Agent Skills: npm-supply-chain-check

Detect known malicious npm package versions and install-time supply-chain indicators in repositories, lockfiles, and node_modules. Use when a user mentions an npm compromise, Shai-Hulud, the Keyv/cacheable incident, suspicious preinstall scripts, credential-stealing packages, or asks whether a JavaScript project was exposed to a package supply-chain attack. Do not use as a general CVE or license audit.

UncategorizedID: majiayu000/claude-arsenal/npm-supply-chain-check

Install this agent skill to your local

pnpm dlx add-skill https://github.com/majiayu000/claude-arsenal/npm-supply-chain-check

Skill Files

Browse the full folder contents for npm-supply-chain-check.

Download Skill

Loading file tree…

Select a file to preview its contents.