npm-supply-chain-check

SKILLFlusso di lavorocommunity
v0.0.0majiayu000MITAggiornato 8 g faFonte →

Detect known malicious npm package versions and install-time supply-chain indicators in repositories, lockfiles, and node_modules. Use when a user mentions an npm compromise, Shai-Hulud, the Keyv/cacheable incident, suspicious preinstall scripts, credential-stealing packages, or asks whether a JavaS

Community-submitted skill. Not yet reviewed by the Forge team. Full prompt content may not be available.Request review →
263Stelle del repo
1Client
1Formati
8 g faUltimo aggiornamento
Skill
Autoremajiayu000
Versione0.0.0
LicenzaMIT
CategoriaFlusso di lavoro
Formatiskill.md
PromptNon pubblicato
Compatibilità
Claude✓ Supportato
Cursor
Copilot
ChatGPT
Gemini
Descrizione

Detect known malicious npm package versions and install-time supply-chain indicators in repositories, lockfiles, and node_modules. Use when a user mentions an npm compromise, Shai-Hulud, the Keyv/cacheable incident, suspicious preinstall scripts, credential-stealing packages, or asks whether a JavaScript project was exposed to a package supply-chain attack. Do not use as a general CVE or license a

Parole chiave
skillclaude