Agent skill

Detecting Dependency Confusion

by mukul975 in mukul975/Anthropic-Cybersecurity-Skills

Detect and prevent dependency confusion (public-over-private package name resolution) in npm, PyPI, and Maven by enumerating claimable internal package names with tools like confused and OWASP…

Apache-2.0Auto-check: warningsSecurity

Install Detecting Dependency Confusion

The automated check flagged lines worth reading first. See the safety section below.

skills CLI
$ npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill detecting-dependency-confusion -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install mukul975/Anthropic-Cybersecurity-Skills detecting-dependency-confusion --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/mukul975/Anthropic-Cybersecurity-Skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/detecting-dependency-confusion .claude/skills/detecting-dependency-confusion && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
detecting-dependency-confusion
GitHub stars
34k
Token cost
~2.9k tokens
SKILL.md length
935 words
Files
5 (incl. scripts, references)
Skills in repo
644
Repo updated
First seen
Licence
Apache-2.0

At a glance

Detect and prevent dependency confusion (public-over-private package name resolution) in npm, PyPI, and Maven by enumerating claimable internal package names with tools like confused and OWASP…

  • Works in 10 steps: Inventory manifests across the codebase → Scan npm manifests with confused → Scan PyPI, Maven, Composer, and RubyGems… → …
  • Onboarding a repo to a supply-chain security program
  • SKILL.md covers Overview, When to Use, Prerequisites and Objectives, plus 4 more sections
  • Runs Python scripts from its folder; calls npm, curl and go; reaches registry.npmjs.org and pypi.org; needs NPM_TOKEN

What it does

Detecting Dependency Confusion is an agent skill from mukul975/Anthropic-Cybersecurity-Skills. Detect and prevent dependency confusion (public-over-private package name resolution) in npm, PyPI, and Maven by enumerating claimable internal package names with tools like confused and OWASP dep-scan, then enforcing source restrictions via .npmrc, pip.conf/pyproject.toml, and Maven settings.xml. Use when onboarding a repo to a supply-chain security program, auditing lockfiles/manifests for confusable dependencies, or after an incident that may have leaked internal package names.

Its SKILL.md is about 2.9k tokens, which your agent loads only when the skill is triggered. The skill folder holds 6 other files, including scripts and reference files (for example `references/api-reference.md`, `references/standards.md` and `scripts/agent.py`).

It sits in Security, covering Supply chain security and Web application vulnerabilities. It works with npm. The repository describes itself as: 817 structured cybersecurity skills for AI agents · Mapped to 6 frameworks: MITRE ATT&CK, NIST CSF 2.0, MITRE ATLAS, D3FEND, NIST AI RMF & MITRE F3 (Fight Fraud) · agentskills.io…. The licence is Apache-2.0.

When your agent uses it

  • Onboarding a repo to a supply-chain security program
  • Auditing lockfiles/manifests for confusable dependencies
  • After an incident that may have leaked internal package names

Example prompts

  • “/detecting-dependency-confusion”

Requirements

  • Python 3
  • Node.js
  • Docker
  • A credential in NPM_TOKEN

Workflow steps

10 steps, taken from the step headings in SKILL.md.

  1. Inventory manifests across the codebase
  2. Scan npm manifests with confused
  3. Scan PyPI, Maven, Composer, and RubyGems manifests
  4. Cross-check with OWASP dep-scan private-namespace mode
  5. Triage candidates and confirm claimability
  6. Remediate npm with scope-to-registry pinning
  7. Remediate PyPI and Maven
  8. Defensively register placeholder packages
  9. Wire detection into CI
  10. Run the bundled helper for batch triage

What it can do on your machine

Read from SKILL.md and the folder at commit 54a7988. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (Python), which the agent can run.

    Shell commands in SKILL.md call:

    • npm
    • curl
    • go
    • pip
    • python

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • registry.npmjs.org
    • pypi.org

    Also links to:

    • github.com
    • owasp.org
    • medium.com
    • docs.npmjs.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • NPM_TOKEN

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Detecting Dependency Confusion loads about 2.9k tokens when it runs, and up to ~3.9k if it reads all its reference files. Until then it costs about 132 tokens; SKILL.md has 935 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~132
When it runs · the whole SKILL.md, loaded when a task matches
~2.9k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~3.9k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: warnings

The automated check found patterns that need a careful read before installing.

