What problem does it solve?
This Skill addresses the risk of supply chain attacks where internal package names resolve to attacker-controlled public registries, leading to malicious code execution during dependency installation, enabling authorized security teams to identify and mitigate these vulnerabilities.
Core Features & Use Cases
- Multi-ecosystem coverage: Supports testing for npm, pip, RubyGems, Maven, Composer, and Docker dependency confusion risks.
- Structured reconnaissance: Provides commands and workflows to identify leakable internal package names and check for public squatting on registries.
- Safe proof-of-concept patterns: Offers non-destructive callback-based PoC examples for authorized red-team supply chain exercises.
- Defensive guidance: Includes actionable controls to prevent dependency confusion attacks in development and CI/CD pipelines.
Quick Start
Use the dependency-confusion skill to review your project's package manifests for internal package names vulnerable to dependency confusion attacks and produce a prioritized risk report of findings.