Official agent skill

Supply Chain Risk Auditor

by trailofbits in trailofbits/skills

Audits a project's dependencies for supply-chain risk: version-matched advisories for direct dependencies and the full lockfile tree, abandoned or archived upstreams, npm publisher concentration…

OfficialCC-BY-SA-4.0Auto-check: notesSecurity

Install Supply Chain Risk Auditor

skills CLI
$ npx skills add trailofbits/skills --skill supply-chain-risk-auditor -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install trailofbits/skills supply-chain-risk-auditor --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/trailofbits/skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/supply-chain-risk-auditor/skills/supply-chain-risk-auditor .claude/skills/supply-chain-risk-auditor && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
supply-chain-risk-auditor
GitHub stars
7.5k
Token cost
~1.7k tokens
SKILL.md length
937 words
Files
13 (incl. scripts, assets)
Skills in repo
79
Repo updated
First seen
Licence
CC-BY-SA-4.0

At a glance

Audits a project's dependencies for supply-chain risk: version-matched advisories for direct dependencies and the full lockfile tree, abandoned or archived upstreams, npm publisher concentration…

  • Works in 5 steps: Confirm the target directory has… → Check gh auth status. Unauthenticated… → Collect, then render. Put outputs… → …
  • Asked to audit dependencies
  • SKILL.md covers Why the scripts do the…, Workflow, Style for what you add and Reading the report, plus 2 more sections
  • Runs Python scripts from its folder; calls uv, gh and npm

What it does

Supply Chain Risk Auditor is an agent skill from trailofbits/skills, published by the product's own GitHub organization. Audits a project's dependencies for supply-chain risk: version-matched advisories for direct dependencies and the full lockfile tree, abandoned or archived upstreams, npm publisher concentration, and install-time script execution. Use when asked to audit dependencies, assess supply-chain or third-party package risk, or review a dependency tree before an engagement.

Its SKILL.md is about 1.7k tokens, which your agent loads only when the skill is triggered. The skill folder holds 15 other files, including scripts and assets (for example `agents/openai.yaml`, `scripts/collect.py` and `scripts/model.py`).

It sits in Security, covering Supply chain security and Dependency management. It works with npm. The repository describes itself as: Trail of Bits Claude Code skills for security research, vulnerability detection, and audit workflows. The licence is CC-BY-SA-4.0.

When your agent uses it

  • Asked to audit dependencies
  • Assess supply-chain
  • Third-party package risk
  • Review a dependency tree before an engagement

Example prompts

  • “Use the supply-chain-risk-auditor skill to audit a project's dependencies for supply-chain risk: version-matched advisories for direct dependencies…”
  • “/supply-chain-risk-auditor”

Requirements

  • Python 3
  • Pre-approved tools (allowed-tools): Read, Write, Bash, Glob, Grep

Workflow steps

5 steps, taken from the first numbered list in SKILL.md.

  1. Confirm the target directory has manifests: package.json, pyproject.toml,
  2. Check gh auth status. Unauthenticated GitHub allows 60 requests/hour against 5,000,
  3. Collect, then render. Put outputs somewhere outside the audited repository unless
  4. Read report.md and findings.json. The report is the deliverable; the JSON carries
  5. Add what the collector cannot, clearly separated from what it measured

What it can do on your machine

Read from SKILL.md and the folder at commit 442fc9d. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Read
    • Write
    • Bash
    • Glob
    • Grep

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 10 files in scripts/ (Python), which the agent can run.

    Shell commands in SKILL.md call:

    • uv
    • gh
    • npm

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use uv, gh and npm, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Supply Chain Risk Auditor loads about 1.7k tokens when it runs. Until then it costs about 98 tokens; SKILL.md has 937 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~98
When it runs · the whole SKILL.md, loaded when a task matches
~1.7k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NotePre-approves every shell command (allowed-tools: Bash)SKILL.md
    allowed-tools: Read, Write, Bash, Glob, Grep

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from trailofbits/skills at commit 442fc9d, republished under its CC-BY-SA-4.0 licence (© trailofbits). 937 words, ~1,741 tokens.

Download SKILL.mdSave it as .claude/skills/supply-chain-risk-auditor/SKILL.md (or your agent's skills folder). This skill also uses 12 other files; get the full folder from GitHub.
name
supply-chain-risk-auditor
description
Audits a project's dependencies for supply-chain risk: version-matched advisories for direct dependencies and the full lockfile tree, abandoned or archived upstreams, npm publisher concentration, and install-time script execution. Use when asked to audit dependencies, assess supply-chain or third-party package risk, or review a dependency tree before an engagement.
allowed-tools
Read, Write, Bash, Glob, Grep

Supply Chain Risk Auditor

Generates a supply-chain risk report for a project's direct dependencies (npm, PyPI, Go), plus an advisory sweep of everything its lockfile resolves. Two deterministic scripts do the measuring; your job is the judgment they refuse to automate.

