Skip to main content
在 Manus 中运行任何 Skill
一键导入

supply-chain-security

星标3
分支0
更新时间2026年6月13日 14:16

Best-practice process for keeping JavaScript/Node supply-chain attacks low-impact when working on pnpm, npm, or yarn projects. Use this skill whenever installing, adding, updating, or pinning dependencies; running pnpm/npm/yarn install; resyncing or regenerating a lockfile; setting up a new Astro or Node project; auditing whether a project is safe from a compromised package; editing package.json or a lockfile; or whenever the user mentions supply-chain attacks, compromised npm packages, malicious postinstall scripts, pinning versions, or lockfile hygiene — even if they don't explicitly ask for a "safe install". Default to consulting this before running any install command so the safe procedure is followed rather than a blind re-resolve.

安装

用 Codex 或 Claude 帮你安装 复制这段 Prompt,粘贴到 Codex、Claude 或其他助手里,让它检查 Skill 页面并帮你完成安装。

文件资源管理器
2 个文件
SKILL.md
readonly