Skip to main content

audit-oss-package

星标0
分支0
更新时间2026年5月6日 09:56

Security audit of a third-party package (npm, pip, homebrew, cargo, gem…) before using it. Fetches its source code, scans for malicious or suspicious patterns (outbound network calls, telemetry, eval/exec, install hooks, opaque file writes, supply-chain risks), then recursively audits same-author dependencies found in the package manifest. Use when the user says "is this package safe", "audit this dependency", "check this npm/pip/brew package", "can I trust this library", or asks whether a package is trustworthy before adding it to a project.

安装

用 Codex 或 Claude 帮你安装 复制这段 Prompt,粘贴到 Codex、Claude 或其他助手里,让它检查 Skill 页面并帮你完成安装。

文件资源管理器
2 个文件
SKILL.md
readonly