Why the scripts do the measuring, not you

Every figure in this report is a claim about somebody else's project, and hand-collected figures were measured wrong before this skill was rebuilt around scripts: GitHub contributor counts said five-plus people maintain lodash where npm's ACL says one, and gh saw zero downloads for a package that moves 164 million a week. Do not estimate maintainer counts, downloads, staleness, or CVE history from gh, web search, or memory — run the collector, and quote what it measured.

The scripts enforce two rules worth knowing before you read their output:

  • Unavailable data is never evidence of risk. Every criterion resolves to assessed-clean, assessed-flagged, or unassessable-with-a-reason.
  • An absent measurement is never a clean verdict. A run that measured nothing exits non-zero instead of printing a report that finds nothing.

Workflow

  1. Confirm the target directory has manifests: package.json, pyproject.toml, requirements*.txt, or go.mod. If none exist, say so and stop — do not audit an ecosystem this collector does not parse by hand. Lockfiles read for exact versions and the transitive sweep: package-lock.json/npm-shrinkwrap.json, uv.lock, and a go 1.17+ go.mod. yarn.lock, pnpm-lock.yaml, and poetry.lock are not read — the report says so when they are present, and versions fall back to pins or the latest release.

  2. Check gh auth status. Unauthenticated GitHub allows 60 requests/hour against 5,000, and the collector makes several per dependency; expect repository criteria to come back unassessable without it. Say so rather than fixing it silently.

  3. Collect, then render. Put outputs somewhere outside the audited repository unless asked otherwise:

    sh
    uv run {baseDir}/scripts/collect.py <project-dir> --json <out-dir>/findings.json
    uv run {baseDir}/scripts/render.py <out-dir>/findings.json --out <out-dir>/report.md

    Expect a few minutes for ~50 dependencies — several HTTP requests per dependency, more with many Go modules, and slower without authenticated gh. If collect.py exits non-zero, it is refusing to report — relay its message verbatim instead of retrying or working around it.

  4. Read report.md and findings.json. The report is the deliverable; the JSON carries the datum behind every verdict when you need to cite one.

  5. Add what the collector cannot, clearly separated from what it measured:

    • A short narrative for this reader: what to act on first, and why.
    • Upgrade paths for advisory findings — check whether the fix is a patch or a major version away.
    • Replacement candidates for abandoned or archived dependencies. Verify a candidate exists in the registry before naming it, and label these as judgment, not measurement.
    • For flagged install scripts: whether npm ci --ignore-scripts is viable for this project's build.

Style for what you add

Write added prose the way a security report reads, and apply the same register to the report addendum and the final reply alike — replies get pasted into tickets and reports verbatim. State the finding, the datum behind it, and the action.

  • Impersonal and declarative: no first or second person ("I ran the collector", "you should upgrade"), no contractions, no exclamation points.
  • Active voice, with the subject matter as the actor: "upgrading to 1.19.0 clears all 25 advisories", not "it is recommended that axios be upgraded".
  • Objective: no intensifiers or subjective framing ("very", "significant", "fortunately"), and no guesses about why the project chose what it chose.
  • Tense: past for what the audit did, present for the state of the dependencies, future for the consequences of acting or not.
  • Constructive: a recommendation names the action and its cost, never a culprit.

If the report-writing:writing-style skill is available in the session, follow it — it is the full version of this register.

The rendered report carries facts only. The interpretive rules below are instructions to you, not content for the reader — do not copy them into the deliverable as caveats or framing.

Show full SKILL.md (301 more words)Show less

Reading the report

  • Unassessable is not risk. PyPI publishes no maintainer ACL and Go has no registry; those rows say what could not be known, not what is wrong.
  • The coverage table bounds every claim. "No advisories" means "none among what was assessed" — check the assessed count before repeating a clean verdict.
  • Quote figures verbatim. Do not re-derive, round, or embellish the report's numbers; every one is reproducible from the artifact.
  • Absence from the findings is not endorsement. A dependency with no findings was measured against these criteria only.

Rationalizations to reject

  • "gh can give me maintainer counts faster than the collector." Measured wrong — repo contributors and registry publish rights are different populations.
  • "No findings, so the dependencies are safe." Read the coverage table; on PyPI and Go, half the criteria are structurally unassessable.
  • "The unassessable rows would just confuse the reader; I'll drop them." They are the boundary of every claim in the report. Dropping them turns partial coverage into a clean bill of health, which is the failure this skill was rebuilt to prevent.
  • "The version is probably close enough." A range checked at latest-release and a lockfile-resolved version are different claims; the report labels which one it makes. Keep the label.

