Catch risky package settings before they ship.
supply-chain security
Audits a JavaScript/TypeScript repository's package-manager configuration for supply-chain hardening.
When to use it
Use it when the user invokes /check-npm or asks to audit package-manager security settings in a Grafana plugin or JavaScript/TypeScript project.
Give it a JavaScript/TypeScript project; it returns a PASS/FAIL audit covering the package manager, tool version, scripts, dependency protocols, and release age.
What you provide
No additional actions listed in the analysis.
A package.json file must exist at the workspace root.