npm-supply-chain-audit
作者:agent67尚無安裝尚無按讚更新於 2026年8月17日分類: 其他
它能做什麼
Audit npm projects for Shai-Hulud-class supply-chain exposure: lifecycle scripts, Git dependency prepare hooks, release-age gaps, publish-token exposure, trusted publishing, signed releases, and verifier docs.
安裝會在你的 AgentsRoom 桌面版開啟這個條目。如果還沒有安裝應用,你會被帶到下載頁面。
SKILL.md
--- name: npm-supply-chain-audit description: Audit npm projects for Shai-Hulud-class supply-chain exposure: lifecycle scripts, Git dependency prepare hooks, release-age gaps, publish-token exposure, trusted publishing, signed releases, and verifier docs. --- # npm-supply-chain-audit Use this skill when reviewing a JavaScript or TypeScript repository for install-time malware exposure, compromised npm maintainer risk, or CI publish-path abuse. ## Triggers - "npm supply chain audit" - "Shai-Hulud" - "malicious npm package" - "trusted publishing review" - "publish token exposure" - "Git dependency prepare script" - "router_init.js" / "tanstack_runner.js" ## Audit sequence ### 1. Dependency source scan Search manifests and lockfiles for exotic sources: ```bash rg -n '"(git\\+|git://|github:|file:|link:)|https?://[^"]+\\.(tgz|tar\\.gz)' package.json package-lock.json ``` Findings to escalate: - `github:` or `git+` dependencies, especially in `optionalDependencies`. - Direct tarballs from non-registry hosts. - `file:` or `link:` sources outside deliberate local workspace development. Run the known-affected package feed scan as a separate hard gate: ```bash npm run lint:affected-packages AIWG_AFFECTED_PACKAGES_CSV=/mnt/ops/users/roctinam/Downloads/22-packages.csv npm run lint:affected-packages AIWG_AFFECTED_PACKAGES_CSV=https://gist.githubusercontent.com/<user>/<gist-id>/raw/22-packages.csv npm run lint:affected-packages ``` Treat exact package/version hits as incident evidence. Preserve the package name, version, published timestamp, detected timestamp range, and feed source URL/path in the finding. ### 2. Lifecycle-script review Inspect root package scripts and nested package manifests: ```bash rg -n '"(preinstall|install|postinstall|prepare)"' package.json package-lock.json . ``` Treat install-time scripts as code execution on every developer machine and CI runner. Remove them unless the package cannot function without them. If one must remain, document the exact reason and what it can access. ### 3. Release-age gate Check for `.npmrc`: ```ini min-release-age=7 ``` Confirm contributors and lockfile-changing CI jobs use npm 11.5+. Use 10 days or higher for release-prep dependency churn and security- sensitive branches. ### 4. Publish-path hardening Review release workflows for: - npm trusted publishing or another OIDC publish path. - No long-lived npmjs.org publish token once trusted publishing is active. - `permissions: id-token: write` scoped only to the job that publishes. - Signed tag verification before build, pack, publish, or asset upload. - SHA-pinned actions and digest-pinned containers in release jobs. - No publish step on fork pull requests or untrusted PR triggers. ### 5. Evidence and user verification For packages users install from a registry, require: - npm provenance attestation where supported, - signed git tag, - signed release tarball or equivalent artifact signature, - SBOM, - user-facing verification docs. The verifier docs should avoid commands that run lifecycle scripts while checking an artifact. Prefer `npm install --package-lock-only --ignore-scripts <pkg>@<version>` followed by `npm audit signatures`. ## Incident-response trigger If a known malicious version was installed or a suspicious lifecycle script ran, assume secrets reachable from that environment are exposed. Rotate npm tokens, GitHub/Gitea tokens, cloud credentials, Kubernetes service account tokens, Vault tokens, and deployment secrets. Then audit recent publishes and workflow runs. If the affected-package feed hit a CI runner or workstation cache, quarantine that cache before reuse. ## Output format Lead with findings, ordered by severity: ```markdown ## Findings - CRITICAL: <file:line> <risk> <fix> - HIGH: <file:line> <risk> <fix> ## Clean Checks - No Git dependency sources found. - No install lifecycle scripts found. ## Follow-up Issues - <title>, <acceptance criteria> ``` ## References - npm trusted publishing: <https://docs.npmjs.com/trusted-publishers> - npm audit signatures: <https://docs.npmjs.com/cli/v11/commands/npm-audit#audit-signatures> - npm `min-release-age`: <https://docs.npmjs.com/cli/v11/using-npm/config#min-release-age>
延伸閱讀
Claude Ads:幫你審計廣告帳戶的 Claude Code 技能
Claude Ads 是一款面向 Claude Code 的開源技能:對 Google、Meta、LinkedIn、TikTok、Amazon 廣告等做 250 多項檢查,給出百分制評分和按優先順序排序的行動方案,全程只需十來分鐘。本文講解安裝、命令、侷限,以及如何在 AgentsRoom 中把它編排起來。
AGENTS.md:一個上下文檔案餵飽所有編碼 Agent(Codex、Antigravity、Claude)
AGENTS.md 是 AI 編碼 Agent 在動你程式碼之前先讀的那份可移植指令檔案。該往裡寫什麼、它和 CLAUDE.md 有何區別,以及如何在 Codex、Antigravity 和 Claude 之間保持同一份上下文。
下載 AgentsRoom
在一個視窗中執行你所有專案的所有 AI 代理。
免費下載 AgentsRoom
配套應用:隨時隨地監控你的 Agent
使用 Claude、Codex、Antigravity CLI 或其他 AI 提供商。
獲取擴充功能
Chrome Web Store
把 Bug 和需求直接傳送到您的公開待辦清單。