Supply Chain Risk Auditor
Audit a project's npm, PyPI, and Go dependencies for supply-chain risk: version-matched advisories for direct dependencies and the full lockfile tree, abandoned upstreams, npm publisher concentration, and install scripts
- Type
- Plugin
- Repository
- trailofbits/skills
- GitHub stars
- 7.3k
- License
- CC-BY-SA-4.0
- Repo last updated
- Sep 25, 2026
- Version
- 2.0.4
- Author
- Eric Quintero
What Supply Chain Risk Auditor is
Supply Chain Risk Auditor is a plugin published in the trailofbits/skills repository on GitHub, which has about 7.3k stars. The repository describes itself as: “Trail of Bits Claude Code skills for security research, vulnerability detection, and audit workflows”
A plugin is a package that bundles skills, slash commands, subagents, hooks, and MCP connectors so they install together. Plugins are plain files with a manifest at .claude-plugin/plugin.json, and they work in both Claude Code and Claude Cowork.
Installing Supply Chain Risk Auditor adds everything it ships in one step. Connectors inside a plugin still need to be connected separately, and hooks and subagents only run in Cowork and Claude Code, not in regular chat.
How to install Supply Chain Risk Auditor
Claude Code
- Add the repository as a plugin marketplace: claude plugin marketplace add trailofbits/skills
- Install the plugin: claude plugin install supply-chain-risk-auditor@<marketplace-name>, using the marketplace name from the repository's .claude-plugin/marketplace.json.
- Restart the session if the new skills or commands don't appear straight away.
Claude Cowork
- Open Customize → Plugins and choose Add marketplace.
- Enter trailofbits/skills (the owner/repo shorthand works for GitHub).
- Find Supply Chain Risk Auditor in the list, click Install, then connect any connectors it needs from its Connectors tab.
New to extending Cowork? Our plugins guide and Customize guide explain how skills, plugins, and connectors fit together.
Inside the source file
An excerpt from plugins/supply-chain-risk-auditor/.claude-plugin/plugin.json, shared under the repository's CC-BY-SA-4.0 license. Read the full file on GitHub.
Generate a supply-chain risk report for a project's direct dependencies across npm, PyPI, and Go, plus a known-advisory sweep of everything the lockfile resolves. A deterministic collector queries registries and advisory databases; a renderer turns the artifact into a Markdown report; the model adds narrative and remediation judgment on top, clearly separated from what was measured.
Author: Spencer Michaels (original), Eric Quintero (current design)
What it measures
Every criterion resolves to assessed-clean, assessed-flagged, or unassessable-with-a-reason, and the report carries a coverage table stating what could and could not be measured. Two rules are enforced by the code rather than by convention: unavailable data is never treated as evidence of risk, and an absent measurement is never a clean verdict — a run that measures nothing refuses to produce a report.
Usage
Ask Claude to "audit this project's dependencies" or "assess the supply-chain risk of this repo", or run the scripts directly:
cd skills/supply-chain-risk-auditor/scripts
uv run collect.py <project-dir> --json findings.json
uv run render.py findings.json --out report.mdRequirements: uv (the scripts are stdlib-only Python). Authenticated gh is strongly recommended — unauthenticated GitHub allows 60 requests/hour against 5,000, and the collector makes several per dependency. HTTP responses are cached (six-hour freshness bound) under the system temp directory; --offline reruns from cache alone.
Scope and audience
Written for the reader who owns or is engaged on the audited project. Direct dependencies carry the full criteria set; the transitive tree is checked for advisories only, and only where a lockfile (package-lock.json/npm-shrinkwrap.json, uv.lock, or a go 1.17+ go.mod) resolves it. yarn.lock, pnpm-lock.yaml, and poetry.lock are not read; the report notes their presence and versions fall back to manifest pins or the latest release. Dependencies that resolve from outside their public registry (workspace, git, vendored) are reported as unassessable rather than looked up by name. The report states what was not examined rather than leaving it to be inferred.
The audit is designed to be useful given nothing more than a list of dependencies: it reads manifests and lockfiles, and never installs, builds, or executes the project or its packages. Whether the pinned set actually installs or imports cleanly is out of scope, as are scanning the target's own source, reading dependency source, and license compliance.
Installation
/plugin install trailofbits/skills/plugins/supply-chain-risk-auditor Before you install
- Read the whole file first. Skills, commands, and subagents are instructions Claude will follow, so make sure they match what you want.
- Check which tools, scripts, or MCP servers it uses. Local servers and scripts run with your permissions.
- Try it in a test project or a copy of your files before pointing it at real work.
- Pin the version you tested, and review changes before updating.
- Watch for instructions that fetch web content or run shell commands; those are where prompt injection risks start. See our prompt injection guide.
FAQ
What is Supply Chain Risk Auditor?
Supply Chain Risk Auditor is a plugin for Claude Code and Claude Cowork from the trailofbits/skills repository on GitHub. Audit a project's npm, PyPI, and Go dependencies for supply-chain risk: version-matched advisories for direct dependencies and the full lockfile tree, abandoned upstreams, npm publisher concentration, and install scripts
How do I install Supply Chain Risk Auditor in Claude Code?
Add the repository as a plugin marketplace: claude plugin marketplace add trailofbits/skills Install the plugin: claude plugin install supply-chain-risk-auditor@<marketplace-name>, using the marketplace name from the repository's .claude-plugin/marketplace.json. Restart the session if the new skills or commands don't appear straight away.
Can I use Supply Chain Risk Auditor in Claude Cowork?
Open Customize → Plugins and choose Add marketplace. Enter trailofbits/skills (the owner/repo shorthand works for GitHub). Find Supply Chain Risk Auditor in the list, click Install, then connect any connectors it needs from its Connectors tab.
Is Supply Chain Risk Auditor safe to install?
It is a third-party community resource, not reviewed by Anthropic or this site. Read the source file first, check which tools and connectors it uses, and install only from sources you trust.
Similar resources
- Trailofbits:Scan Apk Scans Android APKs for Firebase security misconfigurations Slash Command · trailofbits/skills
- Trailofbits:Entry Points Identifies state-changing entry points in smart contracts Slash Command · trailofbits/skills
- Workflow Skill Reviewer Reviews workflow-based Claude Code skills for structural quality, pattern adherence, tool assignment correctness, and anti-pattern… Subagent · trailofbits/skills
- Trailofbits:Semgrep Rule Creates Semgrep rules with test-first methodology Slash Command · trailofbits/skills
- Testing Handbook Skills Skills from the Trail of Bits Application Security Testing Handbook (appsec.guide) Plugin · trailofbits/skills
- Static Analysis Static analysis toolkit with CodeQL, Semgrep, and SARIF parsing for security vulnerability detection Plugin · trailofbits/skills
- Trailmark Builds source and binary code graphs for security analysis, context slicing, mutation testing, cryptographic protocol modeling, finding triage, and variant analysis. Plugin · trailofbits/skills
- Spec To Code Compliance Check code against the documentation that specifies it: one agent per requirement, divergences refuted before they are reported, evidence cited to the line Plugin · trailofbits/skills