Agent skill

Detecting Malicious npm Packages

by mukul975 in mukul975/Anthropic-Cybersecurity-Skills

Triage npm packages and lockfiles for install-script malware, credential exfiltration, and worming behavior using GuardDog, manual tarball inspection, and dynamic detonation with network/filesystem…

Apache-2.0Auto-check: warningsDevelopment

Install Detecting Malicious npm Packages

The automated check flagged lines worth reading first. See the safety section below.

skills CLI
$ npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill detecting-malicious-npm-packages -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install mukul975/Anthropic-Cybersecurity-Skills detecting-malicious-npm-packages --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/mukul975/Anthropic-Cybersecurity-Skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/detecting-malicious-npm-packages .claude/skills/detecting-malicious-npm-packages && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
detecting-malicious-npm-packages
GitHub stars
34k
Token cost
~2.6k tokens
SKILL.md length
846 words
Files
5 (incl. scripts, references)
Skills in repo
644
Repo updated
First seen
Licence
Apache-2.0

At a glance

Triage npm packages and lockfiles for install-script malware, credential exfiltration, and worming behavior using GuardDog, manual tarball inspection, and dynamic detonation with network/filesystem…

  • Works in 10 steps: Download the package without executing it → Scan a single package with GuardDog → Verify an entire dependency tree → …
  • Vetting a new dependency
  • SKILL.md covers Overview, When to Use, Prerequisites and Objectives, plus 4 more sections
  • Runs Python scripts from its folder; calls npm, jq and python

What it does

Detecting Malicious npm Packages is an agent skill from mukul975/Anthropic-Cybersecurity-Skills. Triage npm packages and lockfiles for install-script malware, credential exfiltration, and worming behavior using GuardDog, manual tarball inspection, and dynamic detonation with network/filesystem monitoring. Use when vetting a new dependency, reviewing a package.json/package-lock.json during code review, checking lockfiles against a supply-chain advisory's known-bad versions, or investigating a host suspected of installing a trojanized package.

Its SKILL.md is about 2.6k tokens, which your agent loads only when the skill is triggered. The skill folder holds 6 other files, including scripts and reference files (for example `references/api-reference.md`, `references/standards.md` and `scripts/agent.py`).

It sits in Development, covering Dependency management and Supply chain security. It works with npm. The repository describes itself as: 817 structured cybersecurity skills for AI agents · Mapped to 6 frameworks: MITRE ATT&CK, NIST CSF 2.0, MITRE ATLAS, D3FEND, NIST AI RMF & MITRE F3 (Fight Fraud) · agentskills.io…. The licence is Apache-2.0.

When your agent uses it

  • Vetting a new dependency
  • Reviewing a package.json/package-lock.json during code review
  • Checking lockfiles against a supply-chain advisorys known-bad versions
  • Investigating a host suspected of installing a trojanized package

Example prompts

  • “/detecting-malicious-npm-packages”

Requirements

  • Python 3
  • Node.js
  • Docker

Workflow steps

10 steps, taken from the step headings in SKILL.md.

  1. Download the package without executing it
  2. Scan a single package with GuardDog
  3. Verify an entire dependency tree
  4. Focus on the highest-signal heuristics
  5. Emit machine-readable output for pipelines
  6. Manually inspect lifecycle scripts and source
  7. Cross-check lockfiles against known-malicious versions
  8. Detonate safely with monitoring (only if static is inconclusive)
  9. Extract and operationalize IOCs
  10. Run the bundled triage helper

What it can do on your machine

Read from SKILL.md and the folder at commit 54a7988. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (Python), which the agent can run.

    Shell commands in SKILL.md call:

    • npm
    • jq
    • python
    • pip
    • docker
    • go
    • curl

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • github.com
    • docs.npmjs.com
    • securitylabs.datadoghq.com
    • semgrep.dev

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Detecting Malicious npm Packages loads about 2.6k tokens when it runs, and up to ~3.5k if it reads all its reference files. Until then it costs about 121 tokens; SKILL.md has 846 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~121
When it runs · the whole SKILL.md, loaded when a task matches
~2.6k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~3.5k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: warnings

The automated check found patterns that need a careful read before installing.

