supply-chain-risk-auditor

Identify dependencies with elevated risk of exploitation or takeover.

31|4|Updated Apr 6, 2026
One-click install
npx skills add https://github.com/kissrosecicd-hub/agents-evolution --skill supply-chain-risk-auditor-kissrosecicd-hub
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: supply-chain-risk-auditor
Source: https://github.com/kissrosecicd-hub/agents-evolution/tree/main/.agents/skills/tob-supply-chain-risk-auditor
Command: npx skills add https://github.com/kissrosecicd-hub/agents-evolution --skill supply-chain-risk-auditor-kissrosecicd-hub

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Identifies dependencies at heightened risk of exploitation or takeover to help security teams scope engagements, prioritize remediation, and reduce overall supply-chain risk.

Core Features & Use Cases

  • Risk-factor based evaluation of dependencies (single maintainer, unmaintained, low popularity, high-risk features, past CVEs, and absence of security contact).
  • Generates concise risk reports listing high-risk dependencies and justification to guide remediation and vendor negotiations.
  • Useful for pre-engagement scoping, vendor risk analysis, and ongoing supply chain security programs.

Quick Start

Audit all direct dependencies and produce a risk report highlighting high-risk factors.

Frequently Asked Questions about supply-chain-risk-auditor

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I assess dependencies for supply chain risk before a security engagement?

To assess supply chain risk, evaluate dependencies against criteria like single maintainers, unmaintained projects, low popularity, high-risk features, past CVEs, and absent security contacts, then generate a concise risk report for remediation and vendor negotiations.

What risk factors indicate a vulnerable software dependency in a project?

High-risk dependencies typically exhibit single maintainers, unmaintained project status, low popularity, high-risk features, past CVEs, and absence of security contacts, which signal elevated exploitation or takeover risk during security audits.

Can I audit all direct dependencies and generate a security report automatically?

Yes, you can audit all direct dependencies to produce a risk report that highlights high-risk factors and justification, guiding remediation efforts, vendor negotiations, and ongoing supply chain security programs.

Does supply chain risk evaluation work for vendor risk analysis and pre-engagement scoping?

Supply chain risk evaluation is useful for pre-engagement scoping, vendor risk analysis, and ongoing security programs, helping security teams scope engagements and prioritize remediation across projects by identifying risky dependencies.

What is the best way to identify unmaintained dependencies with single maintainers?

The best way to identify unmaintained dependencies with single maintainers is applying risk-factor based evaluation during supply chain assessments, which flags dependencies lacking security contacts or showing low popularity and past CVEs for remediation.