Skip to main content

audit-oss-package

Stars0
Forks0
UpdatedMay 6, 2026 at 09:56

Security audit of a third-party package (npm, pip, homebrew, cargo, gem…) before using it. Fetches its source code, scans for malicious or suspicious patterns (outbound network calls, telemetry, eval/exec, install hooks, opaque file writes, supply-chain risks), then recursively audits same-author dependencies found in the package manifest. Use when the user says "is this package safe", "audit this dependency", "check this npm/pip/brew package", "can I trust this library", or asks whether a package is trustworthy before adding it to a project.

Installation

Install with Codex or Claude Copy this prompt, paste it into Codex, Claude, or another assistant, and let it review the skill page and install it for you.

File Explorer
2 files
SKILL.md
readonly