Research: supply-chain-risk-auditor

Cached research evidence for supply-chain-risk-auditor (not authority).

Back to catalog page

Generates report on supply-chain threat landscape of direct dependencies (popularity, #maintainers, CVE history, update freq, security contacts). Flags high-risk; suggests alts where known. Uses gh CLI queries. Explicitly does NOT scan source for CVEs/creds. Trail of Bits (Spencer Michaels).

Security / audit / supply chain agents.

trust_tier=needs-inspection; status=inspect-then-install; provenance=verified-install-command; risks=Depends on gh auth + public data quality; holistic flags not exhaustive CVE scanner; network calls via gh. policy=Inspect.; evidence=trailofbits batch + https://github.com/trailofbits/skills/plugins/supply-chain-risk-auditor .

Inspect group install cmd. status=inspect-then-install; selector=named.

trailofbits/skills.

sast-configuration, secrets-management, general dep tools or wshobson patterns. Supply chain specific.

> Web README evidence.