npm Supply Chain Check
majiayu000/spellbook
Scans a repository, its lockfiles and node_modules for known malicious npm package versions and install-time indicators, using a read-only Python scanner.
Agent skill
by jeremylongshore in jeremylongshore/tons-of-skills-marketplace
Build a dependency-tree map of a project (npm or Python) and trace the path from each known-vulnerable transitive package back to one or more direct dependencies.
$ npx skills add jeremylongshore/tons-of-skills-marketplace --skill tracing-transitive-vulnerabilities -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install jeremylongshore/tons-of-skills-marketplace tracing-transitive-vulnerabilities --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/jeremylongshore/tons-of-skills-marketplace.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/.curated/tracing-transitive-vulnerabilities .claude/skills/tracing-transitive-vulnerabilities && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "tracing-transitive-vulnerabilities" agent skill from https://github.com/jeremylongshore/tons-of-skills-marketplace/tree/main/skills/.curated/tracing-transitive-vulnerabilities into .claude/skills/tracing-transitive-vulnerabilities/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "tracing-transitive-vulnerabilities", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/jeremylongshore/tons-of-skills-marketplace/tree/main/skills/.curated/tracing-transitive-vulnerabilitiesType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add jeremylongshore/tons-of-skills-marketplace --skill tracing-transitive-vulnerabilities -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install jeremylongshore/tons-of-skills-marketplace tracing-transitive-vulnerabilities --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/jeremylongshore/tons-of-skills-marketplace.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/.curated/tracing-transitive-vulnerabilities .agents/skills/tracing-transitive-vulnerabilities && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "tracing-transitive-vulnerabilities" agent skill from https://github.com/jeremylongshore/tons-of-skills-marketplace/tree/main/skills/.curated/tracing-transitive-vulnerabilities into .agents/skills/tracing-transitive-vulnerabilities/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "tracing-transitive-vulnerabilities", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add jeremylongshore/tons-of-skills-marketplace --skill tracing-transitive-vulnerabilities -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install jeremylongshore/tons-of-skills-marketplace tracing-transitive-vulnerabilities --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/jeremylongshore/tons-of-skills-marketplace.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/.curated/tracing-transitive-vulnerabilities .cursor/skills/tracing-transitive-vulnerabilities && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "tracing-transitive-vulnerabilities" agent skill from https://github.com/jeremylongshore/tons-of-skills-marketplace/tree/main/skills/.curated/tracing-transitive-vulnerabilities into .cursor/skills/tracing-transitive-vulnerabilities/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "tracing-transitive-vulnerabilities", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/jeremylongshore/tons-of-skills-marketplace.git --path skills/.curated/tracing-transitive-vulnerabilities--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add jeremylongshore/tons-of-skills-marketplace --skill tracing-transitive-vulnerabilities -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install jeremylongshore/tons-of-skills-marketplace tracing-transitive-vulnerabilities --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/jeremylongshore/tons-of-skills-marketplace.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/.curated/tracing-transitive-vulnerabilities .gemini/skills/tracing-transitive-vulnerabilities && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "tracing-transitive-vulnerabilities" agent skill from https://github.com/jeremylongshore/tons-of-skills-marketplace/tree/main/skills/.curated/tracing-transitive-vulnerabilities into .gemini/skills/tracing-transitive-vulnerabilities/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "tracing-transitive-vulnerabilities", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install jeremylongshore/tons-of-skills-marketplace tracing-transitive-vulnerabilitiesInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add jeremylongshore/tons-of-skills-marketplace --skill tracing-transitive-vulnerabilities -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/jeremylongshore/tons-of-skills-marketplace.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/.curated/tracing-transitive-vulnerabilities .github/skills/tracing-transitive-vulnerabilities && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "tracing-transitive-vulnerabilities" agent skill from https://github.com/jeremylongshore/tons-of-skills-marketplace/tree/main/skills/.curated/tracing-transitive-vulnerabilities into .github/skills/tracing-transitive-vulnerabilities/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "tracing-transitive-vulnerabilities", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add jeremylongshore/tons-of-skills-marketplace --skill tracing-transitive-vulnerabilities -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install jeremylongshore/tons-of-skills-marketplace tracing-transitive-vulnerabilities --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/jeremylongshore/tons-of-skills-marketplace.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/.curated/tracing-transitive-vulnerabilities .opencode/skills/tracing-transitive-vulnerabilities && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "tracing-transitive-vulnerabilities" agent skill from https://github.com/jeremylongshore/tons-of-skills-marketplace/tree/main/skills/.curated/tracing-transitive-vulnerabilities into .opencode/skills/tracing-transitive-vulnerabilities/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "tracing-transitive-vulnerabilities", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
tracing-transitive-vulnerabilitiesBuild a dependency-tree map of a project (npm or Python) and trace the path from each known-vulnerable transitive package back to one or more direct dependencies.