  • WarningMentions a credentials file (SSH keys, cloud or package-manager tokens)SKILL.md:3
    then enforcing source restrictions via `.npmrc`, `pip.conf`/`pyproject.toml`, and Maven `settings.xml`. Use when onboard
  • WarningMentions a credentials file (SSH keys, cloud or package-manager tokens)SKILL.md:31
    , and enforcing source restrictions in `.npmrc`, `pip.conf`/`pyproject.toml`, and Maven `settings.xml`. Internal package
  • WarningMentions a credentials file (SSH keys, cloud or package-manager tokens)SKILL.md:53
    - Node.js + npm (for `.npmrc` and `npm config` remediation) and access to your private registry (Artifactory, Nexus, Azu
  • WarningMentions a credentials file (SSH keys, cloud or package-manager tokens)SKILL.md:135
    # .npmrc (project root, committed)
  • WarningMentions a credentials file (SSH keys, cloud or package-manager tokens)SKILL.md:220
    opes pinned to the private registry in `.npmrc` / `pip` config / Maven mirror.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from mukul975/Anthropic-Cybersecurity-Skills at commit 54a7988, republished under its Apache-2.0 licence (© mukul975). 935 words, ~2,945 tokens.

Download SKILL.mdSave it as .claude/skills/detecting-dependency-confusion/SKILL.md (or your agent's skills folder). This skill also uses 4 other files; get the full folder from GitHub.
name
detecting-dependency-confusion
description
Detect and prevent dependency confusion (public-over-private package name resolution) in npm, PyPI, and Maven by enumerating claimable internal package names with tools like `confused` and OWASP `dep-scan`, then enforcing source restrictions via `.npmrc`, `pip.conf`/`pyproject.toml`, and Maven `settings.xml`. Use when onboarding a repo to a supply-chain security program, auditing lockfiles/manifests for confusable dependencies, or after an incident that may have leaked internal package names.
domain
cybersecurity
subdomain
supply-chain-security
tags
supply-chain-security, dependency-confusion, npm, pypi, maven, package-management, devsecops, namespace-hijacking
version
1.0
author
mahipal
license
Apache-2.0
nist_csf
ID.RA-09
mitre_attack
T1195.001

Detecting Dependency Confusion

Legal Notice: This skill is for authorized security testing, defensive engineering, and educational purposes only. Registering or claiming package namespaces you do not own, or testing build pipelines without written authorization, may be illegal and may violate the terms of service of public registries. Only run namespace-claiming or resolution-testing activities against names and infrastructure you control or are explicitly authorized to assess.

Overview

Dependency confusion (also called a substitution or namespace-shadowing attack) was popularized by Alex Birsan in 2021 when he forced malicious code into the internal build systems of Apple, Microsoft, PayPal, and dozens of others. The root cause is that many package managers, when configured to resolve from both an internal/private registry and a public one, will prefer whichever copy has the higher version number rather than honoring the source. An attacker who learns the name of a private package (@acme/internal-utils, acme-billing-sdk) can publish a malicious package of the same name to the public registry (npmjs.com, PyPI, Maven Central) with a very high version (e.g. 99.0.0). When the victim's CI/CD runner or a developer machine resolves dependencies, it pulls the attacker's public package, executes its install scripts, and the supply chain is compromised.

This skill covers both halves of the problem: detection — enumerating internal package names that are not registered (squatted defensively) on public registries and are therefore claimable, using confused and OWASP dep-scan — and prevention — pinning scopes/namespaces to private registries, registering placeholder packages, and enforcing source restrictions in .npmrc, pip.conf/pyproject.toml, and Maven settings.xml. Internal package names leak constantly: in committed lockfiles, sourcemaps, public JS bundles, Docker layers, and error stack traces, so this is treated as an attack-surface management problem, not a one-time check.

