Check repositories and CI surfaces for Shai-Hulud 2.0 compromise indicators when the task is targeted supply-chain triage, not generic malware scanning.
Scanned 6/2/2026
Install to Claude Code
npx -y skills add agentskillexchange/skills --skill scan-repositories-for-shai-hulud-2-0-supply-chain-indicators-with-the-detector-action --agent claude-codeInstalls into .claude/skills of the current project.
Are you the author of Scan Repositories For Shai Hulud 2 0 Supply Chain Indicators With The Detector Action?
Add the live security badge to your README — it updates automatically with every re-scan.
[](https://www.skillsdirectory.com/skills/agentskillexchange-scan-repositories-for-shai-hulud-2-0-supply-chain-)More formats (shields.io, HTML) on the badges page.
---
name: "Scan repositories for Shai-Hulud 2.0 supply-chain indicators with the detector action"
slug: "scan-repositories-for-shai-hulud-2-0-supply-chain-indicators-with-the-detector-action"
description: "Check repositories and CI surfaces for Shai-Hulud 2.0 compromise indicators when the task is targeted supply-chain triage, not generic malware scanning."
github_stars: 124
verification: "security_reviewed"
source: "https://github.com/gensecaihq/Shai-Hulud-2.0-Detector"
author: "GenSecAIHQ"
publisher_type: "GitHub repository"
category: "Security & Verification"
framework: "Multi-Framework"
tool_ecosystem:
github_repo: "gensecaihq/Shai-Hulud-2.0-Detector"
github_stars: 124
---
# Scan repositories for Shai-Hulud 2.0 supply-chain indicators with the detector action
Check repositories and CI surfaces for Shai-Hulud 2.0 compromise indicators when the task is targeted supply-chain triage, not generic malware scanning.
## Prerequisites
GitHub Action or local detector CLI, repository or monorepo to scan, and security triage review
## Installation
Use the upstream install or setup path that matches your environment:
- **STOP** - Do not run npm install or any build commands
- npm cache clean --force
- npm install --ignore-scripts # Prevent postinstall hooks
- npm audit
Requirements and caveats from upstream:
- <strong>🔑 THE SUCCESS OF THIS PROJECT DEPENDS ON YOU!</strong>
- | PostHog | 62 | posthog-node, posthog-js, @posthog/nextjs, @posthog/plugin-server |
- node scripts/update-ioc-database.js
Basic usage or getting-started notes:
- <a href="#quick-start">Quick Start</a> •
- [Quick Start](#quick-start)
- [Local CLI Usage](#local-cli-usage)
- Source: https://github.com/gensecaihq/Shai-Hulud-2.0-Detector
- Extracted from upstream docs: https://raw.githubusercontent.com/gensecaihq/Shai-Hulud-2.0-Detector/HEAD/README.md
## Documentation
- https://github.com/gensecaihq/Shai-Hulud-2.0-Detector#readme
## Source
- [Agent Skill Exchange](https://agentskillexchange.com/skills/scan-repositories-for-shai-hulud-2-0-supply-chain-indicators-with-the-detector-action/)
Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.
No comments yet. Be the first to comment!