Tracing Transitive Vulnerabilities is an agent skill from jeremylongshore/tons-of-skills-marketplace. Build a dependency-tree map of a project (npm or Python) and trace the path from each known-vulnerable transitive package back to one or more direct dependencies. Identifies which direct-dep bump would clear the most findings at once (highest-leverage upgrade), which vulnerabilities are unreachable through any version bump and require overrides or vendor-patch, and which CVEs sit at deep transitive depth (3+ levels from a direct dep) where blast-radius triage is hardest. Use when: a multi-finding audit produces…
Its SKILL.md is about 2.2k tokens, which your agent loads only when the skill is triggered. The skill folder holds 5 other files, including scripts and reference files (for example `references/PLAYBOOK.md`, `references/THEORY.md` and `scripts/trace_vulns.py`). Compatibility notes: Designed for Claude Code
It sits in Security, covering Vulnerability scanning and Supply chain security. It works with npm and Python. The repository describes itself as: Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com. The licence is MIT.
5 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit cfae287. It shows what the files ask for, not the result of running them.
Pre-approves these tools, so the agent can use them without asking each time:
ReadBash(npm:*)Bash(pip:*)Bash(pip-audit:*)Bash(python3:*)Bash(pipdeptree:*)GlobFrom allowed-tools in the SKILL.md frontmatter.
Ships 1 file in scripts/ (Python), which the agent can run.
Shell commands in SKILL.md call:
python3pipnpmjqFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use pip and npm, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Designed for Claude Code
From compatibility in the SKILL.md frontmatter.
Tracing Transitive Vulnerabilities loads about 2.2k tokens when it runs, and up to ~5.4k if it reads all its reference files. Until then it costs about 257 tokens; SKILL.md has 834 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check noted patterns worth knowing about, such as sudo or a known installer.
- Write(.env)- Edit(.env)Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.
The full file from jeremylongshore/tons-of-skills-marketplace at commit cfae287, republished under its MIT licence (© jeremylongshore). 834 words, ~2,168 tokens.
.claude/skills/tracing-transitive-vulnerabilities/SKILL.md (or your agent's skills folder). This skill also uses 3 other files; get the full folder from GitHub.The auditing-npm-dependencies and auditing-python-dependencies skills each surface CVEs, but they don't answer the question that actually decides remediation order: which of these findings can I clear by bumping ONE direct dep, and which require deeper intervention?
That question is the core of supply-chain triage. A high-CVSS CVE
in lodash@4.17.4 is alarming on first read. If it's pulled in by
five different direct deps, the right fix may not be to bump any of
them — it may be a single root-level overrides entry pinning
lodash@^4.17.21. The triage discussion goes very differently when
you can quote: "this CVE is reachable via 5 paths, all of which
flow through webpack, which has a fixed version available." That
shifts a project-wide panic to a one-line PR.
This skill walks the project's dependency graph (via npm ls,
pipdeptree, or equivalent), intersects it with the CVE findings
already produced by the per-language audit skills, and emits a
trace report that includes:
| Finding | Severity | Threshold | Affected control |
|---|---|---|---|
| Critical CVE at deep transitive depth (≥3) | HIGH | Depth ≥3 + severity CRITICAL — blast radius unclear | CWE-1395 |
| High CVE reachable only via overrides | HIGH | No direct-dep version clears the finding | CWE-1395 |
| Multi-CVE direct-dep hotspot | MEDIUM | Single direct dep is ancestor for ≥3 separate CVEs | (informational) |
| Direct-dep bump clears N findings | INFO | Reports the recommended bump | (operational) |
| Unreachable CVE (no fix in any reachable version) | HIGH | Finding has no fix-available across the whole graph | CWE-1395 |
| Circular dep with CVE | MEDIUM | Cycle in the dep graph involves a vulnerable package | (operational) |
pipdeptree (optional but recommended for Python; falls back to
pip show chains if absent — slower but works)The skill auto-detects whether the project is npm-flavored
(package.json + node_modules) or Python-flavored
(pyproject.toml / requirements.txt / installed venv).