When to Use

  • When onboarding a repository or organization to a supply-chain security program and you need to baseline which internal packages are claimable on public registries.
  • When CI/CD pipelines resolve dependencies from both private and public registries (mixed/hybrid feeds).
  • After any incident where internal package names may have been exposed (leaked source, public bundle, breached repo).
  • When auditing package.json, requirements.txt, pom.xml, composer.json, or Gemfile.lock files for confusable dependencies.
  • As a recurring scheduled control to detect newly added internal packages that have not yet been defensively registered.

Prerequisites

  • Go 1.20+ to install confused:
    bash
    go install github.com/visma-prodsec/confused@latest
    # binary lands in $(go env GOPATH)/bin/confused
  • Python 3.10+ for OWASP dep-scan:
    bash
    pip install owasp-depscan
    # or container: docker pull ghcr.io/owasp-dep-scan/dep-scan
  • Node.js + npm (for .npmrc and npm config remediation) and access to your private registry (Artifactory, Nexus, Azure Artifacts, GitHub Packages, AWS CodeArtifact).
  • Read access to the repositories / lockfiles being assessed and write access to your private registry for defensive registration.

Objectives

  • Enumerate every internal dependency declared in project manifests across npm, PyPI, Maven, Composer, and RubyGems.
  • Determine which internal names are not present on the corresponding public registry and are therefore claimable.
  • Distinguish true exposure from false positives (scoped packages, already-mirrored names).
  • Apply registry-pinning and scope-restriction controls that make public substitution impossible.
  • Defensively register placeholder packages for unclaimed internal names.
  • Establish a recurring detection control in CI to catch newly introduced confusable dependencies.

MITRE ATT&CK Mapping

Technique IDTechnique NameRelevance
T1195.001Supply Chain Compromise: Compromise Software Dependencies and Development ToolsCore technique — attacker substitutes a malicious public package for an internal dependency.
T1195.002Supply Chain Compromise: Compromise Software Supply ChainBroader category covering the compromised build artifacts produced once confusion succeeds.
T1059.007Command and Scripting Interpreter: JavaScriptnpm preinstall/postinstall lifecycle scripts execute attacker JavaScript on resolution.
T1071.001Application Layer Protocol: Web ProtocolsSubstituted package beacons stolen environment/credentials to attacker HTTP(S) endpoint.
Show full SKILL.md (365 more words)Show less

Workflow

1. Inventory manifests across the codebase

Locate every dependency manifest so nothing is missed.

bash
# Find all supported manifests in a monorepo
find . -type f \( \
  -name package.json -o \
  -name requirements.txt -o \
  -name pom.xml -o \
  -name composer.json -o \
  -name Gemfile.lock \
\) -not -path '*/node_modules/*' -print
2. Scan npm manifests with confused

confused reads the manifest and reports every dependency name not found on the public registry — those are candidates for confusion.

bash
# npm (default language is npm)
confused -l npm package.json

# Treat your known-good scopes as secure to suppress false positives (supports wildcards)
confused -l npm -s '@acme/*,@acme-internal/*' package.json

# Verbose, to see each lookup
confused -l npm -v package.json
3. Scan PyPI, Maven, Composer, and RubyGems manifests

The -l flag selects the ecosystem; each maps to its standard manifest file.

bash
confused -l pip requirements.txt          # PyPI  -> requirements.txt
confused -l mvn pom.xml                    # Maven -> pom.xml
confused -l composer composer.json        # PHP   -> composer.json
confused -l rubygems Gemfile.lock         # Ruby  -> Gemfile.lock
4. Cross-check with OWASP dep-scan private-namespace mode

dep-scan confirms confusion exposure for declared private namespaces and folds it into a broader risk audit.

bash
# Flag private namespaces accidentally claimable on public registries
depscan --src $PWD --reports-dir ./reports \
  --private-ns acme,acme_internal,@acme

# Enable deep package risk audit (npm + pypi): typosquats, takeover risk, etc.
depscan --src $PWD --reports-dir ./reports --risk-audit
5. Triage candidates and confirm claimability

For each flagged name, verify it is genuinely absent on the public registry (a 404 means claimable).

bash
# npm: a 404 status means the name is unregistered on the public registry
curl -s -o /dev/null -w "%{http_code}\n" https://registry.npmjs.org/@acme%2finternal-utils

