Skip to main content

supply-chain-sweep

Scan this machine for indicators of an npm/PyPI supply-chain compromise and produce a clear verdict report. Use whenever the user pastes or links a security advisory about compromised packages (Socket, Aikido, Snyk, Phylum posts, CVE writeups, "X package was hijacked" news) and wants to know if they are affected; whenever they ask "am I compromised", "check my device/laptop for that malware", "did the worm hit us", "are we exposed to the keyv/Shai-Hulud/xz-style attack"; and whenever they mention malicious package versions, credential-stealing postinstall/preinstall scripts, or ask to audit node_modules, lockfiles, or package caches against known-bad versions — even if they never use the words "scan" or "IOC".

Aller à l'installation

Informations de source

Dépôt
nibzard/supply-chain-sweep
Dernière activité de la source
4 août 2026 à 16:18
Langue détectée de SKILL.md
anglais
Étoiles
0
Forks
1

Options d'installation

Le prompt qui vérifie d'abord la source est sélectionné par défaut. Vous pouvez passer à une commande directe ou télécharger une copie locale.

Vérifiez les fichiers source

Lisez SKILL.md et les fichiers associés affichés par SkillsMP avant de décider de l'installer.