  • WarningMentions a credentials file (SSH keys, cloud or package-manager tokens)SKILL.md:31
    exfiltrating environment variables, `~/.npmrc` tokens, SSH keys, and cloud credentials to an attacker-controlled URL; o
  • WarningMentions a credentials file (SSH keys, cloud or package-manager tokens)SKILL.md:75
    redentials In Files | Packages steal `~/.npmrc`, `.env`, SSH keys, and cloud credential files. |

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from mukul975/Anthropic-Cybersecurity-Skills at commit 54a7988, republished under its Apache-2.0 licence (© mukul975). 846 words, ~2,603 tokens.

Download SKILL.mdSave it as .claude/skills/detecting-malicious-npm-packages/SKILL.md (or your agent's skills folder). This skill also uses 4 other files; get the full folder from GitHub.
name
detecting-malicious-npm-packages
description
Triage npm packages and lockfiles for install-script malware, credential exfiltration, and worming behavior using GuardDog, manual tarball inspection, and dynamic detonation with network/filesystem monitoring. Use when vetting a new dependency, reviewing a package.json/package-lock.json during code review, checking lockfiles against a supply-chain advisory's known-bad versions, or investigating a host suspected of installing a trojanized package.
domain
cybersecurity
subdomain
supply-chain-security
tags
supply-chain-security, npm, malware-analysis, guarddog, install-scripts, exfiltration, static-analysis, threat-detection
version
1.0
author
mahipal
license
Apache-2.0
nist_csf
DE.CM-09
mitre_attack
T1195.002

Detecting Malicious npm Packages

Legal Notice: Analyze packages in an isolated, disposable environment. Some malicious packages execute on install (npm install runs lifecycle scripts automatically) or on import. Never analyze a suspect package on a workstation with credentials, SSH keys, cloud tokens, or network access to production. This skill is for defensive analysis and authorized incident response only.

Overview

The npm registry is the largest software package ecosystem in the world and the most heavily targeted by supply-chain attackers. Malicious packages reach victims through typosquatting (expresss, crossenv), dependency confusion, account/maintainer takeover (the 2025 Shai-Hulud worm and the event-stream compromise are canonical examples), and starjacking. The defining danger of npm is that npm install automatically runs preinstall, install, and postinstall lifecycle scripts with the developer's full privileges before any application code is invoked — so simply installing a package is enough to be compromised. Roughly 2% of npm packages use install scripts, which makes them both common and a powerful malware delivery vehicle.

Typical malicious behaviors are: exfiltrating environment variables, ~/.npmrc tokens, SSH keys, and cloud credentials to an attacker-controlled URL; opening reverse shells; dropping cryptominers; reading and posting process.env; obfuscating payloads with base64/eval; and self-propagating (worming) by stealing the maintainer's npm token and republishing trojanized versions of other packages they own.

This skill provides a repeatable triage workflow centered on GuardDog (Datadog's open-source heuristic scanner built on Semgrep + metadata rules), supplemented by manual tarball inspection, lockfile-based compromise checks against known-bad version lists, and dynamic detonation with network and filesystem monitoring. The goal is to decide, quickly and safely, whether a given package or a project's dependency tree contains malicious code.

When to Use

  • Triaging a specific npm package before adding it as a dependency.
  • Vetting a full package.json / package-lock.json during code review or onboarding a third-party library.
  • Responding to a supply-chain advisory (e.g., a worm campaign) and needing to check whether your lockfiles pulled a known-bad version.
  • Investigating an endpoint or CI runner suspected of having installed a trojanized package.
  • Building a pre-install gate in CI/CD that blocks packages exhibiting malicious indicators.

