supply-chain-risk-auditor

Supply chain risk auditor

supply-chain-risk-auditor is Trail of Bits' agent skill for auditing a project's npm, PyPI and Go dependencies for known advisories, abandoned upstreams, publisher concentration and install scripts, measured by bundled scripts.

Install Supply chain risk auditor

Install this skill with the skills CLI

Terminal
npx skills add trailofbits/skills --skill supply-chain-risk-auditor

Or, in Claude Code, add Trail of Bits' plugin marketplace

Terminal
/plugin marketplace add trailofbits/skills

Or, in Codex, add the same marketplace from your terminal

Terminal
codex plugin marketplace add trailofbits/skills

Then install the supply-chain-risk-auditor plugin in Codex

Terminal
codex plugin add supply-chain-risk-auditor@trailofbits

In Claude Code, open /plugin menu after adding the marketplace and install the supply-chain-risk-auditor plugin. For a ChatGPT workspace, Trail of Bits' README says to import the repository's .claude-plugin/marketplace.json.

Or paste this into your coding agent: Install the agent skill supply-chain-risk-auditor from github.com/trailofbits/skills. A skill can include scripts that run on your computer, so read its source first.

What Supply chain risk auditor does

supply-chain-risk-auditor is an agent skill from security firm Trail of Bits that produces a risk report for a project's direct dependencies on npm, PyPI and Go, plus an advisory sweep of everything the lockfile resolves. It checks version-matched security advisories, archived or abandoned upstream repositories, how few people can publish a package on npm, and scripts that run at install time.

The measuring in supply-chain-risk-auditor is done by two bundled Python scripts, not by the agent. Trail of Bits explains why: hand-collected figures were wrong before, such as GitHub contributor counts suggesting five maintainers where npm showed one. The scripts mark each criterion as clean, flagged or unassessable with a reason, and refuse to print a report when they measured nothing.

The agent adds only judgment, kept apart from the measured data: what to fix first, whether an advisory fix is a patch or a major upgrade away, replacement candidates for abandoned packages, and whether npm ci with install scripts disabled would work. It reads lockfiles from npm (package-lock), uv and Go modules; it does not read poetry.lock, pnpm-lock.yaml or yarn.lock.

When to use Supply chain risk auditor

  • You want to know which of your dependencies have known vulnerabilities at the versions you use.
  • You suspect some of your packages are abandoned or archived upstream.
  • You are about to start a security engagement and need a dependency risk baseline.
  • You want to know which npm packages run scripts when they install.

When to pick something else

  • License compliance checks or scanning your own source code for secrets: the skill does neither.
  • Projects outside npm, PyPI and Go, such as Rust crates or Maven.

What Supply chain risk auditor needs

  • uv to run the bundled scripts
  • The GitHub CLI signed in; without it GitHub allows 60 requests an hour and repository checks come back unassessable
  • A package.json, pyproject.toml, requirements file or go.mod

Which agents Supply chain risk auditor works in

Trail of Bits documents Supply chain risk auditor for Claude Code, Codex, ChatGPT workspace marketplace. The open skills CLI also installs it into 78 agents, including Claude Code, Codex, Cursor, Gemini CLI, GitHub Copilot, OpenCode (we listed it with the CLI on October 1, 2026). See where each agent looks for skills.

Supply chain risk auditor license

Supply chain risk auditor is published under CC-BY-SA-4.0. CC-BY-SA-4.0 is a share-alike license. You can copy the skill into a project and change it, even for commercial work, if you credit Trail of Bits, link the license and say what you changed. If you share a changed version, for example in a public repository, it must stay under CC-BY-SA-4.0. It is a content license, not a software license, so ask your legal team before bundling it inside a closed product.

Questions people ask

Can I copy Trail of Bits' supply-chain-risk-auditor skill into my own repository?

Yes, with conditions. The skills are CC-BY-SA-4.0. You may copy and adapt them, even commercially, if you credit Trail of Bits, link the license and note your changes. Any changed version you share must carry the same CC-BY-SA-4.0 license. Using the skill unchanged in your own work does not put your code under that license.

Does supply-chain-risk-auditor support pnpm or Yarn lockfiles?

Not on 2026-10-01. It reads package-lock.json, npm-shrinkwrap.json, uv.lock and Go 1.17+ go.mod files. When yarn.lock, pnpm-lock.yaml or poetry.lock are present, the report notes this, and it uses pinned versions or, without them, the latest release.

  • Firebase security rules auditor: firebase-security-rules-auditor is the Firebase team's agent skill for auditing Firestore and Cloud Storage security rules for privilege escalation, update bypasses and missing limits, returning a 1 to 5 score in JSON. (462 repository stars on October 2, 2026)
  • GitHub Actions security review: gha-security-review is Sentry's agent skill for auditing GitHub Actions workflows for attacks an outsider can run, such as pwn requests, expression injection and credential theft, with a concrete exploit for each finding. (1,031 repository stars on October 2, 2026)
  • Security review: security-review is Sentry's agent skill for reviewing code for exploitable vulnerabilities, such as injection, XSS, broken access control and weak crypto, reporting only findings it has confirmed with high confidence. (1,031 repository stars on October 2, 2026)
  • Differential review: differential-review is Trail of Bits' agent skill for security review of a pull request, commit or diff, using git history, blast radius counts and test coverage, and ending in a written markdown report. (7,328 repository stars on October 2, 2026)

More from Trail of Bits

  • Mutation testing: mutation-testing is Trail of Bits' agent skill for configuring mutation testing campaigns with its mewt or muton tools, reading surviving mutants, telling equivalent mutants from real test gaps, and hunting bugs they expose. (7,328 repository stars on October 2, 2026)
  • Semgrep rule creator: semgrep-rule-creator is Trail of Bits' agent skill for writing custom Semgrep rules that detect vulnerabilities and bug patterns, test-first, with taint mode preferred and every test required to pass. (7,328 repository stars on October 2, 2026)

Lists that include supply-chain-risk-auditor