GITHUB_TOKEN`, `AWS_SECRET`, kube config | Credential exfiltration | Y
  • NoteRuns commands with sudoSKILL.md:91
    11: `npm --version`. If older, upgrade (`sudo npm i -g npm@latest` or tarball-swap if self-upgrade races).
  • WarningMentions a credentials file (SSH keys, cloud or package-manager tokens)SKILL.md:92
    2. Write `~/.npmrc` and `~/.bunfig.toml` with the config above.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from jamditis/claude-skills-journalism at commit e3e2172, republished under its MIT licence (© jamditis). 928 words, ~2,016 tokens.

Download SKILL.mdSave it as .claude/skills/supply-chain-hardening/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
supply-chain-hardening
description
Install-time cooldowns for npm/bun plus a sandboxed pre-install scan for bypasses. Use for supply-chain attacks or npm security.

Supply-chain hardening

Defends a journalism toolchain against the dominant npm/bun supply-chain attack pattern: a maintainer account or CI pipeline is compromised, a malicious version ships, and machines install it before anyone notices. Recent example: the Mini Shai-Hulud TanStack attack (2026-05-11) compromised 84 versions across 42 @tanstack/* packages and exfiltrated AWS / GCP / Vault / GitHub / SSH credentials via a postinstall script.

The defense is layered and intentionally simple:

  1. Install-time cooldown, only install package versions older than N days (default 7). This is the primary defense. By the time the cooldown expires, the security community has almost always flagged a compromised version and the registry has yanked it.
  2. Sandboxed pre-install scan, when the cooldown has to be bypassed (CVE patch, fresh dep, urgent install), run the candidate tarball through a static-analysis scan that looks for the diagnostic signatures of supply-chain malware. The scan runs inside bwrap/firejail/unshare so a malicious package can't escape the inspection.
  3. --ignore-scripts at install, postinstall is the #1 attack vector. Skip lifecycle scripts on every cooldown-bypass install.

These three together would have blocked the Mini Shai-Hulud TanStack attack on a stock laptop with no human in the loop.

Configure the cooldown

Verified config keys (npm v11+ and bun 1.3+):

ManagerFileKeyUnitsExclusion key
npm~/.npmrc (or project .npmrc)min-release-agedaysnone yet, proposed in npm/cli#8994
bun~/.bunfig.toml (or project bunfig.toml)[install] minimumReleaseAgeseconds[install] minimumReleaseAgeExcludes = [] (exact names, no globs)

Minimal config:

ini
# ~/.npmrc
min-release-age=7
toml
# ~/.bunfig.toml
[install]
minimumReleaseAge = 604800  # 7 days
minimumReleaseAgeExcludes = []

Requires npm 11+. Older npm silently ignores unknown keys, so the config looks correct but does nothing. Check with npm --version and npm config get min-release-age (should echo 7, not null).

Per-command bypass

When the cooldown blocks an install you actually want:

bash
npm install <pkg>@<version> --min-release-age=0 --ignore-scripts
bun add     <pkg>@<version> --minimum-release-age=0 --ignore-scripts

The bun add --minimum-release-age=0 CLI flag works in 1.3+ even though the docs don't list it, it follows bun's bunfig key → kebab-case flag convention.

Always pair the bypass with --ignore-scripts. Postinstall is the most common payload-execution path in supply-chain malware (Mini Shai-Hulud, event-stream, ua-parser-js, coa, all used it). Native modules that legitimately need postinstall can have the script run manually after a human-readable review:

bash
(cd node_modules/<pkg> && cat package.json | jq .scripts) # eyeball it
(cd node_modules/<pkg> && npm run postinstall)            # run if it checks out

When to scan before bypassing

The scan is for the dangerous moment: you've decided to bypass the cooldown and need a sanity check. The skill ships a reference script (scripts/hotpatch.example.sh) implementing the heuristics. Adapt it to your machine, Bash assumes bwrap (Linux); macOS users substitute sandbox-exec or skip the sandbox layer with the trade-off documented.

Static checks the scan should perform (each backed by a real attack):

CheckDiagnostic ofSeverity
optionalDependencies / dependencies containing github: or git+ URLsMini Shai-Hulud (delivered payload via github:tanstack/router#<sha> ref)RED
Large JS file at package root not referenced by main/module/exports/bin/filesPlanted payload pattern (router_init.js in Mini Shai-Hulud)RED
Unpacked size >3x the prior stable versionBulk payload smugglingRED
fileCount delta of 1–4 paired with >2x size jumpSingle planted fileRED
preinstall/install/postinstall/prepare scripts presentLifecycle-script attack vector (event-stream, ua-parser-js, etc.)YELLOW
JS files referencing .ssh/, .aws/, .npmrc, GITHUB_TOKEN, AWS_SECRET, kube configCredential exfiltrationYELLOW
Version flagged deprecated in npm registry with "security"/"compromised"/"malicious" wordingMaintainer/registry yankRED
OSV.dev returns known vulnerabilities for <pkg>@<version>Disclosed CVERED (severity-dependent)

Why prerelease versions are skipped from the size-delta baseline: dev/beta/rc versions have wildly different sizes than stable releases and produce false positives.

