npm Supply Chain Check
majiayu000/spellbook
Scans a repository, its lockfiles and node_modules for known malicious npm package versions and install-time indicators, using a read-only Python scanner.
Run a large sharded measurement sweep over npm packages (the build-jail catalog probe, or any harness that installs thousands of package-versions and records a verdict per run).
$ npx skills add nubjs/nub --skill corpus-sweep -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install nubjs/nub corpus-sweep --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/nubjs/nub.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/corpus-sweep .claude/skills/corpus-sweep && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "corpus-sweep" agent skill from https://github.com/nubjs/nub/tree/main/.claude/skills/corpus-sweep into .claude/skills/corpus-sweep/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "corpus-sweep", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/nubjs/nub/tree/main/.claude/skills/corpus-sweepType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add nubjs/nub --skill corpus-sweep -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install nubjs/nub corpus-sweep --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/nubjs/nub.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.claude/skills/corpus-sweep .agents/skills/corpus-sweep && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "corpus-sweep" agent skill from https://github.com/nubjs/nub/tree/main/.claude/skills/corpus-sweep into .agents/skills/corpus-sweep/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "corpus-sweep", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add nubjs/nub --skill corpus-sweep -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install nubjs/nub corpus-sweep --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/nubjs/nub.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.claude/skills/corpus-sweep .cursor/skills/corpus-sweep && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "corpus-sweep" agent skill from https://github.com/nubjs/nub/tree/main/.claude/skills/corpus-sweep into .cursor/skills/corpus-sweep/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "corpus-sweep", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/nubjs/nub.git --path .claude/skills/corpus-sweep--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add nubjs/nub --skill corpus-sweep -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install nubjs/nub corpus-sweep --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/nubjs/nub.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.claude/skills/corpus-sweep .gemini/skills/corpus-sweep && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "corpus-sweep" agent skill from https://github.com/nubjs/nub/tree/main/.claude/skills/corpus-sweep into .gemini/skills/corpus-sweep/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "corpus-sweep", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install nubjs/nub corpus-sweepInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add nubjs/nub --skill corpus-sweep -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/nubjs/nub.git skills-src && mkdir -p .github/skills && cp -r skills-src/.claude/skills/corpus-sweep .github/skills/corpus-sweep && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "corpus-sweep" agent skill from https://github.com/nubjs/nub/tree/main/.claude/skills/corpus-sweep into .github/skills/corpus-sweep/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "corpus-sweep", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add nubjs/nub --skill corpus-sweep -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install nubjs/nub corpus-sweep --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/nubjs/nub.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.claude/skills/corpus-sweep .opencode/skills/corpus-sweep && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "corpus-sweep" agent skill from https://github.com/nubjs/nub/tree/main/.claude/skills/corpus-sweep into .opencode/skills/corpus-sweep/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "corpus-sweep", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
corpus-sweepRun a large sharded measurement sweep over npm packages (the build-jail catalog probe, or any harness that installs thousands of package-versions and records a verdict per run).
Corpus Sweep is an agent skill from nubjs/nub. Run a large sharded measurement sweep over npm packages (the build-jail catalog probe, or any harness that installs thousands of package-versions and records a verdict per run). Invoke BEFORE launching a sweep, before believing any standalone reproduction of a sweep failure, and before reporting that a failure is or is not a real defect. Carries the self-deception patterns that each cost hours: an install exiting 0 while the build was silently skipped, find not following store symlinks, a restricted PATH swapping…
Its SKILL.md is about 2.4k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Security, covering Supply chain security. It works with npm and Python. The repository describes itself as: The fast all-in-one Node.js toolkit. The licence is MIT.
Read from SKILL.md and the folder at commit 568e73a. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
python3From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Corpus Sweep loads about 2.4k tokens when it runs. Until then it costs about 208 tokens; SKILL.md has 1,365 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from nubjs/nub at commit 568e73a, republished under its MIT licence (© nubjs). 1,365 words, ~2,442 tokens.
.claude/skills/corpus-sweep/SKILL.md (or your agent's skills folder).A sweep installs thousands of third-party package-versions and records a verdict for each. The verdicts feed something real — for the build jail, the capability catalog that decides what actual user installs are permitted. So a wrong verdict is not a flaky test, it is a shipped defect.
The single most important thing in this skill: nearly every wrong conclusion comes from a STANDALONE REPRODUCTION THAT SILENTLY TESTED NOTHING. The harness says a package fails. You run it by hand, it passes, and you conclude the harness is wrong. It is almost always the reverse.
