exposure-scan
Installation
SKILL.md
Exposure Scan
Machine-wide supply-chain check. Runs bumblebee to inventory every installed package (npm, Go, PyPI, RubyGems, MCP servers, editor + browser extensions) and match them against maintained exposure catalogs of known-compromised (ecosystem, name, version) releases. Emits findings only when a real match exists.
This is a personal/machine-level tool — it is global on purpose, not tied to any project.
When to use
- "Am I running any compromised packages?" / "scan for the shai-hulud worm" / supply-chain audit
- After news of an npm/PyPI/Go/gem or VS Code extension compromise — refresh catalogs, then scan
- Periodic hygiene check (the underlying scan is ~13s)
Prerequisites (one-time)
bumblebee must be installed and on PATH: