Audits npm dependencies for supply chain risks using npm audit, Socket.dev API, and Snyk vulnerability database. Detects typosquatting, install scripts, and maintainer account takeovers.
Scanned 6/8/2026
Install via CLI
openskills install agentskillexchange/skills---
name: "NPM Package Supply Chain Auditor"
slug: "npm-package-supply-chain-auditor"
description: "Audits npm dependencies for supply chain risks using npm audit, Socket.dev API, and Snyk vulnerability database. Detects typosquatting, install scripts, and maintainer account takeovers."
github_stars: 5516
verification: "security_reviewed"
source: "https://github.com/snyk/cli"
author: "snyk"
category: "Security & Verification"
framework: "OpenClaw"
tool_ecosystem:
github_repo: "snyk/cli"
github_stars: 5516
npm_package: "snyk"
npm_weekly_downloads: 2566112
---
# NPM Package Supply Chain Auditor
Audits npm dependencies for supply chain risks using npm audit, Socket.dev API, and Snyk vulnerability database. Detects typosquatting, install scripts, and maintainer account takeovers.
## Installation
Requirements and caveats from upstream:
- To use the CLI, you must install it and authenticate your machine. See [Install or update the Snyk CLI](https://docs.snyk.io/snyk-cli/install-or-update-the-snyk-cli) and [Authenticate the CLI with your account](https:...
- Before you can use the CLI for Open Source scanning, you must install your package manager. The needed third-party tools, such as Gradle or Maven, must be in the PATH.
- Before using the Snyk CLI to test your Open Source Project for vulnerabilities, with limited exceptions, you must build your Project. For details, see [Open Source Projects that must be built before testing](https://d...
Basic usage or getting-started notes:
- ## Introduction to the Snyk CLI
- Snyk is a developer-first, cloud-native security tool to scan and monitor your software development projects for security vulnerabilities. Snyk scans multiple content types for security issues:
- [Snyk Open Source](https://docs.snyk.io/scan-with-snyk/snyk-open-source): Find and automatically fix open-source vulnerabilities
- Source: https://github.com/snyk/cli
- Extracted from upstream docs: https://raw.githubusercontent.com/snyk/cli/HEAD/README.md
## Source
- [Agent Skill Exchange](https://agentskillexchange.com/skills/npm-package-supply-chain-auditor/)
No comments yet. Be the first to comment!