supply-chain-risk-auditor

Identify dependencies at heightened risk of exploitation or takeover.

16|4|Updated Mar 22, 2026
One-click install
npx skills add https://github.com/idchain-world/id-agents --skill supply-chain-risk-auditor-idchain-world
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: supply-chain-risk-auditor
Source: https://github.com/idchain-world/id-agents/tree/main/configs/agents/security/skills/supply-chain-risk-auditor
Command: npx skills add https://github.com/idchain-world/id-agents --skill supply-chain-risk-auditor-idchain-world

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Identifies and evaluates dependencies to surface high-risk components that could threaten supply chain integrity in software projects.

Core Features & Use Cases

  • Identify high-risk dependencies using predefined risk factors
  • Produce a structured risk report with justification and suggested mitigations
  • Use for pre-engagement scoping and vendor risk assessments

Quick Start

Run a full dependency risk audit on your project to generate a results.md report.

Frequently Asked Questions about supply-chain-risk-auditor

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
What is software supply chain risk and how do I identify vulnerable dependencies?

Software supply chain risk involves dependencies vulnerable to exploitation or takeover. You identify vulnerable dependencies by evaluating dependency health against risk factors like single maintainer status, unmaintained code, low popularity, high-risk features, past CVEs, and missing security contacts to generate a structured assessment.

How do I audit dependencies for supply chain security risks?

You audit dependencies for supply chain security risks by applying predefined risk criteria to evaluate dependency health. This process identifies high-risk components based on factors like single maintainer projects, unmaintained status, low popularity, past CVEs, and absent security contacts, outputting a structured results report.

Can I use a dependency risk audit for vendor risk assessments and pre-engagement scoping?

Yes, you can use a dependency risk audit for vendor risk assessments and pre-engagement security scoping. It evaluates dependency health to surface high-risk components that threaten supply chain integrity, producing a structured risk report with justifications and suggested mitigations to scope remediation work.

What's the best way to report on unmaintained or single maintainer dependencies?

The best way to report on unmaintained or single maintainer dependencies is to run a full dependency risk audit. It assesses these specific supply chain risk criteria alongside low popularity, high-risk features, past CVEs, and absent security contacts, generating a structured results.md report with suggested mitigations.

What risk factors should I check to prevent software supply chain attacks?

To prevent software supply chain attacks, check dependencies for single maintainer status, unmaintained status, low popularity, high-risk features, past CVEs, and absence of a security contact. Evaluating these risk factors surfaces high-risk components vulnerable to exploitation or takeover.

Does a dependency risk audit require any external security tools to run?

A dependency risk audit does not require external security tools to run. It evaluates dependency health internally by applying predefined risk criteria like single maintainer status, unmaintained code, low popularity, past CVEs, and missing security contacts to output a structured results report.