← Browse
supply-chain-risk-auditor
trailofbits ★ 7317
This plugin audits a project's npm, PyPI, and Go dependencies for supply-chain risks by checking version-matched advisories (OSV), deprecated packages, abandoned repositories, publisher concentration, and install scripts. It generates a deterministic Markdown report with clear separation between measured data and model-provided narrative and remediation guidance.
Install
> /plugin marketplace add trailofbits/skills/tree/HEAD/plugins/supply-chain-risk-auditor
> /plugin install supply-chain-risk-auditor
Source: https://github.com/trailofbits/skills/tree/HEAD/plugins/supply-chain-risk-auditor
What it's made of
1 skill
- Commands
- 0
- Agents
- 0
- Skills
- 1
- MCP servers
- 0
- Hooks
- 0
What it needs & plugs into
- API keys
- none
- Paid services
- none detected
- External tools
- none
- Talks to
- nothing external detected
Facts extracted from the plugin's files. Prose generated by claude-haiku-4-5-20251001.
Is this your plugin?
Claim it to keep the card accurate and enter the weekly contest. Requires signing in as the GitHub owner (trailofbits).