Show full SKILL.md (391 more words)Show less

What the cooldown does not catch

Be honest about the limits with whoever you're configuring this for:

  • Old packages with new malicious versions still in the cooldown window are blocked, but if the bad version also passes the cooldown (rare but possible, a compromise that goes >7 days undetected), the cooldown alone won't help. The scan catches most of those.
  • Transitive deps. A clean <pkg> you install can pull in a compromised transitive. Defenses: scan against the resolved tree (npm audit, osv-scanner), and keep the cooldown active globally so transitive resolution also waits.
  • npm ci against an existing lockfile. The cooldown applies during resolution, not installation of already-pinned versions. If your lockfile pins a compromised version, npm ci will install it. Mitigation: scan lockfiles in CI with osv-scanner --lockfile=package-lock.json.
  • Pre-existing compromised packages in node_modules. Hardening protects future installs, not past ones. Audit existing deps separately (npm audit, osv-scanner, manual review of recently-published deps in your tree).

Quick-start workflow for a new machine

  1. Verify npm >= 11: npm --version. If older, upgrade (sudo npm i -g npm@latest or tarball-swap if self-upgrade races).
  2. Write ~/.npmrc and ~/.bunfig.toml with the config above.
  3. Verify: npm config get min-release-age returns 7. cat ~/.bunfig.toml shows the [install] block.
  4. Copy scripts/hotpatch.example.sh to ~/.claude/hotpatch.sh (or wherever fits). Make executable. Run ./hotpatch.sh --self-test against the synthetic Mini Shai-Hulud fixture (also shipped) to confirm the heuristics fire.
  5. Document the bypass workflow somewhere your team will find it. The whole skill assumes the bypass is rare and reviewed, not the default.

Threat model: what this defends and what it doesn't

Defends againstDoesn't defend against
Maintainer account compromise (npm token theft)Targeted attack tailored to wait through the cooldown
CI/CD pipeline hijack (Mini Shai-Hulud, valid OIDC tokens, SLSA-attested malice)Compromise of a transitive dep already pinned in a lockfile
Typosquatting (lookalike package names), when paired with npm pkg fix and lockfile reviewMalicious code in your own dev dependencies that you authored
Postinstall payload execution (cooldown + --ignore-scripts = belt and suspenders)Runtime supply-chain attacks (e.g., dynamic loading of bad code from a CDN)
Drive-by npm install of a brand-new transitiveCompromise of the registry itself (very rare; out of scope)

Further reading

© jamditis, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file in security-toolkit/skills/supply-chain-hardening of jamditis/claude-skills-journalism.

  • SKILL.md
  • agents/openai.yaml

Open the folder on GitHubat commit e3e2172

Compare with similar skills

Supply Chain Hardening next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Supply Chain Hardening compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Supply Chain Hardening this skilljamditis/claude-skills-journalism416—~2kAutomated safety check: WarnMIT
npm Supply Chain Securitybodadotsh/npm-security-best-practices858—~1kAutomated safety check: WarnMIT
Dependency Update Auditbacknotprop/plannotator9.3k—~1.8kAutomated safety check: PassApache-2.0
Hol Guard Protectionhashgraph-online/hol-guard845—~605Automated safety check: PassApache-2.0
npm Supply Chain Checkmajiayu000/spellbook287—~1.5kAutomated safety check: PassMIT
Interlinked Supply ChainQuentinCody/interlinked-cli178—~2.8kAutomated safety check: PassMIT

Similar skills

  • npm Supply Chain Security

    bodadotsh/npm-security-best-practices

    Applies safer package manager defaults and dependency vetting to JavaScript and TypeScript projects to reduce supply-chain attack risk.

    858 GitHub stars~1k tokensUpdated 10 days ago
    SecurityAuto-check: warnings
  • Dependency Update Audit

    backnotprop/plannotator

    Audits outdated npm and Bun packages for supply chain integrity before bumping them, deferring risky ones and logging every decision.

    9.3k GitHub stars~1.8k tokensUpdated today
    SecurityAuto-check passed
  • Hol Guard Protection

    hashgraph-online/hol-guard

    Use HOL Guard to preview and protect AI-agent package installs, Cursor surfaces, CI, and automation workflows.

    845 GitHub stars~605 tokensUpdated today
    SecurityAuto-check passed
  • npm Supply Chain Check

    majiayu000/spellbook

    Scans a repository, its lockfiles and node_modules for known malicious npm package versions and install-time indicators, using a read-only Python scanner.

    287 GitHub stars~1.5k tokensUpdated 2 days ago
    SecurityAuto-check passed
  • Interlinked Supply Chain

    QuentinCody/interlinked-cli

    Respond to blocked package installs and manage the Interlinked supply-chain allowlist.

