PlugMyPlugin
← Browse

supply-chain-risk-auditor

trailofbits ★ 7317

This plugin audits a project's npm, PyPI, and Go dependencies for supply-chain risks by checking version-matched advisories (OSV), deprecated packages, abandoned repositories, publisher concentration, and install scripts. It generates a deterministic Markdown report with clear separation between measured data and model-provided narrative and remediation guidance.

Security Project Management free prompt pack

Install

> /plugin marketplace add trailofbits/skills/tree/HEAD/plugins/supply-chain-risk-auditor
> /plugin install supply-chain-risk-auditor

Source: https://github.com/trailofbits/skills/tree/HEAD/plugins/supply-chain-risk-auditor

What it's made of

1 skill

Commands
0
Agents
0
Skills
1
MCP servers
0
Hooks
0

What it needs & plugs into

API keys
none
Paid services
none detected
External tools
none
Talks to
nothing external detected

Facts extracted from the plugin's files. Prose generated by claude-haiku-4-5-20251001.

Is this your plugin?

Claim it to keep the card accurate and enter the weekly contest. Requires signing in as the GitHub owner (trailofbits).