The skill can run the per-language audit itself, or consume a pre-produced audit JSON:
# Self-running mode
python3 ./scripts/trace_vulns.py /path/to/project
# Pre-produced mode (faster on re-runs)
python3 plugins/security/penetration-tester/skills/auditing-npm-dependencies/scripts/audit_npm.py \
/path/to/project --format json --output /tmp/audit.json
python3 ./scripts/trace_vulns.py /path/to/project --audit-input /tmp/audit.jsonFor npm, the skill calls npm ls --json --all to enumerate the
full installed tree. For Python, it calls pipdeptree --json-tree
or falls back to recursive pip show.
The resulting graph is intersected with the per-package CVE findings, producing a path list for each vulnerability.
The report ranks findings by:
For each direct dep, the report aggregates:
Use the "highest-leverage upgrade" recommendation as the first PR. Then re-run this skill against the post-upgrade state to confirm how many findings dropped. Iterate until the residual is overrides / vendor work only.
# Run base audit
python3 plugins/security/penetration-tester/skills/auditing-npm-dependencies/scripts/audit_npm.py \
. --format json --output /tmp/npm-audit.json
# Trace
python3 ./scripts/trace_vulns.py . --audit-input /tmp/npm-audit.json \
--format markdown --output /tmp/trace.md/tmp/trace.md is human-readable: per-CVE path lists + recommended
bumps + leverage analysis.
python3 ./scripts/trace_vulns.py . --format json --leverage-only \
| jq '.[] | select(.cve_count >= 3)'Surfaces direct deps that, if bumped, would clear ≥3 CVEs at once.
python3 ./scripts/trace_vulns.py . --min-depth 3 --format markdown \
--output deep-trace.mdLimits output to findings at depth ≥3 from a direct dep — the hardest-to-triage class.
JSON / JSONL / Markdown per lib/report.py. Exit codes: 0 clean,
1 high/critical, 2 error.
Each Finding includes:
id — trace::<cve-id>::<vulnerable-package>severity — re-derived based on depth + reachabilitycategory — transitive-tracesummary — short description of the path situationevidence — original CVE, dep path(s), depth, parent direct-deps,
recommended bumpreferences — link back to the source audit findingA "leverage report" section in markdown output lists the top-N direct-dep bumps ranked by aggregate CVE-clearance count.
pip show recursion;
emits INFO finding recommending pipdeptree install for accuracy.references/THEORY.md — Why deep transitive deps are
disproportionately risky, dependency-graph traversal theory,
SBOM (Software Bill of Materials) standards (CycloneDX, SPDX
3.0), reachability theory for vulnerability analysis,
exploit-prediction-scoring-system (EPSS) integration plansreferences/PLAYBOOK.md — Per-runtime trace patterns, SBOM
generation patterns (cyclonedx-cli, syft, anchore), graph-based
upgrade planning, when to override vs vendor-patch, integration
with the per-language audit skills© jeremylongshore, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 3 other files (scripts, references) in skills/.curated/tracing-transitive-vulnerabilities of jeremylongshore/tons-of-skills-marketplace.
Open the folder on GitHubat commit cfae287
Tracing Transitive Vulnerabilities next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Tracing Transitive Vulnerabilities this skilljeremylongshore/tons-of-skills-marketplace | 2.8k | — | ~2.2k | Automated safety check: Notes | MIT | |
| npm Supply Chain Checkmajiayu000/spellbook | 287 | — | ~1.5k | Automated safety check: Pass | MIT | |
| Vulners API Python SDKvulnersCom/api | 376 | — | ~2.3k | Automated safety check: Pass | MIT | |
| Security AuditTheDecipherist/claude-code-mastery | 551 | — | ~1.3k | Automated safety check: Notes | MIT | |
| Cyber NeoHainrixz/cyber-neo | 283 | — | ~5.9k | Automated safety check: Warn | MIT | |
| Corpus Sweepnubjs/nub | 4.4k | — | ~2.4k | Automated safety check: Pass | MIT |
majiayu000/spellbook
Scans a repository, its lockfiles and node_modules for known malicious npm package versions and install-time indicators, using a read-only Python scanner.
vulnersCom/api
A skill your agent uses when modifying, testing, documenting, or reviewing the Vulners Python SDK.
