exposure-scan

Installation
SKILL.md

Exposure Scan

Machine-wide supply-chain check. Runs bumblebee to inventory every installed package (npm, Go, PyPI, RubyGems, MCP servers, editor + browser extensions) and match them against maintained exposure catalogs of known-compromised (ecosystem, name, version) releases. Emits findings only when a real match exists.

This is a personal/machine-level tool — it is global on purpose, not tied to any project.

When to use

  • "Am I running any compromised packages?" / "scan for the shai-hulud worm" / supply-chain audit
  • After news of an npm/PyPI/Go/gem or VS Code extension compromise — refresh catalogs, then scan
  • Periodic hygiene check (the underlying scan is ~13s)

Prerequisites (one-time)

bumblebee must be installed and on PATH:

Installs
1
First Seen
Aug 7, 2026
exposure-scan — stylusnexus/agent-plugins