# PyPI: 404 from the JSON API means the project name is free
curl -s -o /dev/null -w "%{http_code}\n" https://pypi.org/pypi/acme-billing-sdk/json
6. Remediate npm with scope-to-registry pinning

Bind every internal scope to the private registry so a public package of the same name can never be resolved.

ini
# .npmrc (project root, committed)
@acme:registry=https://artifactory.example.com/api/npm/npm-internal/
//artifactory.example.com/api/npm/npm-internal/:_authToken=${NPM_TOKEN}

# Force the default registry to a single proxy that does NOT merge public + private
registry=https://artifactory.example.com/api/npm/npm-virtual/

Verify the resolution source before installing:

bash
npm config get @acme:registry
npm install --dry-run   # confirm @acme/* resolves from the private host
7. Remediate PyPI and Maven

Pin Python index resolution and Maven mirroring so public sources cannot shadow internal artifacts.

toml
# pyproject.toml (PEP 621 / pip >= 23): explicit index pinning
[tool.pip]
index-url = "https://artifactory.example.com/api/pypi/pypi-internal/simple/"
# Do NOT use extra-index-url for internal packages — pip merges and picks highest version.
xml
<!-- ~/.m2/settings.xml: mirror everything through a single virtual repo -->
<mirrors>
  <mirror>
    <id>internal-virtual</id>
    <mirrorOf>*</mirrorOf>
    <url>https://artifactory.example.com/artifactory/maven-virtual</url>
  </mirror>
</mirrors>
8. Defensively register placeholder packages

For names you cannot fully isolate, claim the public name yourself with an empty, non-functional placeholder so an attacker cannot.

bash
# npm placeholder claim (scoped, public)
mkdir acme-internal-utils && cd acme-internal-utils
npm init -y
npm pkg set version=0.0.1-placeholder description="Reserved internal name. Do not use."
npm publish --access public
9. Wire detection into CI

Fail the pipeline if any new confusable dependency appears.

yaml
# .github/workflows/depconfusion.yml
name: dependency-confusion
on: [push, pull_request]
jobs:
  confused:
    runs-on: ubuntu-latest
    steps:
      - uses: actions/checkout@v4
      - uses: actions/setup-go@v5
        with: { go-version: '1.22' }
      - run: go install github.com/visma-prodsec/confused@latest
      - name: Scan npm manifest
        run: $(go env GOPATH)/bin/confused -l npm -s '@acme/*' package.json
10. Run the bundled helper for batch triage

Use the included agent.py to scan a tree and emit a structured report combining confused and live registry probes.

bash
python scripts/agent.py --path . --ecosystem npm \
  --secure-namespaces '@acme/*,@acme-internal/*' \
  --output report.json

Tools and Resources

ToolPurposeSource
confusedDetect lingering free namespaces for declared dependencieshttps://github.com/visma-prodsec/confused
ConfusedDotnetSame check for NuGet/.NEThttps://github.com/visma-prodsec/ConfusedDotnet
OWASP dep-scanRisk audit incl. --private-ns confusion checkhttps://github.com/owasp-dep-scan/dep-scan
OWASP CI/CD Top 10CICD-SEC-03 Dependency Chain Abusehttps://owasp.org/www-project-top-10-ci-cd-security-risks/
Birsan researchOriginal dependency confusion writeuphttps://medium.com/@alex.birsan/dependency-confusion-4a5d60fec610
npm scopes docsScope-to-registry pinning referencehttps://docs.npmjs.com/cli/v10/using-npm/scope

Validation Criteria

  • All dependency manifests in the codebase enumerated.
  • confused run for every relevant ecosystem with secure namespaces supplied.
  • OWASP dep-scan --private-ns run and reconciled with confused output.
  • Each flagged name confirmed claimable (404) or dismissed as a false positive.
  • Internal scopes pinned to the private registry in .npmrc / pip config / Maven mirror.
  • extra-index-url and merged virtual feeds reviewed for highest-version pull risk.
  • Placeholder packages registered for names that cannot be isolated.
  • CI job enforces the check on every push/PR.
  • Findings documented with owner and remediation status.

© mukul975, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 4 other files (scripts, references) in skills/detecting-dependency-confusion of mukul975/Anthropic-Cybersecurity-Skills.

