npm Supply Chain Check
majiayu000/spellbook
Scans a repository, its lockfiles and node_modules for known malicious npm package versions and install-time indicators, using a read-only Python scanner.
Agent skill
by jeremylongshore in jeremylongshore/tons-of-skills-marketplace
Audit a Node.js project's installed npm dependency tree for known CVEs by wrapping the npm audit JSON output and emitting findings in the canonical penetration-tester schema.
$ npx skills add jeremylongshore/tons-of-skills-marketplace --skill auditing-npm-dependencies -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install jeremylongshore/tons-of-skills-marketplace auditing-npm-dependencies --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/jeremylongshore/tons-of-skills-marketplace.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/.curated/auditing-npm-dependencies .claude/skills/auditing-npm-dependencies && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "auditing-npm-dependencies" agent skill from https://github.com/jeremylongshore/tons-of-skills-marketplace/tree/main/skills/.curated/auditing-npm-dependencies into .claude/skills/auditing-npm-dependencies/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "auditing-npm-dependencies", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/jeremylongshore/tons-of-skills-marketplace/tree/main/skills/.curated/auditing-npm-dependenciesType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add jeremylongshore/tons-of-skills-marketplace --skill auditing-npm-dependencies -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install jeremylongshore/tons-of-skills-marketplace auditing-npm-dependencies --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/jeremylongshore/tons-of-skills-marketplace.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/.curated/auditing-npm-dependencies .agents/skills/auditing-npm-dependencies && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "auditing-npm-dependencies" agent skill from https://github.com/jeremylongshore/tons-of-skills-marketplace/tree/main/skills/.curated/auditing-npm-dependencies into .agents/skills/auditing-npm-dependencies/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "auditing-npm-dependencies", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add jeremylongshore/tons-of-skills-marketplace --skill auditing-npm-dependencies -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install jeremylongshore/tons-of-skills-marketplace auditing-npm-dependencies --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/jeremylongshore/tons-of-skills-marketplace.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/.curated/auditing-npm-dependencies .cursor/skills/auditing-npm-dependencies && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "auditing-npm-dependencies" agent skill from https://github.com/jeremylongshore/tons-of-skills-marketplace/tree/main/skills/.curated/auditing-npm-dependencies into .cursor/skills/auditing-npm-dependencies/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "auditing-npm-dependencies", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/jeremylongshore/tons-of-skills-marketplace.git --path skills/.curated/auditing-npm-dependencies--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add jeremylongshore/tons-of-skills-marketplace --skill auditing-npm-dependencies -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install jeremylongshore/tons-of-skills-marketplace auditing-npm-dependencies --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/jeremylongshore/tons-of-skills-marketplace.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/.curated/auditing-npm-dependencies .gemini/skills/auditing-npm-dependencies && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "auditing-npm-dependencies" agent skill from https://github.com/jeremylongshore/tons-of-skills-marketplace/tree/main/skills/.curated/auditing-npm-dependencies into .gemini/skills/auditing-npm-dependencies/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "auditing-npm-dependencies", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install jeremylongshore/tons-of-skills-marketplace auditing-npm-dependenciesInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add jeremylongshore/tons-of-skills-marketplace --skill auditing-npm-dependencies -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/jeremylongshore/tons-of-skills-marketplace.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/.curated/auditing-npm-dependencies .github/skills/auditing-npm-dependencies && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "auditing-npm-dependencies" agent skill from https://github.com/jeremylongshore/tons-of-skills-marketplace/tree/main/skills/.curated/auditing-npm-dependencies into .github/skills/auditing-npm-dependencies/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "auditing-npm-dependencies", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add jeremylongshore/tons-of-skills-marketplace --skill auditing-npm-dependencies -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install jeremylongshore/tons-of-skills-marketplace auditing-npm-dependencies --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/jeremylongshore/tons-of-skills-marketplace.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/.curated/auditing-npm-dependencies .opencode/skills/auditing-npm-dependencies && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "auditing-npm-dependencies" agent skill from https://github.com/jeremylongshore/tons-of-skills-marketplace/tree/main/skills/.curated/auditing-npm-dependencies into .opencode/skills/auditing-npm-dependencies/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "auditing-npm-dependencies", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
auditing-npm-dependenciesAudit a Node.js project's installed npm dependency tree for known CVEs by wrapping the npm audit JSON output and emitting findings in the canonical penetration-tester schema.
