Research: supply-chain-risk-auditor
Cached research evidence for supply-chain-risk-auditor (not authority).
Purpose
Section titled “Purpose”Generates report on supply-chain threat landscape of direct dependencies (popularity, #maintainers, CVE history, update freq, security contacts). Flags high-risk; suggests alts where known. Uses gh CLI queries. Explicitly does NOT scan source for CVEs/creds. Trail of Bits (Spencer Michaels).
Harness Coverage
Section titled “Harness Coverage”Security / audit / supply chain agents.
Trust And Risks
Section titled “Trust And Risks”trust_tier=needs-inspection; status=inspect-then-install; provenance=verified-install-command; risks=Depends on gh auth + public data quality; holistic flags not exhaustive CVE scanner; network calls via gh. policy=Inspect.; evidence=trailofbits batch + https://github.com/trailofbits/skills/plugins/supply-chain-risk-auditor .
Install Prerequisites
Section titled “Install Prerequisites”Inspect group install cmd. status=inspect-then-install; selector=named.
Upstream Maintainer
Section titled “Upstream Maintainer”Comparable Alternatives
Section titled “Comparable Alternatives”sast-configuration, secrets-management, general dep tools or wshobson patterns. Supply chain specific.
> Web README evidence.
