Lightlines
Catalogue
Sign in
By trailofbits

supply-chain-risk-auditor

trailofbits

See which dependencies deserve attention first.

software supply chain

What it does

Generates a report identifying dependency advisories, abandoned upstreams, publisher concentration, and install-time script risks.

When to use it

Use it to audit dependencies, assess supply-chain risk, or review a dependency tree before an engagement.

How to use it

Give it a project; it collects dependency findings and writes a rendered risk report and supporting JSON outside the project by default.

What you provide

  • An existing project

Uses


Access · 5

This skill

GitHub

Read

Checks GitHub repository metadata

npm registry

Read

Reads npm registry metadata

PyPI registry

Read

Reads PyPI registry metadata

OSV

Read

Queries OSV for advisories

What you need · 4

The bundled collector and renderer require Python 3.11 or later.

The workflow invokes both bundled scripts with uv.

The workflow checks GitHub authentication through the gh CLI.

An authenticated GitHub account increases the request allowance and enables more repository criteria to be assessed.


About this skill

Visibility
Public
Repository
trailofbits/skills
Created
Oct 8, 2026
Updated
Oct 8, 2026
Files
13