Auditing npm Dependencies is an agent skill from jeremylongshore/tons-of-skills-marketplace. Audit a Node.js project's installed npm dependency tree for known CVEs by wrapping the npm audit JSON output and emitting findings in the canonical penetration-tester schema. Detects direct AND transitive vulnerabilities, normalizes npm's severity scale (info/low/moderate/ high/critical) to the shared Severity enum, and parses both v1 and v2 audit output formats so the skill works against npm 6 and npm 7+ lockfiles. Use when: pre-merge gate on a Node project, post-incident sweep after a transitive package…
Its SKILL.md is about 2.5k tokens, which your agent loads only when the skill is triggered. The skill folder holds 5 other files, including scripts and reference files (for example `references/PLAYBOOK.md`, `references/THEORY.md` and `scripts/audit_npm.py`). Compatibility notes: Designed for Claude Code
It sits in Security, covering Dependency management, Vulnerability scanning and Digital forensics. It works with npm and Node.js. The repository describes itself as: Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com. The licence is MIT.
4 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit cfae287. It shows what the files ask for, not the result of running them.
Pre-approves these tools, so the agent can use them without asking each time:
ReadBash(npm:*)Bash(python3:*)GlobFrom allowed-tools in the SKILL.md frontmatter.
Ships 1 file in scripts/ (Python), which the agent can run.
Shell commands in SKILL.md call:
npmpython3jqFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use npm, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Designed for Claude Code
From compatibility in the SKILL.md frontmatter.
Auditing npm Dependencies loads about 2.5k tokens when it runs, and up to ~5.2k if it reads all its reference files. Until then it costs about 227 tokens; SKILL.md has 997 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check noted patterns worth knowing about, such as sudo or a known installer.
- Write(.env)- Edit(.env)Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.
The full file from jeremylongshore/tons-of-skills-marketplace at commit cfae287, republished under its MIT licence (© jeremylongshore). 997 words, ~2,473 tokens.
.claude/skills/auditing-npm-dependencies/SKILL.md (or your agent's skills folder). This skill also uses 3 other files; get the full folder from GitHub.Modern Node.js applications pull in hundreds of transitive packages
through a single npm install. The ratio of direct-to-transitive
dependencies on a typical app is around 1:50 — install 30 packages,
end up with 1,500. Every one of those packages can ship a CVE, get
maintainer-takeover-attacked, or contain a typosquatted near-name
package that someone slipped into your lockfile.
The published-CVE feed for npm is among the busiest in the ecosystem
because the registry is shared, public, and trivially installable.
npm audit queries the same advisory database GitHub's Dependabot
uses, returning per-package vulnerability records with CVE ID,
severity, affected version range, and fix-available version. Running
it is free and fast; the friction is interpreting the output and
deciding which findings actually block your release.
This skill standardizes that interpretation. It wraps npm audit --json, parses both the v1 (npm 6) and v2 (npm 7+) output shapes,
maps npm's severity vocabulary to the shared Severity enum, and
emits Findings in the canonical penetration-tester JSON shape so
downstream tooling (CI gates, security dashboards, SOC2 evidence
collection) gets uniform records regardless of which package
manager surfaced them.
| Finding | Severity | Threshold | Affected control |
|---|---|---|---|
| Critical CVE in direct dep | CRITICAL | npm severity: critical AND package in dependencies of root package.json | CWE-1104 |
| Critical CVE in transitive dep | CRITICAL | npm severity: critical AND package NOT in root dependencies | CWE-1104 |
| High CVE in direct dep | HIGH | npm severity: high AND direct | CWE-1104 |
| High CVE in transitive dep | HIGH | npm severity: high AND transitive | CWE-1104 |
| Moderate CVE | MEDIUM | npm severity: moderate | CWE-1104 |
| Low CVE | LOW | npm severity: low | CWE-1104 |
| Info advisory | INFO | npm severity: info | CWE-1104 |
| Vulnerable package with no patch | HIGH | finding has no fix.available and severity ≥ moderate | CWE-1395 |
| Audit registry unreachable | INFO | npm exits non-zero with network error | (operational) |
| Audit returns malformed output | INFO | JSON parse fails on npm audit --json stdout | (operational) |
Direct vs transitive matters: a CVE in lodash you require directly
is fixable by upgrading your package.json. A CVE in lodash pulled
in transitively through aws-sdk requires either upgrading aws-sdk
to a version with a newer lodash floor, or pinning via overrides
in your root package.json.
package.json and at minimum
one of package-lock.json, npm-shrinkwrap.jsonregistry.npmjs.org by default)Locate the project directory. The scanner expects package.json at
the directory root. Monorepos with multiple package.json files
should be scanned per package; the scanner does not auto-traverse
workspaces (use npm audit --workspaces separately for that case).
python3 ./scripts/audit_npm.py /path/to/node-projectOptions:
Usage: audit_npm.py PATH [OPTIONS]
Options:
--output FILE Write findings to FILE (default: stdout)
--format FMT json | jsonl | markdown (default: markdown)
--min-severity SEV (default: info)
--include-dev Audit `devDependencies` too (default: prod only)
--no-cache Pass --no-audit-cache to npm (slower; fresh data)
--json-only Print raw `npm audit --json` and exit (debug)The scanner shells out to npm audit --json in the target directory,
parses the output, deduplicates per-CVE across direct and transitive
paths, and emits one Finding per CVE.
