Dependency audit — defensive review for hijacks, typosquats and supply-chain attacks
Vet new dependencies before install: registry reputation, release-history anomalies, suspicious package behaviors (postinstall scripts, obfuscation, credential access), safer alternatives and audit scripts
- What
- Vet new dependencies before install: registry reputation, release-history anomalies, suspicious package behaviors (postinstall scripts, obfuscation, credential access), safer alternatives and audit scripts
- Cost
- Free
- Needs
- a project with third-party dependencies to vet — the skill is a defensive review methodology the agent follows, not software
- Install
- Copy the installer prompt below into your Muse — your agent does the rest.
Curated by Skill Harbor — @briiirussell's dependency-audit skill: a defensive review checklist for vetting any new dependency before it enters your project. Walks through registry reputation (npm, PyPI, crates.io), release-history anomalies (version squatting, rapid publishes), suspicious package behaviors to flag (postinstall scripts, obfuscated code, credential access, network calls), when to prefer safer alternatives, and audit scripts to run. Honest caveats: this is a review methodology, not an automated scanner — it won't catch what you don't look at; pair it with real tooling (npm audit, pip-audit, socket.dev) for enforcement. MIT licensed. Skill Harbor never reviews the code, review it yourself before use. Discovered via skills.sh.
Version:
Install
Prerequisites: a project with third-party dependencies to vet — the skill is a defensive review methodology the agent follows, not software Install "Dependency audit — defensive review for hijacks, typosquats and supply-chain attacks" for me. It gives my agent @briiirussell's defensive audit checklist: registry reputation checks (npm, PyPI, crates.io), release-history anomaly detection (version squatting, rapid publishes), suspicious behavior flags (postinstall scripts, obfuscated code, credential access, network calls), safer-alternative guidance and audit scripts. NOTE: this is a review methodology, not an automated scanner — pair with npm audit / pip-audit / socket.dev for enforcement. MIT-licensed. Repository: https://github.com/briiirussell/cybersecurity-skills/blob/main/skills/dependency-audit/SKILL.md 1. Fetch the SKILL.md file (and any helper files) from the repository path into a temporary folder and summarize what it does in one or two sentences. 2. Safety check: review the SKILL.md and scripts for anything suspicious (unexpected network calls, shell commands, credential harvesting). This repo should contain zero secrets in code. Verify that holds here; STOP on any red flag and tell me. 3. Install it as a skill: copy SKILL.md and its helper files into the agent's skills directory, in a folder named "dependency-audit". 4. Verify with no network calls: frontmatter valid, files in place. 5. Report what was installed, where, and what I still need to do myself (e.g. hand the agent the dependency or lockfile to audit; nothing else — it's a review methodology). GitHub is optional: if I have a GitHub account or the gh CLI, you may use it; otherwise public access is fine. Never require it unless it's in the prerequisites above. Rules: don't touch anything outside the temp folder and the install target. If anything looks off, stop and ask me.
Questions
How do I install a build?
Every product page includes a copy-paste install prompt. Paste it into your Muse and it sets the build up for you — no manual configuration.
Where does my money go?
Straight to the seller. Skill Harbor never processes payments: checkout happens on the seller’s own page, usually Stripe.
What does the ✓ next to a creator’s name mean?
It means we confirmed the identity of the person behind the listing. It says nothing about the code itself — always check a build before installing it.