General skillSecurity and privacy

supply-chain-malware-scanner

Scan for npm/PyPI supply-chain worms and plan safe eradication.

Stars
0
Forks
0
License
MIT
Updated
Updated May 13, 2026

Checking live repository facts…

Project overview

This standalone agent skill scans local files, lockfiles, processes, persistence points, containers, and CI surfaces for indicators from documented npm and PyPI worm campaigns. Its key safety rule is to stop persistence and quarantine evidence before revoking credentials, then release a dependency-ordered rotation plan only after a clean second scan. It supports macOS, Linux, Windows, WSL, containers, and CI, but remains an incident-response runbook rather than a guarantee of safety.

Repository facts

Primary language
Not detected
License
MIT
Repository updated
May 13, 2026
Default branch
main

Resource types

General skill

Use cases

Security and privacy

Platforms

Claude Code, Codex, and more

Runtime

Local

Capabilities

Verification and evals

Audience

Developers

Related projects

Browse more similar projects