  • SKILL.md
  • LICENSE
  • references/api-reference.md
  • references/standards.md
  • scripts/agent.py

Open the folder on GitHubat commit 54a7988

Compare with similar skills

Detecting Dependency Confusion next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Detecting Dependency Confusion compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Detecting Dependency Confusion this skillmukul975/Anthropic-Cybersecurity-Skills34k—~2.9kAutomated safety check: WarnApache-2.0
Dependency AwarenessGoldziher/ai-rulez159—~250Automated safety check: PassMIT
npm Supply Chain Securitybodadotsh/npm-security-best-practices858—~1kAutomated safety check: WarnMIT
Security and Hardeningaddyosmani/agent-skills104k1 repos~4.4kAutomated safety check: NotesMIT
Cyber NeoHainrixz/cyber-neo283—~5.9kAutomated safety check: WarnMIT
Code Vuln Auditzebbern/claude-code-guide4.7k—~1.3kAutomated safety check: PassMIT

Similar skills

  • Dependency Awareness

    Goldziher/ai-rulez

    Per-language dependency vulnerability audit tool reference (cargo audit/deny, pip-audit, npm/pnpm audit, govulncheck, bundler-audit, composer audit, OWASP dependency-check, dotnet vulnerable…

    159 GitHub stars~250 tokensUpdated today
    SecurityAuto-check passed
  • npm Supply Chain Security

    bodadotsh/npm-security-best-practices

    Applies safer package manager defaults and dependency vetting to JavaScript and TypeScript projects to reduce supply-chain attack risk.

    858 GitHub stars~1k tokensUpdated 9 days ago
    SecurityAuto-check: warnings
  • Security and Hardening

    addyosmani/agent-skills

    Applies a threat-model-first approach to web code that handles untrusted input, authentication, data storage, dependencies or personal data.

    104k GitHub starsUsed in 1 repo~4.4k tokens
    SecurityAuto-check: notes
  • Cyber Neo

    Hainrixz/cyber-neo

    Comprehensive cybersecurity analysis for any local project. An agent skill from Hainrixz/cyber-neo.

    283 GitHub stars~5.9k tokensUpdated 2 mo ago
    SecurityAuto-check: warnings
  • Code Vuln Audit

    zebbern/claude-code-guide

    Scan code for security issues: dependency vulnerabilities (npm/pip audit), secret leaks (regex and entropy analysis), and OWASP anti-patterns like SQL injection, XSS, or command injection.

    4.7k GitHub stars~1.3k tokensUpdated today
    SecurityAuto-check passed
  • Dependency Update Audit

    backnotprop/plannotator

    Audits outdated npm and Bun packages for supply chain integrity before bumping them, deferring risky ones and logging every decision.

    9.3k GitHub stars~1.8k tokensUpdated today
    SecurityAuto-check passed

More from mukul975/Anthropic-Cybersecurity-Skills

All 644 skills in this repo
  • Campaign Attribution Evidence Analysis

    mukul975/Anthropic-Cybersecurity-Skills

    Weighs infrastructure, TTP, malware code and timing evidence with the Diamond Model and competing hypotheses to reach a confidence-rated attribution.

    34k GitHub stars~2.3k tokensUpdated 1 mo ago
    Auto-check passed
  • Go Malware Analysis in Ghidra

    mukul975/Anthropic-Cybersecurity-Skills

    Walks through reverse engineering Go-compiled malware in Ghidra: parsing buildinfo and pclntab, recovering stripped function names and extracting dependencies.

    34k GitHub stars~2.8k tokensUpdated 1 mo ago
    Auto-check passed
  • LNK and Jump List Forensics

    mukul975/Anthropic-Cybersecurity-Skills

    Guides forensic analysis of Windows LNK shortcut files and Jump Lists with LECmd, JLECmd and manual parsing to show file access and program execution.

    34k GitHub stars~2.8k tokensUpdated 1 mo ago
    Auto-check passed
  • Malware Persistence Analysis with Autoruns

    mukul975/Anthropic-Cybersecurity-Skills

    Hunts Windows malware persistence with Sysinternals Autoruns, covering run keys, services, scheduled tasks and drivers, with baseline comparison.

