See which dependencies deserve attention first.
software supply chain
Generates a report identifying dependency advisories, abandoned upstreams, publisher concentration, and install-time script risks.
When to use it
Use it to audit dependencies, assess supply-chain risk, or review a dependency tree before an engagement.
Give it a project; it collects dependency findings and writes a rendered risk report and supporting JSON outside the project by default.
What you provide
This skill
GitHub
Checks GitHub repository metadata
npm registry
Reads npm registry metadata
PyPI registry
Reads PyPI registry metadata
OSV
Queries OSV for advisories
The bundled collector and renderer require Python 3.11 or later.
The workflow invokes both bundled scripts with uv.
The workflow checks GitHub authentication through the gh CLI.
An authenticated GitHub account increases the request allowance and enables more repository criteria to be assessed.