supply-chain-malware-scanner
Scan for npm/PyPI supply-chain worms and plan safe eradication.
Scan for npm/PyPI supply-chain worms and plan safe eradication.
This standalone agent skill scans local files, lockfiles, processes, persistence points, containers, and CI surfaces for indicators from documented npm and PyPI worm campaigns. Its key safety rule is to stop persistence and quarantine evidence before revoking credentials, then release a dependency-ordered rotation plan only after a clean second scan. It supports macOS, Linux, Windows, WSL, containers, and CI, but remains an incident-response runbook rather than a guarantee of safety.
Resource types
Use cases
Platforms
Runtime
Audit suspension risks in a Claude Code working environment.
Check whether a specific CVE actually applies to your environment.
Capabilities
Audience
Public GitHub facts last synced Jul 10, 2026.
Store and inject development secrets through 1Password from Claude Code.
Audit a deployed public app for production gaps missed during coding.