When not to use

  • License compliance auditing.
  • Scanning the target's own source for vulnerabilities or secrets — this skill never reads dependency source, only registry, advisory, and repository metadata.
  • Judging whether the project installs or builds. The audit is designed to work from nothing more than the dependency list — manifests and lockfiles — and never installs, builds, or executes anything. Broken installs and import-time breakage are out of scope, and worth saying so if the user seems to expect them.
  • Ecosystems other than npm, PyPI, and Go; say the ecosystem is unsupported rather than improvising an audit for it.

© trailofbits, CC-BY-SA-4.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 12 other files (scripts, assets) in plugins/supply-chain-risk-auditor/skills/supply-chain-risk-auditor of trailofbits/skills.

  • SKILL.md
  • agents/openai.yaml
  • assets/trail-of-bits-mark.svg
  • scripts/collect.py
  • scripts/model.py
  • scripts/pyproject.toml
  • scripts/render.py
  • scripts/sources.py
  • scripts/test_collect.py
  • scripts/test_model.py
  • scripts/test_render.py
  • scripts/test_sources.py
  • scripts/uv.lock

Open the folder on GitHubat commit 442fc9d

Compare with similar skills

Supply Chain Risk Auditor next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Supply Chain Risk Auditor compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Supply Chain Risk Auditor this skilltrailofbits/skills7.5k—~1.7kAutomated safety check: NotesCC-BY-SA-4.0
Dependency Update Auditbacknotprop/plannotator9.3k—~1.8kAutomated safety check: PassApache-2.0
Dependency Auditbriiirussell/cybersecurity-skills413—~3.2kAutomated safety check: WarnMIT
npm Supply Chain Securitybodadotsh/npm-security-best-practices858—~1kAutomated safety check: WarnMIT
npm Supply Chain Checkmajiayu000/spellbook287—~1.5kAutomated safety check: PassMIT
Interlinked Supply ChainQuentinCody/interlinked-cli178—~2.8kAutomated safety check: PassMIT

Similar skills

  • Dependency Update Audit

    backnotprop/plannotator

    Audits outdated npm and Bun packages for supply chain integrity before bumping them, deferring risky ones and logging every decision.

    9.3k GitHub stars~1.8k tokensUpdated today
    SecurityAuto-check passed
  • Dependency Audit

    briiirussell/cybersecurity-skills

    Audit project dependencies, frameworks, languages, and dev tools for known vulnerabilities, CVEs, and security anti-patterns.

    413 GitHub stars~3.2k tokensUpdated 4 mo ago
    SecurityAuto-check: warnings
  • npm Supply Chain Security

    bodadotsh/npm-security-best-practices

    Applies safer package manager defaults and dependency vetting to JavaScript and TypeScript projects to reduce supply-chain attack risk.

    858 GitHub stars~1k tokensUpdated 9 days ago
    SecurityAuto-check: warnings
  • npm Supply Chain Check

    majiayu000/spellbook

    Scans a repository, its lockfiles and node_modules for known malicious npm package versions and install-time indicators, using a read-only Python scanner.

    287 GitHub stars~1.5k tokensUpdated yesterday
    SecurityAuto-check passed
  • Interlinked Supply Chain

    QuentinCody/interlinked-cli

    Respond to blocked package installs and manage the Interlinked supply-chain allowlist.

    178 GitHub stars~2.8k tokensUpdated today
    SecurityAuto-check passed
  • Detecting Typosquatting Packages

    mukul975/Anthropic-Cybersecurity-Skills

    Flag misspelled, brandjacked, and typosquatted package names across npm, PyPI, and crates.io before installation, using edit-distance, keyboard-proximity, and known-target corpus matching with…

    34k GitHub stars~3k tokensUpdated 1 mo ago
    SecurityAuto-check passed

More from trailofbits/skills

All 79 skills in this repo
  • CodeQL Security Scan

    trailofbits/skills

    Official

    Scans a codebase for vulnerabilities with CodeQL's data flow and taint tracking in run-all or important-only modes, including data extensions for project-specific sources and sinks.

    7.5k GitHub stars~4.6k tokensUpdated today
    Auto-check: notes
  • Code Graph Mermaid Diagrams

    trailofbits/skills

    Official

    Generates Mermaid diagrams from Trailmark code graphs, including call graphs, class hierarchies, module dependency maps, complexity heatmaps and attack surface data flows.

