Works with the AI tools you already use

    Claude CodeClaude CodeCursorCursorCodex CLICodex CLIMuseMuseDotsDots+22 more

    Dependency & Supply Chain Risk Gate

    1

    Audit your project's dependencies for supply-chain risk before they ship. Detects the ecosystem, runs the right vulnerability scanners against live advisory data, and adds the checks tooling misses — outdated or abandoned packages, typosquatted or suspicious names, risky install scripts, and license conflicts — then returns a prioritized fix list and a PASS / REVIEW / BLOCK verdict. It's npm audit with triage and judgment on top.

    $14

    Secure checkout via Stripe

    30-day refund guarantee

    Converts to your local currency at checkout

    4 installsSecurity scanned
    Dependency & Supply Chain Risk Gate

    Dependency & Supply Chain Risk Gate

    Example session with this skill installed

    Audit the dependencies in this Node project — are we safe to ship?

    • Read your context and instructions
    • Compiled the dependency & supply

    A risk report: BLOCK on a high-severity prototype-pollution CVE in a transitive lodash version (safe minor-bump fix, top of the fix list); REVIEW a direct dependency whose repo was archived three years ago (plan a replacement); and a flag that a package named "reqeusts" may be a typosquat of "requests" — worth verifying, not assumed malicious. Verdict: BLOCK until the lodash fix lands.

    Connects securely to your tools. The creator never sees your data.

    What you get

    Audit a repo's dependencies for known vulnerabilities before a release.Review a lockfile or a dependency-bump PR before merging it.Catch abandoned, deprecated, or typosquatted packages in your tree.Check license risk across your dependencies for a proprietary project.

    About this skill

    Most of a project's risk isn't in code the team wrote — it's in the hundreds of transitive packages it pulled in: known CVEs, abandoned libraries, a typosquatted name one character off a popular package, an install script doing something it shouldn't, or a copyleft license in a proprietary product. This gate orchestrates the right tooling and adds the human-judgment layer scanners can't:

    • Detects the ecosystem and lockfiles (npm/pnpm/yarn, pip/Poetry, Go, Cargo, Bundler, Maven, and more)
    • Runs the appropriate scanner against live advisory data — never stale memory of CVEs
    • Triages by severity × reachability × fix availability, flagging breaking-change fixes
    • Flags outdated, deprecated, and abandoned packages
    • Surfaces supply-chain signals tooling misses — typosquatting, low-trust packages, risky install scripts, non-registry sources, ownership changes — flagged to verify, never accused
    • Checks license risk (informational, not legal advice)
    • Returns a prioritized fix list and a PASS / REVIEW / BLOCK verdict

    It catches the fixable critical that actually matters and tells you the one upgrade to make first — not a wall of raw audit output.

    How to install

    Works the same in every agent - Claude, Cursor, Codex, Copilot and 20+ more.

    ~30 seconds
    1. 1

      Download the ZIP

      Free skills download straight away. Paid skills unlock right after purchase.

    2. 2

      Unzip into your skills folder

      Every agent reads skills from one folder on your machine. Drop the unzipped folder in there.

    3. 3

      Ask your agent to use it

      Restart the agent if it was already running. It picks the skill up automatically - no config needed.

    Skills folder by agent

    Click the path to copy it. Create the folder if it does not exist yet.

    Reviews

    No reviews yet

    Be one of the first to try it. Every listed skill passes our trust checks below.

    Security scanned

    Passed our 8-point scan before listing

    4 installs

    Downloaded by developers to date

    30-day refund

    Not a fit? Get your money back

    Trust & safety

    Security scanned

    Verified clean 3 months ago

    • Passed all security checks, Safe to install

    Listed3 months ago
    Updated2 days ago

    What's inside

    Frequently Asked Questions