Prerequisites

  • An isolated VM or disposable container with no production credentials and snapshot/rollback capability.
  • GuardDog:
    bash
    pip install guarddog
    # or run via Docker without local install:
    docker pull ghcr.io/datadog/guarddog
    alias guarddog='docker run --rm ghcr.io/datadog/guarddog'
  • Node.js + npm (use --ignore-scripts when downloading for analysis).
  • jq, tar, and optionally OSV-Scanner for known-vulnerability/known-malicious cross-checks:
    bash
    go install github.com/google/osv-scanner/cmd/osv-scanner@v1
  • For dynamic analysis: a sandbox with egress logging (e.g., tcpdump, a DNS sink, or a network namespace).

Objectives

  • Statically scan an npm package (or a whole dependency tree) for malicious heuristics without executing it.
  • Identify install-script abuse, environment/credential exfiltration, obfuscation, and silent process execution.
  • Cross-check lockfile-pinned versions against known-malicious version lists / OSV.
  • Safely detonate a suspect package and observe network and filesystem behavior.
  • Extract indicators of compromise (URLs, IPs, hashes) for blocking and threat intel.
  • Produce a defensible verdict (benign / suspicious / malicious) with evidence.

MITRE ATT&CK Mapping

Technique IDTechnique NameRelevance
T1195.002Supply Chain Compromise: Compromise Software Supply ChainCore technique — trojanized npm package delivered through the registry.
T1059.007Command and Scripting Interpreter: JavaScriptMalicious install scripts / module code execute attacker JavaScript.
T1552.001Unsecured Credentials: Credentials In FilesPackages steal ~/.npmrc, .env, SSH keys, and cloud credential files.
T1041Exfiltration Over C2 ChannelStolen secrets posted to attacker HTTP(S) endpoints.
T1027Obfuscated Files or Informationbase64/eval/hex obfuscation hides the payload from review.
Show full SKILL.md (311 more words)Show less

Workflow

1. Download the package without executing it

Fetch the tarball with scripts disabled so nothing runs during acquisition.

bash
mkdir triage && cd triage
# Resolve the tarball URL and download it (no install, no scripts)
npm pack express@4.18.2            # produces express-4.18.2.tgz
# or for an arbitrary version:
npm view some-pkg@1.2.3 dist.tarball
curl -sL "$(npm view some-pkg@1.2.3 dist.tarball)" -o some-pkg.tgz
tar -xzf some-pkg.tgz              # extracts into ./package
2. Scan a single package with GuardDog

GuardDog applies metadata + source heuristics and prints which rules matched.

bash
# Scan the latest published version from the registry
guarddog npm scan express

# Scan a specific version
guarddog npm scan some-pkg --version 1.2.3

# Scan the local tarball / extracted directory you downloaded above
guarddog npm scan ./some-pkg.tgz
guarddog npm scan ./package/
3. Verify an entire dependency tree

verify scans every dependency declared in a manifest — ideal for code review.

bash
guarddog npm verify /path/to/repo/package.json
4. Focus on the highest-signal heuristics

Filter to the npm rules most indicative of malware to cut noise during triage.

bash
guarddog npm scan some-pkg \
  --rules npm-install-script \
  --rules npm-serialize-environment \
  --rules npm-exec-base64 \
  --rules npm-silent-process-execution \
  --rules npm-obfuscation \
  --rules shady-links \
  --rules typosquatting
5. Emit machine-readable output for pipelines

JSON for tooling, SARIF for GitHub code scanning.

bash
guarddog npm scan some-pkg --output-format=json   > guarddog.json
guarddog npm verify package.json --output-format=sarif > guarddog.sarif
6. Manually inspect lifecycle scripts and source

Lifecycle scripts are the first thing to read; obfuscation and outbound URLs are red flags.