Run this checklist. Each line is a measured failure that produced a confident wrong answer.
| Check | Why |
|---|---|
| Did the script actually RUN? | nub install exits 0 while the trust policy skips the build entirely — WARN ignored build scripts for N package(s). You must run nub approve-builds --all after the install. An exit code proves nothing about whether a lifecycle script executed. |
Did you look for the artifact with find -L? | Under the isolated linker every node_modules entry is a SYMLINK into the global store. Plain find does not follow symlinks and reports zero addons where ls shows them present. |
| What is on PATH? | Restricting PATH to /usr/bin silently hands node-gyp Xcode's Python 3.9 instead of the host's 3.14 — so the Python-dependent failure you are chasing cannot reproduce. Print the resolved python3, node, and node-gyp versions in the probe output, not just the exit code. |
| Is each arm getting a FRESH home AND a fresh store? | Sequential arms against a shared store make the second one warm. That confounds every A/B, and it is how four consecutive wrong answers about one package were reached. |
| Are you varying exactly ONE thing? | A separate tool (classify-broken.sh) differing from the harness in fixture, env scrubbing, pinned Node/Python AND jail state is not a control for concurrency. |
A clean result where you expected a messy one is a signal to distrust the instrument, not to conclude. Three passes in a row after a real failure means you probably are not running the thing you think you are running.
A screen that returns zero hits has two explanations and you cannot tell them apart without a
control. Measured: an OSV screen over 2,250 entries returned 0 MAL-* hits. That happened to be
correct — but the only way to know was to re-run it against a package known to be flagged
(@ctrl/tinycolor@4.1.2 → MAL-2025-47141) and confirm the instrument fires. Do this for every
batch API call, grep filter, and classifier before reading a conclusion off it.
Batch APIs deserve a second control: put the known positive in the MIDDLE of a full-size batch and check it is still found at the right index. Silent truncation is real.
A package with a MAL-* advisory must never have its scripts run, on this machine or any machine.
--dangerously-allow-all-scripts. If a refusal verdict is
computed after the oracle arms, the harness executes the malicious script itself.Round-robin the worklist so each shard gets a mix of heavy head and cheap tail:
python3 -c "
lines=[l.strip() for l in open('worklist.txt') if l.strip()]
for i in range(3):
open(f'shard{i}.txt','w').write('\n'.join(lines[i::3])+'\n')"Then launch each shard as its OWN harness-tracked background task — never &, which the harness
rejects because a detached job cannot report completion.
fs.mkdtempSync). Verify before launching, not after.$HOME, so a sweep generates millions of file events. Measured: fseventsd 60%,
backupd 30%, mds + spotlightknowledged 47% — about 1.7 cores of pure overhead. Fix with
touch <cache>/.metadata_never_index and tmutil addexclusion <cache>, both idempotent.ps -Ao pid,%cpu,comm -r
before assuming contention; the answer may be an OS daemon.pkill it — and stop-fix-restart is the normal loop when triaging. Measured: 31 orphans,
18.9 GB, on a disk already at 98%. Sweep anything untouched for >30 min at startup; a live shard
touches its root continuously so the threshold cannot catch one in use.A sweep and its debugging leave several distinct piles. Delete all of them:
mkdtemp dirs under the cache);/tmp;Keep the results.json records — they are small (~39 KB each, ~0.1 GB for a 2,250 corpus) and they
are the actual output.
Every harness fix invalidates the records taken before it, because a record means something different under a changed instrument. That is what provenance hashes exist to expose.
Load the probe-platforms skill. It owns the bring-up ladder (debug with the SMALLEST payload —
six Windows faults were found using a 25-minute package when seconds would have done), the Windows
spawn/path/disk faults, the Linux Landlock and node-layout traps, and the remote-shell mechanics.
Two rules from it that bite during a sweep specifically:
read alongside write: "disk", which is redundant) and falls back to the
compiled-in one silently — so a run you believe grants network may have none.© nubjs, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in .claude/skills/corpus-sweep of nubjs/nub.
