supply-chain-risk-auditor
An agent skill by trailofbits, from trailofbits/skills. Tags: analysis, compliance, dependencies, security.
What it does
Audits a project's dependencies for supply-chain risk: version-matched advisories for direct dependencies and the full lockfile tree, abandoned or archived upstreams, npm publisher concentration, and install-time script execution. Use when asked to audit dependencies, assess supply-chain or third-party package risk, or review a dependency tree before an engagement.
Install
With the skills CLI, which installs into Claude Code, Codex, Cursor and other agents:
npx skills add trailofbits/skills --skill supply-chain-risk-auditor
Or copy the skill folder into Claude Code's skills directory by hand (~/.claude/skills for every project, or .claude/skills inside one):
git clone --depth 1 https://github.com/trailofbits/skills
cp -r skills/plugins/supply-chain-risk-auditor/skills/supply-chain-risk-auditor ~/.claude/skills/supply-chain-risk-auditor
Safety box score
Not rated yet. A safety box score grades what a skill and its scripts can reach on the machine of whoever installs it, across eight categories from shell execution to secrets access. Anyone can request one from this page; it is saved for everyone. How the score works.
Source
- Repository
- trailofbits/skills (all skills from this repository)
- Path
- plugins/supply-chain-risk-auditor/skills/supply-chain-risk-auditor/SKILL.md
- Branch
- main
- Collection
- supply-chain-risk-auditor
- Updated
- 2026-09-19
Related skills
- vulnerability-triage-brocards — This skill should be used when the user asks to "triage a vulnerability report", "assess a CVE", "evaluate a bug bounty submission".
- algorand-vulnerability-scanner — Scans Algorand smart contracts for 11 common vulnerabilities including rekeying attacks, unchecked transaction fees, missing field validations.
- audit-augmentation — x binary-analysis graph exports. ).
- audit-context-building — Understand a codebase before looking for bugs in it - what each function assumes, what it guarantees, and what it depends on elsewhere.
- audit-prep-assistant — Prepares codebases for security review using Trail of Bits' checklist.
- burpsuite-project-parser — burp) from the command line.