bash
# Show all lifecycle hooks
jq '.scripts' package/package.json

# Hunt for exfiltration / execution primitives in the source
grep -rEn "child_process|exec\(|spawn|eval\(|Buffer\.from\(.*base64|process\.env|https?://" package/ \
  --include='*.js' --include='*.ts' | head -50
7. Cross-check lockfiles against known-malicious versions

During an active campaign, compare pinned versions to the advisory's bad-version list, and run OSV.

bash
# Extract resolved name@version pairs from a v3 lockfile
jq -r '.packages | to_entries[] | select(.key|startswith("node_modules/")) | "\(.key|ltrimstr("node_modules/"))@\(.value.version)"' package-lock.json

# OSV-Scanner flags known-vulnerable AND known-malicious (MAL-) advisories
osv-scanner --lockfile=package-lock.json
8. Detonate safely with monitoring (only if static is inconclusive)

Run the install inside a disposable, network-monitored sandbox.

bash
# In a throwaway container / VM with egress capture running (tcpdump -w capture.pcap):
npm install ./some-pkg.tgz            # scripts WILL run — sandbox only
# Baseline-diff the filesystem afterwards for writes outside node_modules,
# and inspect capture.pcap for unexpected DNS / HTTP beacons.
9. Extract and operationalize IOCs

Pull URLs, IPs, and hashes for blocking and intel sharing.

bash
grep -rhoE "https?://[a-zA-Z0-9./?=_%:-]+" package/ | sort -u > urls.txt
sha256sum some-pkg.tgz package/*.js > hashes.txt
10. Run the bundled triage helper

agent.py orchestrates GuardDog, lifecycle-script inspection, and IOC extraction into one report.

bash
python scripts/agent.py --package some-pkg --version 1.2.3 --output verdict.json
# or against a local tarball:
python scripts/agent.py --tarball ./some-pkg.tgz --output verdict.json

Tools and Resources

ToolPurposeSource
GuardDogHeuristic npm/PyPI/Go malware scannerhttps://github.com/DataDog/guarddog
OSV-ScannerKnown-vulnerable & known-malicious (MAL-) advisory matchinghttps://github.com/google/osv-scanner
OSV malicious DBOpen-source malicious package advisorieshttps://github.com/ossf/malicious-packages
npm lifecycle docspreinstall/install/postinstall semanticshttps://docs.npmjs.com/cli/v10/using-npm/scripts
Datadog Security Labsnpm campaign writeups & ruleshttps://securitylabs.datadoghq.com/
SemgrepRule engine GuardDog uses for source heuristicshttps://semgrep.dev/

Validation Criteria

  • Package acquired with scripts disabled in an isolated environment.
  • GuardDog scan run on the target version with results captured.
  • Full dependency tree run through GuardDog verify where applicable.
  • Lifecycle scripts (preinstall/install/postinstall) read and assessed.
  • Lockfile versions cross-checked against OSV / known-bad lists.
  • Dynamic detonation performed in a sandbox if static analysis was inconclusive.
  • IOCs (URLs, IPs, hashes) extracted and recorded.
  • Documented verdict (benign / suspicious / malicious) with supporting evidence.
  • Malicious findings reported to the registry and shared as threat intel.

© mukul975, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 4 other files (scripts, references) in skills/detecting-malicious-npm-packages of mukul975/Anthropic-Cybersecurity-Skills.

  • SKILL.md
  • LICENSE
  • references/api-reference.md
  • references/standards.md
  • scripts/agent.py

Open the folder on GitHubat commit 54a7988

Compare with similar skills

Detecting Malicious npm Packages next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Detecting Malicious npm Packages compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Detecting Malicious npm Packages this skillmukul975/Anthropic-Cybersecurity-Skills34k—~2.6kAutomated safety check: WarnApache-2.0
Stash Supply Chain Securitycipherstash/stack157—~5.2kAutomated safety check: WarnMIT
Dependency Upgrade Protocoldralgorhythm/claude-agentic-framework125—~1.5kAutomated safety check: PassNone
Doormanccplugins/awesome-claude-code-plugins970—~1.5kAutomated safety check: PassMIT
npm Supply Chain Securitybodadotsh/npm-security-best-practices858—~1kAutomated safety check: WarnMIT
Dependency Update Auditbacknotprop/plannotator9.3k—~1.8kAutomated safety check: PassApache-2.0

Similar skills

  • Supply-chain security controls for the @cipherstash/stack monorepo.

