多语言供应链投毒检测。支持 python(.pth投毒/setup.py hooks)、npm(postinstall hooks/eval混淆)、go(init() 后门/go:generate)、rust(build.rs)、ruby(extconf.rb)、java(Maven plugin/Gradle exec)、php(composer scripts)。当用户担心供应链安全、想检查依赖投毒、或提到 litellm/ua-parser-js/event-stream 等供应链攻击事件时使用。
$npx -y skills add xwtro0tk1t-cloud/harness --skill supply-chain-auditInstalls into the current project.
Run `npx skills use "https://github.com/xwtro0tk1t-cloud/harness" --skill "xwtro0tk1t-cloud/harness/supply-chain-audit"` and follow the generated skill instructions now. Read its complete output, redirecting it to a temporary file first if necessary. Resolve relative paths from the supporting-files directory it provides.
Use the skills in "https://github.com/xwtro0tk1t-cloud/harness" that are relevant to the current task. Run `npx skills add "https://github.com/xwtro0tk1t-cloud/harness"` and select the relevant skills, then follow their instructions.