Skills Explorer Add Skills

supply-chain-risk-auditor

An agent skill by trailofbits, from trailofbits/skills. Tags: analysis, compliance, dependencies, security.

What it does

Audits a project's dependencies for supply-chain risk: version-matched advisories for direct dependencies and the full lockfile tree, abandoned or archived upstreams, npm publisher concentration, and install-time script execution. Use when asked to audit dependencies, assess supply-chain or third-party package risk, or review a dependency tree before an engagement.

Install

With the skills CLI, which installs into Claude Code, Codex, Cursor and other agents:

npx skills add trailofbits/skills --skill supply-chain-risk-auditor

Or copy the skill folder into Claude Code's skills directory by hand (~/.claude/skills for every project, or .claude/skills inside one):

git clone --depth 1 https://github.com/trailofbits/skills
cp -r skills/plugins/supply-chain-risk-auditor/skills/supply-chain-risk-auditor ~/.claude/skills/supply-chain-risk-auditor

Safety box score

Not rated yet. A safety box score grades what a skill and its scripts can reach on the machine of whoever installs it, across eight categories from shell execution to secrets access. Anyone can request one from this page; it is saved for everyone. How the score works.

Source

Repository
trailofbits/skills (all skills from this repository)
Path
plugins/supply-chain-risk-auditor/skills/supply-chain-risk-auditor/SKILL.md
Branch
main
Collection
supply-chain-risk-auditor
Updated
2026-09-19