Dependency and Supply Chain Security Audits
Your app runs far more third-party code than code you wrote, and AI coding tools add packages faster than anyone reviews them. We audit what you install, how it gets installed, and what it can reach once it runs.
30-minute intro call · fixed-scope quote · human review, not scanner output. Read client case studies.
How supply chain attacks reach AI-built apps
Recent npm and PyPI incidents have targeted exactly the tools AI developers use: LLM proxies, AI SDKs, coding-agent tooling, and CI tokens. These are the paths we check.
Hallucinated and typosquatted packages
AI assistants sometimes suggest package names that do not exist. Attackers register those names (slopsquatting) or near-misses of popular packages, waiting for an install.
Install scripts with full access
npm postinstall scripts and Python build hooks run with your user's permissions on developer laptops and CI runners, where cloud keys, SSH keys, and tokens live.
Compromised AI SDKs and proxies
Packages such as LLM gateways and AI SDKs sit next to every provider API key you own. A malicious release of one of them is a direct path to those credentials.
Unpinned versions and missing lockfiles
Wide version ranges, lockfiles that are not committed, or installs that ignore them mean a new malicious release can reach production without anyone changing code.
CI pipelines and GitHub Actions
Third-party actions referenced by mutable tags, over-scoped tokens, and secrets exposed to pull requests from forks let an upstream compromise reach your deploy credentials.
Agent config files as an attack vector
Files such as CLAUDE.md, AGENTS.md, editor rules, and MCP configs instruct coding agents. A malicious change to them, or to a dependency that ships them, can steer an agent into running commands.
What a supply chain security audit covers
A fixed-scope review of your manifests, lockfiles, build pipeline, and developer tooling, with a prioritized list of changes.
How the review works
- 1
Inventory
We collect manifests, lockfiles, container images, and CI configuration, and build a list of everything that executes during install, build, and runtime.
- 2
Risk analysis
We check each dependency against vulnerability advisories, maintenance signals, install-time behaviour, and how much access it has to secrets.
- 3
Pipeline and tooling review
We review CI workflows, deploy credentials, and coding-agent configuration for paths an upstream compromise could use.
- 4
Remediation plan
You receive a prioritized list of removals, upgrades, pins, and configuration changes, plus lightweight policies to keep the dependency tree healthy.
Supply chain checks you can run today
Start here before you book anything. If any of these fail or you are not sure how to check, that is the signal to get a second pair of eyes.
- Commit your lockfile and use `npm ci` or the equivalent in CI so builds install exactly what was reviewed.
- Run `npm audit` or `pip-audit` and look up any package you do not recognise before trusting it.
- Pin third-party GitHub Actions to a full commit SHA instead of a tag like `@v3`.
- Make sure CI secrets are not available to workflows triggered by pull requests from forks.
- Review CLAUDE.md, AGENTS.md, and MCP config changes in pull requests with the same care as code.
Want a scored version? Take the free vibe code security check or work through the 25-point launch checklist.
Frequently asked questions
Related services and guides
The LiteLLM supply chain attack
What happened and what it means for AI app credentials.
npm package stealing Codex tokens
How a fake package targeted coding-agent credentials.
TrapDoor and CLAUDE.md
Agent config files as a supply chain vector.
Shai-Hulud npm worm
A self-spreading worm that bypassed npm's malware scanner.
Miasma worm and AI SDKs
An npm campaign aimed at AI SDK packages.
AI agent security audit
Review tools, MCP servers, and agent permissions.