    157 GitHub stars~5.2k tokensUpdated today
    DevelopmentAuto-check: warnings
  • Dependency Upgrade Protocol

    dralgorhythm/claude-agentic-framework

    Sequences safe dependency upgrades: read the changelog, verify the version exists upstream, pin it, and keep major bumps in separate commits behind a full gate run.

    125 GitHub stars~1.5k tokensUpdated 2 mo ago
    DevelopmentAuto-check passed
  • Doorman

    ccplugins/awesome-claude-code-plugins

    Dependency gatekeeper. An agent skill from ccplugins/awesome-claude-code-plugins.

    970 GitHub stars~1.5k tokensUpdated 1 mo ago
    DevelopmentAuto-check passed
  • npm Supply Chain Security

    bodadotsh/npm-security-best-practices

    Applies safer package manager defaults and dependency vetting to JavaScript and TypeScript projects to reduce supply-chain attack risk.

    858 GitHub stars~1k tokensUpdated 10 days ago
    SecurityAuto-check: warnings
  • Dependency Update Audit

    backnotprop/plannotator

    Audits outdated npm and Bun packages for supply chain integrity before bumping them, deferring risky ones and logging every decision.

    9.3k GitHub stars~1.8k tokensUpdated today
    SecurityAuto-check passed
  • npm Supply Chain Check

    majiayu000/spellbook

    Scans a repository, its lockfiles and node_modules for known malicious npm package versions and install-time indicators, using a read-only Python scanner.

    287 GitHub stars~1.5k tokensUpdated 2 days ago
    SecurityAuto-check passed

More from mukul975/Anthropic-Cybersecurity-Skills

All 644 skills in this repo
  • Campaign Attribution Evidence Analysis

    mukul975/Anthropic-Cybersecurity-Skills

    Weighs infrastructure, TTP, malware code and timing evidence with the Diamond Model and competing hypotheses to reach a confidence-rated attribution.

    34k GitHub stars~2.3k tokensUpdated 1 mo ago
    Auto-check passed
  • Go Malware Analysis in Ghidra

    mukul975/Anthropic-Cybersecurity-Skills

    Walks through reverse engineering Go-compiled malware in Ghidra: parsing buildinfo and pclntab, recovering stripped function names and extracting dependencies.

    34k GitHub stars~2.8k tokensUpdated 1 mo ago
    Auto-check passed
  • LNK and Jump List Forensics

    mukul975/Anthropic-Cybersecurity-Skills

    Guides forensic analysis of Windows LNK shortcut files and Jump Lists with LECmd, JLECmd and manual parsing to show file access and program execution.

    34k GitHub stars~2.8k tokensUpdated 1 mo ago
    Auto-check passed
  • Malware Persistence Analysis with Autoruns

    mukul975/Anthropic-Cybersecurity-Skills

    Hunts Windows malware persistence with Sysinternals Autoruns, covering run keys, services, scheduled tasks and drivers, with baseline comparison.

    34k GitHub stars~1.2k tokensUpdated 1 mo ago
    Auto-check passed
  • NTFS MFT Deleted File Recovery

    mukul975/Anthropic-Cybersecurity-Skills

    Guides a Windows forensic examination of the NTFS Master File Table to recover deleted-file evidence, build timelines and spot timestomping.

