axios-security-checkChecks for the March 2026 axios supply chain attack — two malicious npm versions ([email protected] and [email protected]) that injected a RAT dropper via a fake depen...
Install via ClawdBot CLI:
clawdbot install vjumpkung/axios-security-checkGrade Fair — based on market validation, documentation quality, package completeness, maintenance status, and authenticity signals.
Accesses system directories or attempts privilege escalation
/etc/hostsCalls external URL not in known-safe list
https://github.com/step-security/harden-runnerAI Analysis
The skill provides legitimate security guidance for a known supply chain attack and does not contain instructions to send user data to external servers, harvest credentials, or override user intent. The flagged signals (accessing /etc/hosts, linking to a hardening guide) are part of the remediation advice and do not constitute active malicious behavior.
Audited Apr 17, 2026 · audit v1.0
Generated May 20, 2026
A SaaS company runs an npm audit after a security alert and uses this skill to check if their CI/CD pipeline pulled malicious axios versions. It detects presence of plain-crypto-js and triggers credential rotation for all cloud providers.
A DevOps team suspects their build servers were compromised during the March 2026 window. The skill helps locate RAT artifacts across macOS, Linux, and Windows systems and guides them to rebuild from a known-good state.
A fintech startup uses the skill to audit their lock file for malicious axios versions. They find no direct infection but proactively pin safe versions and add overrides to prevent future supply chain attacks.
An enterprise IT security team runs the skill across hundreds of repositories to identify all projects that installed the malicious packages. They produce a centralized report and coordinate credential rotation for affected teams.
An open source library maintainer uses the skill to confirm their axios dependency is clean before releasing a new version. They also add --ignore-scripts to their CI workflow as a preventative measure.
Offer automated npm vulnerability scanning and remediation as a monthly subscription. The skill provides the detection engine, with premium tiers including CI/CD integration and credential rotation orchestration.
Provide one-time or retainer-based security consulting to audit and remediate supply chain compromises. The skill accelerates detection and remediation, allowing consultants to deliver faster results.
Sell a package that includes the detection script plus training materials on supply chain security best practices. Bundled with a full walkthrough of this skill, it targets DevOps teams improving their security posture.
💬 Integration Tip
Integrate into your CI/CD pipeline as a post-install audit step (e.g., after npm ci) to automatically flag any malicious version presence and trigger alerts.
Scored May 20, 2026
Use when building iOS/macOS applications with Swift 5.9+, SwiftUI, or async/await concurrency. Invoke for protocol-oriented programming, SwiftUI state management, actors, server-side Swift.
Control Android devices via ADB (Android Debug Bridge) from a Mac. Use when: remotely operating an Android phone (tap, swipe, type, screenshot, screen record...
Quickly view and analyze Android device page stacks including current page, Activity history, Fragments, and monitor page switches via ADB commands.
Review Arabic-first family and mobile apps for RTL layout, bilingual copy, onboarding, approval flows, and safe local-first defaults.
Use when upgrading an iOS or macOS app's Auth0.swift SDK from v2 to v3. Detects the current version, fetches the new SDK source to confirm API signatures, an...
Control iOS automation via StarryForest Agent Mail API. Use when creating alarms, reminders, memos, calendar events, focus modes, music playback, or journal...