TheDecipherist/claude-code-mastery
Checks a codebase for hardcoded secrets, vulnerable dependencies, weak input handling, weak authentication and unsafe transport settings before deployment or merge.
Hainrixz/cyber-neo
Comprehensive cybersecurity analysis for any local project. An agent skill from Hainrixz/cyber-neo.
nubjs/nub
Run a large sharded measurement sweep over npm packages (the build-jail catalog probe, or any harness that installs thousands of package-versions and records a verdict per run).
AgentSecOps/SecOpsAgentKit
Software Composition Analysis (SCA) and container vulnerability scanning using Aqua Trivy for identifying CVE vulnerabilities in dependencies, container images, IaC misconfigurations, and license…
jeremylongshore/tons-of-skills-marketplace
Execute this skill enables AI assistant to conduct a security-focused code review using the security-agent plugin.
jeremylongshore/tons-of-skills-marketplace
Build this skill automates the adaptation of pre-trained machine learning models using transfer learning techniques.
jeremylongshore/tons-of-skills-marketplace
Execute proactive auto-loading: automatically detects and loads agents.md files.
jeremylongshore/tons-of-skills-marketplace
Aggregate and centralize performance metrics from applications, systems, databases, caches, and services.
jeremylongshore/tons-of-skills-marketplace
Execute this skill enables AI assistant to analyze capacity requirements and plan for future growth.
jeremylongshore/tons-of-skills-marketplace
Process use when you need to work with database indexing. An agent skill from jeremylongshore/tons-of-skills-marketplace.
Categories
Build a dependency-tree map of a project (npm or Python) and trace the path from each known-vulnerable transitive package back to one or more direct dependencies. Tracing Transitive Vulnerabilities is an agent skill from jeremylongshore/tons-of-skills-marketplace. Build a dependency-tree map of a project (npm or Python) and trace the path from each known-vulnerable transitive package back to one or more direct dependencies.
Tracing Transitive Vulnerabilities fits situations like: : a multi-finding audit produces noise and you need to prioritize; planning a major dependency refresh; after an upstream package compromise hits your tree (e.g; with: trace transitive vulns.
Run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill tracing-transitive-vulnerabilities -a claude-code`. Or copy the skill folder (skills/.curated/tracing-transitive-vulnerabilities in jeremylongshore/tons-of-skills-marketplace) into .claude/skills/tracing-transitive-vulnerabilities in your project. Claude Code loads it when a task matches its description.
Run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill tracing-transitive-vulnerabilities -a codex`. Or copy the skill folder (skills/.curated/tracing-transitive-vulnerabilities in jeremylongshore/tons-of-skills-marketplace) into .agents/skills/tracing-transitive-vulnerabilities in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill tracing-transitive-vulnerabilities -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/tracing-transitive-vulnerabilities, .gemini/skills/tracing-transitive-vulnerabilities, .github/skills/tracing-transitive-vulnerabilities and .opencode/skills/tracing-transitive-vulnerabilities in your project.
Going by SKILL.md and its folder, Tracing Transitive Vulnerabilities needs Python for the scripts in its folder and the command-line tools its instructions call (python3, pip, npm and jq). Our summary lists: Python 3; Node.js. Its frontmatter pre-approves these tools: Read, Bash(npm:*), Bash(pip:*), Bash(pip-audit:*), Bash(python3:*), Bash(pipdeptree:*), Glob. Compatibility (from SKILL.md): Designed for Claude Code.
SKILL.md contains no URLs. Its commands use pip and npm, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found notes only (mentions a .env file), nothing it rates as a warning. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.
Tracing Transitive Vulnerabilities is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.
About 2.2k tokens (SKILL.md is roughly 8.7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 3.3k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Tracing Transitive Vulnerabilities: npm Supply Chain Check (majiayu000/spellbook, 287 stars), Vulners API Python SDK (vulnersCom/api, 376 stars), Security Audit (TheDecipherist/claude-code-mastery, 551 stars) and Cyber Neo (Hainrixz/cyber-neo, 283 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
jeremylongshore (a GitHub user) maintains it in jeremylongshore/tons-of-skills-marketplace, which has 2,827 GitHub stars. The repository holds 3,342 skills in this directory. The repository was last updated on October 10, 2026.
Source: jeremylongshore/tons-of-skills-marketplace on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.