    34k GitHub stars~2.7k tokensUpdated 1 mo ago
    Auto-check passed
  • Network Covert Channel Analysis

    mukul975/Anthropic-Cybersecurity-Skills

    Detects DNS tunneling, ICMP exfiltration and HTTP-based covert channels in packet captures and DNS logs when hunting for hidden command-and-control traffic.

    34k GitHub stars~2k tokensUpdated 1 mo ago
    Auto-check passed

Works with

Questions about Detecting Malicious npm Packages

What does Detecting Malicious npm Packages do?

Triage npm packages and lockfiles for install-script malware, credential exfiltration, and worming behavior using GuardDog, manual tarball inspection, and dynamic detonation with network/filesystem…. Detecting Malicious npm Packages is an agent skill from mukul975/Anthropic-Cybersecurity-Skills. Triage npm packages and lockfiles for install-script malware, credential exfiltration, and worming behavior using GuardDog, manual tarball inspection, and dynamic detonation with network/filesystem monitoring.

When should I use Detecting Malicious npm Packages?

Detecting Malicious npm Packages fits situations like: vetting a new dependency; reviewing a package.json/package-lock.json during code review; checking lockfiles against a supply-chain advisorys known-bad versions; investigating a host suspected of installing a trojanized package.

How do I install Detecting Malicious npm Packages in Claude Code?

Run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill detecting-malicious-npm-packages -a claude-code`. Or copy the skill folder (skills/detecting-malicious-npm-packages in mukul975/Anthropic-Cybersecurity-Skills) into .claude/skills/detecting-malicious-npm-packages in your project. Claude Code loads it when a task matches its description.

How do I install Detecting Malicious npm Packages in Codex?

Run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill detecting-malicious-npm-packages -a codex`. Or copy the skill folder (skills/detecting-malicious-npm-packages in mukul975/Anthropic-Cybersecurity-Skills) into .agents/skills/detecting-malicious-npm-packages in your project. Codex loads it when a task matches its description.

Can I use Detecting Malicious npm Packages in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill detecting-malicious-npm-packages -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/detecting-malicious-npm-packages, .gemini/skills/detecting-malicious-npm-packages, .github/skills/detecting-malicious-npm-packages and .opencode/skills/detecting-malicious-npm-packages in your project.

What does Detecting Malicious npm Packages need to run?

Going by SKILL.md and its folder, Detecting Malicious npm Packages needs Python for the scripts in its folder and the command-line tools its instructions call (npm, jq, python, pip, docker and go). Our summary lists: Python 3; Node.js; Docker.

Does Detecting Malicious npm Packages access the network?

SKILL.md names 4 domains. As links in the text: github.com, docs.npmjs.com, securitylabs.datadoghq.com and semgrep.dev. This is read from the text; nothing was executed.

Is Detecting Malicious npm Packages safe to install?

Our automated static check of SKILL.md flagged 2 warning(s): mentions a credentials file (ssh keys, cloud or package-manager tokens). Read the flagged lines before installing; the check is not a guarantee either way. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Detecting Malicious npm Packages use?

Detecting Malicious npm Packages is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Detecting Malicious npm Packages use?

About 2.6k tokens (SKILL.md is roughly 10k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 946 tokens, read only when the agent opens those files.

What are the alternatives to Detecting Malicious npm Packages?

Skills that share tags, products or a category with Detecting Malicious npm Packages: Stash Supply Chain Security (cipherstash/stack, 157 stars), Dependency Upgrade Protocol (dralgorhythm/claude-agentic-framework, 125 stars), Doorman (ccplugins/awesome-claude-code-plugins, 970 stars) and npm Supply Chain Security (bodadotsh/npm-security-best-practices, 858 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Detecting Malicious npm Packages?

mukul975 (a GitHub user) maintains it in mukul975/Anthropic-Cybersecurity-Skills, which has 34,116 GitHub stars. The repository holds 644 skills in this directory. The repository was last updated on August 31, 2026.

Source: mukul975/Anthropic-Cybersecurity-Skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.