npm-supply-chain-check
Installation
SKILL.md
NPM Supply Chain Check
Run an evidence-bounded, read-only scan. Distinguish a dependency reference from proof that malicious code executed, and never read or print secret values.
Workflow
1. Fix the scan boundary
Resolve the exact repository or directory first. Default to the current repository only. Do not silently expand a repo scan to the user's home directory, all worktrees, global package caches, or CI systems.