dependency-supply-chain

SKILLWorkflowcommunauté
v0.0.0GoldenWing-360MITMis à jour il y a 18 jSource →

Audit and defend against malicious dependencies in npm, pnpm, PyPI, and similar ecosystems. Covers lockfile hygiene, the limits of npm audit, behavior-level scanning with socket.dev, postinstall script review, typosquat and slopsquat detection, and minimum-permission CI runs. Invoke when adding a ne

Community-submitted skill. Not yet reviewed by the Forge team. Full prompt content may not be available.Request review →
15Étoiles du dépôt
1Clients
1Formats
il y a 18 jDernière mise à jour
Skill
AuteurGoldenWing-360
Version0.0.0
LicenceMIT
CatégorieWorkflow
Formatsskill.md
PromptNon publié
Compatibilité
Claude✓ Pris en charge
Cursor
Copilot
ChatGPT
Gemini
À propos

Audit and defend against malicious dependencies in npm, pnpm, PyPI, and similar ecosystems. Covers lockfile hygiene, the limits of npm audit, behavior-level scanning with socket.dev, postinstall script review, typosquat and slopsquat detection, and minimum-permission CI runs. Invoke when adding a new dependency, after a supply-chain incident, or as periodic audit.

Mots-clés
skillclaude