
Supply Chain Risk Auditor
Securityby trailofbits
3/3 audits passCC-BY-SA-4.0
Audits a project's dependencies for supply-chain risk: version-matched advisories for direct dependencies and the full lockfile tree, abandoned or archived upstreams, npm publisher concentration, and install-time script…
Supply Chain Risk Auditor is a Trail of Bits skill (publisher trailofbits, CC-BY-SA-4.0) that produces a supply-chain risk report for a project's direct npm, PyPI and Go dependencies, plus an advisory sweep of everything the lockfile resolves. It checks version-matched advisories, abandoned or archived upstreams, npm publisher concentration and install-time script execution. Two bundled Python scripts do the measuring (collect.py, then render.py), because the skill states that hand-collected maintainer and download figures were wrong before; the agent is told never to estimate these from memory or web search. Two rules are enforced: unavailable data is never evidence of risk, and an absent measurement is never a clean verdict. The agent then adds judgment clearly separated from measurement: upgrade paths, verified replacement candidates and whether npm ci --ignore-scripts is viable, written in an impersonal security-report register.
Use it before an engagement or when assessing third-party package risk. It does not audit licences, scan your own source for vulnerabilities, install or build anything, or cover ecosystems beyond npm, PyPI and Go. It notes that yarn.lock, pnpm-lock.yaml and poetry.lock are not read.
This skill is for coding agents such as Claude Code. Its value depends on the bundled scripts, which BusinessMCP does not run; an imported copy is instructions only.
What you can do with it
- Audit a project's dependencies before a security engagement
- Find direct dependencies with known advisories and fix paths
- Flag npm packages that run install-time scripts
- Identify archived or abandoned upstream repositories
Run it on your business data
Imported into BusinessMCP, Supply Chain Risk Auditor becomes a playbook your AI business analyst applies to your connected GitHub repositories.
Use Supply Chain Risk Auditor in BusinessMCPInstall it in a coding agent
One command adds Supply Chain Risk Auditor to your project.
npx skills add https://github.com/trailofbits/skills --skill supply-chain-risk-auditorHow we vetted it
- Source
- trailofbits/skills at 0cc1c73
- Licence
- CC-BY-SA-4.0
- Security audits (skills.sh)
- Gen Agent Trust Hub: Pass · Socket: Pass · Snyk: Pass
- Bundled scripts
- Yes — read them before installing
Checked 2026-09-25 against its skills.sh listing. How we vet skills
Related skills
All skillsSemgrep
Runs a Semgrep security scan over a codebase: detects languages, selects rulesets, presents the plan for explicit approval, then runs every approved ruleset through scripts/run-scans.sh, which batches the semgrep…
Security and Hardening
Hardens code against vulnerabilities. Use when auditing an input handler for vulnerabilities, when handling user input, authentication, data storage, or external integrations, or when checking a login flow is safe…
Differential Review
Performs security-focused differential review of code changes. Adapts analysis depth to codebase size, uses git blame for context, calculates blast radius by counting callers, checks test coverage of modified code, and…
Frequently asked questions
Which ecosystems does Supply Chain Risk Auditor support?
npm, PyPI and Go. For other ecosystems the skill tells the agent to say they are unsupported rather than improvise an audit.
Does it install or execute the dependencies?
No. It works from manifests and lockfiles plus registry, advisory and repository metadata, and never installs, builds or executes anything.
How do I install Supply Chain Risk Auditor?
Run `npx skills add trailofbits/skills --skill supply-chain-risk-auditor`, or import it from the BusinessMCP dashboard, where only its instructions are kept and its collector scripts are not run.
Run Supply Chain Risk Auditor against your whole business
Free plan, no credit card.
Use Supply Chain Risk Auditor in BusinessMCP