dependency-supply-chain

SKILLWorkflowcommunity
v0.0.0GoldenWing-360MITUpdated 13d agoSource →

Audit and defend against malicious dependencies in npm, pnpm, PyPI, and similar ecosystems. Covers lockfile hygiene, the limits of npm audit, behavior-level scanning with socket.dev, postinstall script review, typosquat and slopsquat detection, and minimum-permission CI runs. Invoke when adding a ne

Community-submitted skill. Not yet reviewed by the Forge team. Full prompt content may not be available.Request review →
15Repo stars
1Clients
1Formats
13d agoLast update
Skill
AuthorGoldenWing-360
Version0.0.0
LicenseMIT
CategoryWorkflow
Formatsskill.md
PromptNot published
Compatibility
Claude✓ Supported
Cursor
Copilot
ChatGPT
Gemini
About

Audit and defend against malicious dependencies in npm, pnpm, PyPI, and similar ecosystems. Covers lockfile hygiene, the limits of npm audit, behavior-level scanning with socket.dev, postinstall script review, typosquat and slopsquat detection, and minimum-permission CI runs. Invoke when adding a new dependency, after a supply-chain incident, or as periodic audit.

Keywords
skillclaude