    178 GitHub stars~2.8k tokensUpdated yesterday
    SecurityAuto-check passed
  • Corpus Sweep

    nubjs/nub

    Run a large sharded measurement sweep over npm packages (the build-jail catalog probe, or any harness that installs thousands of package-versions and records a verdict per run).

    4.4k GitHub stars~2.4k tokensUpdated yesterday
    SecurityAuto-check passed

More from jamditis/claude-skills-journalism

All 53 skills in this repo
  • Web Design Picker

    jamditis/claude-skills-journalism

    A skill your agent uses when creating distinct website directions, a client review picker, asset catalog, previews, and Cloudflare-ready handoffs.

    416 GitHub stars~3.1k tokensUpdated 6 days ago
    Auto-check passed
  • Okf Wiki

    jamditis/claude-skills-journalism

    Builds an Open Knowledge Format (OKF) knowledge base from existing docs, notes, or a repo.

    416 GitHub stars~4.7k tokensUpdated 6 days ago
    Auto-check passed
  • Private Secret Scanning

    jamditis/claude-skills-journalism

    Local Gitleaks scans for staged changes, push ranges, and full history in private repos, with redacted reports.

    416 GitHub stars~1.8k tokensUpdated 6 days ago
    Auto-check passed
  • Data Journalism

    jamditis/claude-skills-journalism

    Acquire, clean, analyze, verify, visualize, and explain data for journalism.

    416 GitHub stars~1.6k tokensUpdated 6 days ago
    Auto-check passed
  • Document Design

    jamditis/claude-skills-journalism

    Creates print-ready HTML that exports to PDF. An agent skill from jamditis/claude-skills-journalism.

    416 GitHub stars~1.9k tokensUpdated 6 days ago
    Auto-check passed
  • Using Superjawn

    jamditis/claude-skills-journalism

    Establishes how to find and use skills, requiring Skill tool invocation before any response.

    416 GitHub stars~1.5k tokensUpdated 6 days ago
    Auto-check passed

Works with

Categories

Questions about Supply Chain Hardening

What does Supply Chain Hardening do?

Install-time cooldowns for npm/bun plus a sandboxed pre-install scan for bypasses. Supply Chain Hardening is an agent skill from jamditis/claude-skills-journalism. Install-time cooldowns for npm/bun plus a sandboxed pre-install scan for bypasses.

When should I use Supply Chain Hardening?

Supply Chain Hardening fits situations like: supply-chain attacks; tasks that involve Supply chain security.

How do I install Supply Chain Hardening in Claude Code?

Run `npx skills add jamditis/claude-skills-journalism --skill supply-chain-hardening -a claude-code`. Or copy the skill folder (security-toolkit/skills/supply-chain-hardening in jamditis/claude-skills-journalism) into .claude/skills/supply-chain-hardening in your project. Claude Code loads it when a task matches its description.

How do I install Supply Chain Hardening in Codex?

Run `npx skills add jamditis/claude-skills-journalism --skill supply-chain-hardening -a codex`. Or copy the skill folder (security-toolkit/skills/supply-chain-hardening in jamditis/claude-skills-journalism) into .agents/skills/supply-chain-hardening in your project. Codex loads it when a task matches its description.

Can I use Supply Chain Hardening in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add jamditis/claude-skills-journalism --skill supply-chain-hardening -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/supply-chain-hardening, .gemini/skills/supply-chain-hardening, .github/skills/supply-chain-hardening and .opencode/skills/supply-chain-hardening in your project.

What does Supply Chain Hardening need to run?

Going by SKILL.md and its folder, Supply Chain Hardening needs the command-line tools its instructions call (npm, bun and jq) and credentials named GITHUB_TOKEN and AWS_SECRET. Our summary lists: Node.js; A credential in GITHUB_TOKEN; A credential in AWS_SECRET.

Does Supply Chain Hardening access the network?

SKILL.md names 5 domains. As links in the text: github.com, stepsecurity.io, docs.npmjs.com, bun.com and osv.dev. This is read from the text; nothing was executed.

Is Supply Chain Hardening safe to install?

Our automated static check of SKILL.md flagged 4 warning(s): mentions a credentials file (ssh keys, cloud or package-manager tokens). Read the flagged lines before installing; the check is not a guarantee either way.

What licence does Supply Chain Hardening use?

Supply Chain Hardening is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Supply Chain Hardening use?

About 2k tokens (SKILL.md is roughly 8.1k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Supply Chain Hardening?

Skills that share tags, products or a category with Supply Chain Hardening: npm Supply Chain Security (bodadotsh/npm-security-best-practices, 858 stars), Dependency Update Audit (backnotprop/plannotator, 9.3k stars), Hol Guard Protection (hashgraph-online/hol-guard, 845 stars) and npm Supply Chain Check (majiayu000/spellbook, 287 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Supply Chain Hardening?

jamditis (a GitHub user) maintains it in jamditis/claude-skills-journalism, which has 416 GitHub stars. The repository holds 53 skills in this directory. The repository was last updated on October 4, 2026.

Source: jamditis/claude-skills-journalism on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.