    7.5k GitHub stars~1.7k tokensUpdated today
    Auto-check passed
  • Trailmark Graph Evolution

    trailofbits/skills

    Official

    Compares Trailmark code graphs at two snapshots, such as commits, tags or directories, to surface attack paths, blast radius and taint changes that text diffs miss.

    7.5k GitHub stars~3.4k tokensUpdated today
    Auto-check passed
  • Let Fate Decide

    trailofbits/skills

    Official

    Draws a 12 Houses tarot spread to break ties when a request is vague or casually delegated, then reads the cards to pick the next step.

    7.5k GitHub stars~2.5k tokensUpdated today
    Auto-check: notes
  • Semgrep Security Scan

    trailofbits/skills

    Official

    Detects languages, proposes rulesets for approval, then runs the approved Semgrep scan across a codebase and merges the output into one SARIF file.

    7.5k GitHub stars~3.7k tokensUpdated today
    Auto-check: notes
  • Burp Suite Project Parser

    trailofbits/skills

    Official

    Searches and extracts data from Burp Suite project files on the command line: regex searches over responses, audit findings, proxy history and site map data.

    7.5k GitHub starsUsed in 3 repos~4.2k tokens
    Auto-check: notes

Works with

Categories

Questions about Supply Chain Risk Auditor

What does Supply Chain Risk Auditor do?

Audits a project's dependencies for supply-chain risk: version-matched advisories for direct dependencies and the full lockfile tree, abandoned or archived upstreams, npm publisher concentration…. Supply Chain Risk Auditor is an agent skill from trailofbits/skills, published by the product's own GitHub organization. Audits a project's dependencies for supply-chain risk: version-matched advisories for direct dependencies and the full lockfile tree, abandoned or archived upstreams, npm publisher concentration, and install-time script execution.

When should I use Supply Chain Risk Auditor?

Supply Chain Risk Auditor fits situations like: asked to audit dependencies; assess supply-chain; third-party package risk; review a dependency tree before an engagement.

How do I install Supply Chain Risk Auditor in Claude Code?

Run `npx skills add trailofbits/skills --skill supply-chain-risk-auditor -a claude-code`. Or copy the skill folder (plugins/supply-chain-risk-auditor/skills/supply-chain-risk-auditor in trailofbits/skills) into .claude/skills/supply-chain-risk-auditor in your project. Claude Code loads it when a task matches its description.

How do I install Supply Chain Risk Auditor in Codex?

Run `npx skills add trailofbits/skills --skill supply-chain-risk-auditor -a codex`. Or copy the skill folder (plugins/supply-chain-risk-auditor/skills/supply-chain-risk-auditor in trailofbits/skills) into .agents/skills/supply-chain-risk-auditor in your project. Codex loads it when a task matches its description.

Can I use Supply Chain Risk Auditor in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add trailofbits/skills --skill supply-chain-risk-auditor -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/supply-chain-risk-auditor, .gemini/skills/supply-chain-risk-auditor, .github/skills/supply-chain-risk-auditor and .opencode/skills/supply-chain-risk-auditor in your project.

What does Supply Chain Risk Auditor need to run?

Going by SKILL.md and its folder, Supply Chain Risk Auditor needs Python for the scripts in its folder and the command-line tools its instructions call (uv, gh and npm). Our summary lists: Python 3. Its frontmatter pre-approves these tools: Read, Write, Bash, Glob, Grep.

Does Supply Chain Risk Auditor access the network?

SKILL.md contains no URLs. Its commands use uv, gh and npm, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Supply Chain Risk Auditor safe to install?

Our automated static check of SKILL.md found notes only (pre-approves every shell command (allowed-tools: bash)), nothing it rates as a warning. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Supply Chain Risk Auditor use?

Supply Chain Risk Auditor is published under the CC-BY-SA-4.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Supply Chain Risk Auditor use?

About 1.7k tokens (SKILL.md is roughly 7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Supply Chain Risk Auditor?

Skills that share tags, products or a category with Supply Chain Risk Auditor: Dependency Update Audit (backnotprop/plannotator, 9.3k stars), Dependency Audit (briiirussell/cybersecurity-skills, 413 stars), npm Supply Chain Security (bodadotsh/npm-security-best-practices, 858 stars) and npm Supply Chain Check (majiayu000/spellbook, 287 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Supply Chain Risk Auditor?

trailofbits (a GitHub organization, an official publisher) maintains it in trailofbits/skills, which has 7,455 GitHub stars. The repository holds 79 skills in this directory. The repository was last updated on October 9, 2026.

Source: trailofbits/skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.