CRITICAL / HIGH = block the release. Either bump the vulnerable
package to the fix version (most common), or apply an npm overrides
entry if the transitive dep can't be reached through a parent bump.
MEDIUM / LOW = file a remediation ticket but don't block. These often require waiting for the upstream maintainer to ship a fix.
INFO = log only. Informational advisories sometimes flag deprecated packages without an active vulnerability.
For a CVE in a DIRECT dep:
npm audit fix — npm attempts a non-breaking upgrade.npm audit fix says "requires manual review" (semver-major
bump), evaluate the breaking changes and decide whether to upgrade
or accept the risk. Document the decision.package-lock.json; commit the diff.For a CVE in a TRANSITIVE dep:
Identify the path: npm ls <vulnerable-package> shows which
parent(s) pull it in.
Check whether bumping the parent picks up the fix: npm view <parent> dependencies lists the parent's declared range.
If parent has a newer version that floors the vulnerable dep above the fix-version, upgrade the parent.
Otherwise add an overrides block in your root package.json:
"overrides": {
"<vulnerable-package>": "<fix-version>"
}This requires npm 8.3+ and forces the resolution. Document why you're overriding — overrides are easy to forget about.
For a CVE with NO fix available:
python3 ./scripts/audit_npm.py . --min-severity high --format json --output npm-audit.json
jq -e '. == []' npm-audit.json || { echo "High/critical npm CVE — fix before merge"; exit 1; }- name: npm dependency audit
run: |
python3 plugins/security/penetration-tester/skills/auditing-npm-dependencies/scripts/audit_npm.py \
. --min-severity high --format markdown --output npm-audit.md
- name: Upload audit
uses: actions/upload-artifact@v4
with:
name: npm-audit
path: npm-audit.mdpython3 ./scripts/audit_npm.py . --include-dev --no-cache --format json \
--output evidence/CC7-npm-audit-$(date +%Y%m%d).json--include-dev is important for SOC2 evidence: auditors want the
full picture, not just production deps. --no-cache ensures the
evidence reflects current advisory data, not yesterday's cache.
JSON / JSONL / Markdown per lib/report.py. Exit codes: 0 clean, 1
high/critical, 2 error.
Each Finding includes:
id — synthesized as npm-audit::<cve-id> (or npm-audit::<advisory-id> when no CVE assigned)severity — CRITICAL / HIGH / MEDIUM / LOW / INFOcategory — dependency-vulnerabilitysummary — short CVE titleevidence — affected package, affected version range, fix version (if any), dependency pathreferences — GHSA URL, CVE URL, npm advisory URLpackage.json → exits 2 with "target is not a Node project"
error.npm cache clean --force and retry.package.json → npm warns and
may produce partial results; the scanner emits an INFO Finding
flagging the desync and proceeds with whatever data npm returns.references/THEORY.md — Why npm's dependency graph is the largest
CVE surface in modern software, history of npm supply-chain attacks
(event-stream, ua-parser-js, color.js, node-ipc), direct-vs-transitive
remediation theory, when overrides are safe, npm audit v1 vs v2
output schema diffreferences/PLAYBOOK.md — Per-runtime remediation patterns
(frontend webpack/vite, Node server, Electron desktop, Lambda),
parent-bump decision matrix, override-block templates, GitHub
Dependabot integration, SOC2 evidence retention policy© jeremylongshore, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 3 other files (scripts, references) in skills/.curated/auditing-npm-dependencies of jeremylongshore/tons-of-skills-marketplace.
Open the folder on GitHubat commit cfae287
Auditing npm Dependencies next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Auditing npm Dependencies this skilljeremylongshore/tons-of-skills-marketplace | 2.8k | — | ~2.5k | Automated safety check: Notes | MIT | |
| npm Supply Chain Checkmajiayu000/spellbook | 287 | — | ~1.5k | Automated safety check: Pass | MIT | |
| Dep Securitytinyfish-io/tinyfish-cookbook | 2.2k | — | ~2.4k | Automated safety check: Pass | MIT | |
| Cve Scansoftspark/ai-toolkit | 180 | — | ~1.3k | Automated safety check: Notes | Apache-2.0 | |
| Sca AuditOWASP/secure-agent-playbook | 188 | — | ~494 | Automated safety check: Pass | CC-BY-4.0 | |
| Dependency Scanjwynia/agent-skills | 170 | — | ~1.7k | Automated safety check: Pass | MIT |
majiayu000/spellbook
Scans a repository, its lockfiles and node_modules for known malicious npm package versions and install-time indicators, using a read-only Python scanner.
tinyfish-io/tinyfish-cookbook
Check every dependency in a package.json against live CVE databases and security advisories in real time — specifically targeting vulnerabilities disclosed in the last 48 hours, the window that…
softspark/ai-toolkit
Scans deps for known CVEs via native audit (npm, pip, composer, cargo, go, bundler, dart).
