BusinessMCP
Supply Chain Risk Auditor logo

Supply Chain Risk Auditor

Security

by trailofbits

3/3 audits passCC-BY-SA-4.0

Use Supply Chain Risk Auditor in BusinessMCP

Free · imported in one click after signup

View on GitHub

Audits a project's dependencies for supply-chain risk: version-matched advisories for direct dependencies and the full lockfile tree, abandoned or archived upstreams, npm publisher concentration, and install-time script…

Supply Chain Risk Auditor is a Trail of Bits skill (publisher trailofbits, CC-BY-SA-4.0) that produces a supply-chain risk report for a project's direct npm, PyPI and Go dependencies, plus an advisory sweep of everything the lockfile resolves. It checks version-matched advisories, abandoned or archived upstreams, npm publisher concentration and install-time script execution. Two bundled Python scripts do the measuring (collect.py, then render.py), because the skill states that hand-collected maintainer and download figures were wrong before; the agent is told never to estimate these from memory or web search. Two rules are enforced: unavailable data is never evidence of risk, and an absent measurement is never a clean verdict. The agent then adds judgment clearly separated from measurement: upgrade paths, verified replacement candidates and whether npm ci --ignore-scripts is viable, written in an impersonal security-report register.

Use it before an engagement or when assessing third-party package risk. It does not audit licences, scan your own source for vulnerabilities, install or build anything, or cover ecosystems beyond npm, PyPI and Go. It notes that yarn.lock, pnpm-lock.yaml and poetry.lock are not read.

This skill is for coding agents such as Claude Code. Its value depends on the bundled scripts, which BusinessMCP does not run; an imported copy is instructions only.

What you can do with it

  • Audit a project's dependencies before a security engagement
  • Find direct dependencies with known advisories and fix paths
  • Flag npm packages that run install-time scripts
  • Identify archived or abandoned upstream repositories

Run it on your business data

Imported into BusinessMCP, Supply Chain Risk Auditor becomes a playbook your AI business analyst applies to your connected GitHub repositories.

Use Supply Chain Risk Auditor in BusinessMCP

Install it in a coding agent

One command adds Supply Chain Risk Auditor to your project.

npx skills add https://github.com/trailofbits/skills --skill supply-chain-risk-auditor

How we vetted it

Source
trailofbits/skills at 0cc1c73
Licence
CC-BY-SA-4.0
Security audits (skills.sh)
Gen Agent Trust Hub: Pass · Socket: Pass · Snyk: Pass
Bundled scripts
Yes — read them before installing

Checked 2026-09-25 against its skills.sh listing. How we vet skills

Frequently asked questions

Which ecosystems does Supply Chain Risk Auditor support?

npm, PyPI and Go. For other ecosystems the skill tells the agent to say they are unsupported rather than improvise an audit.

Does it install or execute the dependencies?

No. It works from manifests and lockfiles plus registry, advisory and repository metadata, and never installs, builds or executes anything.

How do I install Supply Chain Risk Auditor?

Run `npx skills add trailofbits/skills --skill supply-chain-risk-auditor`, or import it from the BusinessMCP dashboard, where only its instructions are kept and its collector scripts are not run.

Run Supply Chain Risk Auditor against your whole business

Free plan, no credit card.

Use Supply Chain Risk Auditor in BusinessMCP