IN PLAIN ENGLISH
What it does—and when it fits
Supply Chain Risk Auditor is Trail of Bits' measured dependency-audit workflow for npm, PyPI, and Go projects. Deterministic collectors inspect direct and lockfile dependencies for advisories, abandonment, publisher concentration, and install scripts before human interpretation is added.
This is aimed at Security teams reviewing third-party dependency exposure. Compare the examples below with your task, then review the limitations, permissions, and risks before installing.
- Collect dependency evidenceMeasure supported manifests and lockfiles instead of estimating from memory.
- Separate unknown from cleanMark unavailable criteria as unassessable rather than silently passing them.
- Prioritize remediationAdd verified upgrade paths and replacement candidates to the factual report.
- Deterministic scripts preserve the datum behind each verdict.
- Refuses to treat missing measurements as clean results.
No verified review text is in the current dataset. Use the linked source for the latest discussion.
Read the source note ↗INSTALL BY AGENT
Choose your Agent
Paths come from official Agent docs or the universal installer behind skills.sh. Compatibility still follows this Skill's record.
npx skills add trailofbits/skills --skill supply-chain-risk-auditor --agent claude-codenpx skills add trailofbits/skills --skill supply-chain-risk-auditor --agent claude-code -gProject install stays with this repository for team sharing. Personal install adds -g and works across repositories.
View install paths
.claude/skills/supply-chain-risk-auditor/~/.claude/skills/supply-chain-risk-auditor/Claude Code discovers custom Skill folders automatically at project or personal scope.
View path evidence ↗TYPICAL WORKFLOW
A practical workflow
Collect dependency evidence
Measure supported manifests and lockfiles instead of estimating from memory.
Separate unknown from clean
Mark unavailable criteria as unassessable rather than silently passing them.
Prioritize remediation
Add verified upgrade paths and replacement candidates to the factual report.
THE TRADEOFFS
Advantages and tradeoffs
Notable strengths
- Deterministic scripts preserve the datum behind each verdict.
- Refuses to treat missing measurements as clean results.
Limitations
- Does not fully parse yarn.lock, pnpm-lock.yaml, poetry.lock, or unsupported ecosystems.
- Repository health and advisory data can be incomplete, delayed, or unavailable without authentication.
BEST FIT
Who it is for
Security teams reviewing third-party dependency exposure
Engineering leads assessing a dependency tree before release or engagement
BEFORE YOU USE IT
Risks to review before use
Registry and repository metadata exposure
Collection makes external requests for project dependency names and versions. Confirm that package metadata may leave the environment and keep private registry credentials scoped.
SECURITY
What the permission profile means
- Keep collector output outside the audited repository unless explicitly requested.
- Label replacement suggestions as judgment, not measured fact.
Not a security certification. External ratings are attributed references. SkillSignal has not independently executed or security-reviewed this Skill.
COMMON QUESTIONS
Supply Chain Risk Auditor Skill FAQ
What is the Supply Chain Risk Auditor Skill?
Measured dependency risk reports covering advisories, maintainers, abandonment, and install scripts. Supply Chain Risk Auditor is Trail of Bits' measured dependency-audit workflow for npm, PyPI, and Go projects. Deterministic collectors inspect direct and lockfile dependencies for advisories, abandonment, publisher concentration, and install scripts before human interpretation is added.
How do I install the Supply Chain Risk Auditor Skill?
Open and review the listed source, choose the project or personal path for your Agent, then verify the first run in a controlled project. Open the pinned commit and read the current SKILL.md.
Is the Supply Chain Risk Auditor Skill safe to use?
SkillSignal checked the source on 2026-09-23, but that is not a runtime test or security certification. Review the “Registry and repository metadata exposure” risk first and begin with the least access required.
INSIDE THE PACKAGE
Indexed files
TAGS
Original SkillSignal editorial profile grounded in Trail of Bits commit 32e34f81, checked 2026-09-23; not independently executed or security-certified.