OWASP/secure-agent-playbook
Scan project dependencies for known vulnerabilities (CVEs). An agent skill from OWASP/secure-agent-playbook.
jwynia/agent-skills
Detect CVEs and security issues in project dependencies. An agent skill from jwynia/agent-skills.
infometa/workbuddyskills
容器安全CVE漏洞修复验证引擎。从容器漏扫报告(Excel)自动提取漏洞,生成修复计划, SSH到测试环境验证OS包(apt/yum/apk)、Python(pip)、Node.js(npm)、Java(JAR)四种包类型的 修复方案,产出修复验证报告。不涉及主机层漏洞修复、不处理容器编排层安全配置。
jeremylongshore/tons-of-skills-marketplace
Execute this skill enables AI assistant to conduct a security-focused code review using the security-agent plugin.
jeremylongshore/tons-of-skills-marketplace
Build this skill automates the adaptation of pre-trained machine learning models using transfer learning techniques.
jeremylongshore/tons-of-skills-marketplace
Execute proactive auto-loading: automatically detects and loads agents.md files.
jeremylongshore/tons-of-skills-marketplace
Aggregate and centralize performance metrics from applications, systems, databases, caches, and services.
jeremylongshore/tons-of-skills-marketplace
Execute this skill enables AI assistant to analyze capacity requirements and plan for future growth.
jeremylongshore/tons-of-skills-marketplace
Process use when you need to work with database indexing. An agent skill from jeremylongshore/tons-of-skills-marketplace.
Categories
Audit a Node.js project's installed npm dependency tree for known CVEs by wrapping the npm audit JSON output and emitting findings in the canonical penetration-tester schema. Auditing npm Dependencies is an agent skill from jeremylongshore/tons-of-skills-marketplace.js project's installed npm dependency tree for known CVEs by wrapping the npm audit JSON output and emitting findings in the canonical penetration-tester schema.
Auditing npm Dependencies fits situations like: : pre-merge gate on a Node project; post-incident sweep after a transitive package compromise (e.g; with: audit npm deps; npm vulnerability scan.
Run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill auditing-npm-dependencies -a claude-code`. Or copy the skill folder (skills/.curated/auditing-npm-dependencies in jeremylongshore/tons-of-skills-marketplace) into .claude/skills/auditing-npm-dependencies in your project. Claude Code loads it when a task matches its description.
Run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill auditing-npm-dependencies -a codex`. Or copy the skill folder (skills/.curated/auditing-npm-dependencies in jeremylongshore/tons-of-skills-marketplace) into .agents/skills/auditing-npm-dependencies in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill auditing-npm-dependencies -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/auditing-npm-dependencies, .gemini/skills/auditing-npm-dependencies, .github/skills/auditing-npm-dependencies and .opencode/skills/auditing-npm-dependencies in your project.
Going by SKILL.md and its folder, Auditing npm Dependencies needs Python for the scripts in its folder and the command-line tools its instructions call (npm, python3 and jq). Our summary lists: Python 3; Node.js. Its frontmatter pre-approves these tools: Read, Bash(npm:*), Bash(python3:*), Glob. Compatibility (from SKILL.md): Designed for Claude Code.
SKILL.md contains no URLs. Its commands use npm, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found notes only (mentions a .env file), nothing it rates as a warning. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.
Auditing npm Dependencies is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.
About 2.5k tokens (SKILL.md is roughly 9.9k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 2.7k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Auditing npm Dependencies: npm Supply Chain Check (majiayu000/spellbook, 287 stars), Dep Security (tinyfish-io/tinyfish-cookbook, 2.2k stars), Cve Scan (softspark/ai-toolkit, 180 stars) and Sca Audit (OWASP/secure-agent-playbook, 188 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
jeremylongshore (a GitHub user) maintains it in jeremylongshore/tons-of-skills-marketplace, which has 2,827 GitHub stars. The repository holds 3,342 skills in this directory. The repository was last updated on October 10, 2026.
Source: jeremylongshore/tons-of-skills-marketplace on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.