Open the folder on GitHubat commit 568e73a
Corpus Sweep next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Corpus Sweep this skillnubjs/nub | 4.4k | — | ~2.4k | Automated safety check: Pass | MIT | |
| npm Supply Chain Checkmajiayu000/spellbook | 286 | — | ~1.5k | Automated safety check: Pass | MIT | |
| Tracing Transitive Vulnerabilitiesjeremylongshore/tons-of-skills-marketplace | 2.8k | — | ~2.2k | Automated safety check: Notes | MIT | |
| Security AuditTheDecipherist/claude-code-mastery | 550 | — | ~1.3k | Automated safety check: Notes | MIT | |
| Dependency Update Auditbacknotprop/plannotator | 9.2k | — | ~1.8k | Automated safety check: Pass | Apache-2.0 | |
| Sca TrivyAgentSecOps/SecOpsAgentKit | 220 | 2 repos | ~3.7k | Automated safety check: Pass | Custom licence |
majiayu000/spellbook
Scans a repository, its lockfiles and node_modules for known malicious npm package versions and install-time indicators, using a read-only Python scanner.
jeremylongshore/tons-of-skills-marketplace
Build a dependency-tree map of a project (npm or Python) and trace the path from each known-vulnerable transitive package back to one or more direct dependencies.
TheDecipherist/claude-code-mastery
Checks a codebase for hardcoded secrets, vulnerable dependencies, weak input handling, weak authentication and unsafe transport settings before deployment or merge.
backnotprop/plannotator
Audits outdated npm and Bun packages for supply chain integrity before bumping them, deferring risky ones and logging every decision.
AgentSecOps/SecOpsAgentKit
Software Composition Analysis (SCA) and container vulnerability scanning using Aqua Trivy for identifying CVE vulnerabilities in dependencies, container images, IaC misconfigurations, and license…
vulnersCom/api
A skill your agent uses when modifying, testing, documenting, or reviewing the Vulners Python SDK.
nubjs/nub
Diagnose and clear CPU, memory, and disk contention on the maintainer's dev host.
nubjs/nub
Reclaim disk on the maintainer's Mac when the volume is full or filling — ENOSPC, "no space left on device", a failed build or agent harness, or a routine sweep of Rust build residue.
nubjs/nub
Build a performance chart for nubjs.com — the SVG bar figures in blog posts, docs pages and social posts (a runtime augmentation against plain node, an install or dispatch comparison, a cross-tool…
nubjs/nub
A skill your agent uses when running a compatibility/parity AUDIT — enumerating where nub diverges from a reference it claims parity with (pnpm CLI grammar, a lockfile format, a Node behavior, a…
nubjs/nub
Run ad-hoc Nub tests and debugging probes on real local Linux guests.
nubjs/nub
Performance-trace Nub package-manager installs using the existing phase timings, structured diagnostics, and sampling-profiler workflow.
Run a large sharded measurement sweep over npm packages (the build-jail catalog probe, or any harness that installs thousands of package-versions and records a verdict per run). Corpus Sweep is an agent skill from nubjs/nub. Run a large sharded measurement sweep over npm packages (the build-jail catalog probe, or any harness that installs thousands of package-versions and records a verdict per run).
Corpus Sweep fits situations like: tasks that involve Supply chain security.
Run `npx skills add nubjs/nub --skill corpus-sweep -a claude-code`. Or copy the skill folder (.claude/skills/corpus-sweep in nubjs/nub) into .claude/skills/corpus-sweep in your project. Claude Code loads it when a task matches its description.
Run `npx skills add nubjs/nub --skill corpus-sweep -a codex`. Or copy the skill folder (.claude/skills/corpus-sweep in nubjs/nub) into .agents/skills/corpus-sweep in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add nubjs/nub --skill corpus-sweep -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/corpus-sweep, .gemini/skills/corpus-sweep, .github/skills/corpus-sweep and .opencode/skills/corpus-sweep in your project.
Going by SKILL.md and its folder, Corpus Sweep needs the command-line tools its instructions call (python3). Our summary lists: Python 3.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Corpus Sweep is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 2.4k tokens (SKILL.md is roughly 9.8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Corpus Sweep: npm Supply Chain Check (majiayu000/spellbook, 286 stars), Tracing Transitive Vulnerabilities (jeremylongshore/tons-of-skills-marketplace, 2.8k stars), Security Audit (TheDecipherist/claude-code-mastery, 550 stars) and Dependency Update Audit (backnotprop/plannotator, 9.2k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
nubjs (a GitHub organization) maintains it in nubjs/nub, which has 4,372 GitHub stars. The repository holds 31 skills in this directory. The repository was last updated on October 7, 2026.
Source: nubjs/nub on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.