    34k GitHub stars~1.2k tokensUpdated 1 mo ago
    Auto-check passed
  • NTFS MFT Deleted File Recovery

    mukul975/Anthropic-Cybersecurity-Skills

    Guides a Windows forensic examination of the NTFS Master File Table to recover deleted-file evidence, build timelines and spot timestomping.

    34k GitHub stars~2.7k tokensUpdated 1 mo ago
    Auto-check passed
  • Network Covert Channel Analysis

    mukul975/Anthropic-Cybersecurity-Skills

    Detects DNS tunneling, ICMP exfiltration and HTTP-based covert channels in packet captures and DNS logs when hunting for hidden command-and-control traffic.

    34k GitHub stars~2k tokensUpdated 1 mo ago
    Auto-check passed

Works with

Categories

Questions about Detecting Dependency Confusion

What does Detecting Dependency Confusion do?

Detect and prevent dependency confusion (public-over-private package name resolution) in npm, PyPI, and Maven by enumerating claimable internal package names with tools like confused and OWASP…. Detecting Dependency Confusion is an agent skill from mukul975/Anthropic-Cybersecurity-Skills.xml.

When should I use Detecting Dependency Confusion?

Detecting Dependency Confusion fits situations like: onboarding a repo to a supply-chain security program; auditing lockfiles/manifests for confusable dependencies; after an incident that may have leaked internal package names.

How do I install Detecting Dependency Confusion in Claude Code?

Run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill detecting-dependency-confusion -a claude-code`. Or copy the skill folder (skills/detecting-dependency-confusion in mukul975/Anthropic-Cybersecurity-Skills) into .claude/skills/detecting-dependency-confusion in your project. Claude Code loads it when a task matches its description.

How do I install Detecting Dependency Confusion in Codex?

Run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill detecting-dependency-confusion -a codex`. Or copy the skill folder (skills/detecting-dependency-confusion in mukul975/Anthropic-Cybersecurity-Skills) into .agents/skills/detecting-dependency-confusion in your project. Codex loads it when a task matches its description.

Can I use Detecting Dependency Confusion in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill detecting-dependency-confusion -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/detecting-dependency-confusion, .gemini/skills/detecting-dependency-confusion, .github/skills/detecting-dependency-confusion and .opencode/skills/detecting-dependency-confusion in your project.

What does Detecting Dependency Confusion need to run?

Going by SKILL.md and its folder, Detecting Dependency Confusion needs Python for the scripts in its folder, the command-line tools its instructions call (npm, curl, go, pip and python) and credentials named NPM_TOKEN. Our summary lists: Python 3; Node.js; Docker; A credential in NPM_TOKEN.

Does Detecting Dependency Confusion access the network?

SKILL.md names 6 domains. In commands or code: registry.npmjs.org and pypi.org; the agent is likely to contact these when it follows the instructions. As links in the text: github.com, owasp.org, medium.com and docs.npmjs.com. This is read from the text; nothing was executed.

Is Detecting Dependency Confusion safe to install?

Our automated static check of SKILL.md flagged 5 warning(s): mentions a credentials file (ssh keys, cloud or package-manager tokens). Read the flagged lines before installing; the check is not a guarantee either way. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Detecting Dependency Confusion use?

Detecting Dependency Confusion is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Detecting Dependency Confusion use?

About 2.9k tokens (SKILL.md is roughly 12k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 980 tokens, read only when the agent opens those files.

What are the alternatives to Detecting Dependency Confusion?

Skills that share tags, products or a category with Detecting Dependency Confusion: Dependency Awareness (Goldziher/ai-rulez, 159 stars), npm Supply Chain Security (bodadotsh/npm-security-best-practices, 858 stars), Security and Hardening (addyosmani/agent-skills, 104k stars) and Cyber Neo (Hainrixz/cyber-neo, 283 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Detecting Dependency Confusion?

mukul975 (a GitHub user) maintains it in mukul975/Anthropic-Cybersecurity-Skills, which has 34,116 GitHub stars. The repository holds 644 skills in this directory. The repository was last updated on August 31, 2026.

Source: mukul975/Anthropic-Cybersecurity-Skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.