SecurityCC-BY-SA-4.0

Supply-chain risk auditor

by Trail of Bits (opens in a new tab) trailofbits/skills

Measures dependency and lockfile supply-chain risk for npm, PyPI and Go projects.

Installation

Skills CLI

Skills CLI command
npx skills@latest add trailofbits/skills --skill supply-chain-risk-auditor

Requires Node.js and npm. Choose your agents in the installer; add -g for a global installation.

Fieldbook review

Reviewed 27 Sept 2026

Writes its report outside the audited repository and distinguishes unassessable data from a clean result. Yarn, pnpm and Poetry lockfiles are not parsed.

  • LicenceCC-BY-SA-4.0
  • FrontmatterValid name and description
  • Risky patternsNone found
  • Size123 lines
  • Last checked27 Sept 2026 · a1254b7f8d3a1731a9a7e1f9cd6c67b59cf84ed6ef7c7fb455db9a14c528ceb4

What it can touch

  • Runs commands

    Runs shell commands such as tests, builds or installs.

  • Network

    Reaches external services or the web.

  • Writes docs

    Creates or updates documents such as specs, plans or ADRs.

Read the source

Fieldbook links to the original instead of copying it, so you always read the version you install.

plugins/supply-chain-risk-auditor/skills/supply-chain-risk-auditor/SKILL.md on GitHub (opens in a new tab)