Skip to content
Supply Chain Risk icon

Supply Chain Risk

Package, dependency & exploit risk

Supply Chain Risk audits open-source packages for known vulnerabilities, exploited CVEs, and dependency exposure across every major ecosystem โ€” npm, PyPI, Maven, Go, Cargo, NuGet, RubyGems, and more. It turns a package name and version into a clear risk score in seconds.

Security teams and developers use it to triage dependency risk before shipping, catch vulnerabilities in pull requests, and investigate specific advisories. Each package audit returns a deterministic 0โ€“100 risk score, severity breakdown, CISA KEV hits, EPSS exploitability probability, provenance checks, OpenSSF Scorecard health, fixed versions, and vulnerable dependency paths โ€” everything you need to make a go/no-go call.

What you can do

  • package_risk โ€” full security audit for one exact package version with risk score, advisories, and fix recommendations
  • batch_risk โ€” rank up to 10 packages by risk in one call โ€” great for triaging a dependency list
  • dependency_graph โ€” fetch the full dependency tree for a package with per-node vulnerability counts and vulnerable paths
  • advisory_details โ€” look up a specific CVE, GHSA, or OSV advisory by ID for full details

Who it's for

Security engineers, developers, and DevSecOps teams who need to understand and communicate dependency risk. Also useful for anyone doing vendor due diligence or supply chain compliance work.

How to use it

  1. Use package_risk with a package URL like pkg:npm/lodash@4.17.20 to get an instant risk score and advisory list
  2. For a list of dependencies, use batch_risk to get a ranked table sorted by descending risk
  3. Use dependency_graph to see which transitive dependencies are vulnerable and which direct upgrades would fix the most paths
  4. When you see a CVE or GHSA ID in results, use advisory_details to open the full record

Getting started

No setup needed โ€” all four skills work immediately with no credentials required.

Information

Price
Free

Related Tools

Open Cloudflare Traffic Auditor
Cloudflare Traffic Auditor icon
Cloudflare Traffic AuditorExplain traffic and security changes without exposing visitor identities4 skills ยท from $0.005
Open Browser Tester
Browser Tester icon
Browser TesterTest any page across Chrome, Safari, and Firefox3 skills ยท from $0.005
Open Page Speed Test
Page Speed Test icon
Page Speed TestPerformance, SEO & Web Vitals1 skill ยท from $0.005
Rated 3.0 of 5 โ€”1
Open Security Scanner
Security Scanner icon
Security ScannerScan URLs, IPs, domains and files for threats7 skills ยท from $0.005