Works with the AI tools you already use
Dependency & Supply Chain Risk Gate
Audit your project's dependencies for supply-chain risk before they ship. Detects the ecosystem, runs the right vulnerability scanners against live advisory data, and adds the checks tooling misses — outdated or abandoned packages, typosquatted or suspicious names, risky install scripts, and license conflicts — then returns a prioritized fix list and a PASS / REVIEW / BLOCK verdict. It's npm audit with triage and judgment on top.
$14
Dependency & Supply Chain Risk Gate
Example session with this skill installed
Audit the dependencies in this Node project — are we safe to ship?
- Read your context and instructions
- Compiled the dependency & supply
A risk report: BLOCK on a high-severity prototype-pollution CVE in a transitive lodash version (safe minor-bump fix, top of the fix list); REVIEW a direct dependency whose repo was archived three years ago (plan a replacement); and a flag that a package named "reqeusts" may be a typosquat of "requests" — worth verifying, not assumed malicious. Verdict: BLOCK until the lodash fix lands.
Connects securely to your tools. The creator never sees your data.
What you get
About this skill
Most of a project's risk isn't in code the team wrote — it's in the hundreds of transitive packages it pulled in: known CVEs, abandoned libraries, a typosquatted name one character off a popular package, an install script doing something it shouldn't, or a copyleft license in a proprietary product. This gate orchestrates the right tooling and adds the human-judgment layer scanners can't:
- Detects the ecosystem and lockfiles (npm/pnpm/yarn, pip/Poetry, Go, Cargo, Bundler, Maven, and more)
- Runs the appropriate scanner against live advisory data — never stale memory of CVEs
- Triages by severity × reachability × fix availability, flagging breaking-change fixes
- Flags outdated, deprecated, and abandoned packages
- Surfaces supply-chain signals tooling misses — typosquatting, low-trust packages, risky install scripts, non-registry sources, ownership changes — flagged to verify, never accused
- Checks license risk (informational, not legal advice)
- Returns a prioritized fix list and a PASS / REVIEW / BLOCK verdict
It catches the fixable critical that actually matters and tells you the one upgrade to make first — not a wall of raw audit output.
How to install
Works the same in every agent - Claude, Cursor, Codex, Copilot and 20+ more.
- 1
Download the ZIP
Free skills download straight away. Paid skills unlock right after purchase.
- 2
Unzip into your skills folder
Every agent reads skills from one folder on your machine. Drop the unzipped folder in there.
- 3
Ask your agent to use it
Restart the agent if it was already running. It picks the skill up automatically - no config needed.
Skills folder by agent
Click the path to copy it. Create the folder if it does not exist yet.
Reviews
No reviews yet
Be one of the first to try it. Every listed skill passes our trust checks below.
Security scanned
Passed our 8-point scan before listing
4 installs
Downloaded by developers to date
30-day refund
Not a fit? Get your money back
Trust & safety
Security scanned
Verified clean 3 months ago
- Passed all security checks, Safe to install