/install axios-supply-chain-attack-check
Skill Instructions
适用场景
适用于所有前端项目,当检测到前端项目依赖存在axios恶意版本(1.14.1/0.30.4)、[email protected]后门依赖,或出现开发/构建环境异常外联、未知脚本执行时,立即执行本技能完成应急处置。
紧急排查
依赖版本风险核查及处理
执行以下命令检查项目依赖树中是否存在风险版本:
bash ./scripts/check-axios-risk.sh
- Make sure OpenClaw is installed (local or Docker)
- Run the install command in chat:
/install axios-supply-chain-attack-check - After installation, invoke the skill by name or use
/axios-supply-chain-attack-check - Provide required inputs per the skill's parameter spec and get structured output
What is axios-supply-chain-attack-check?
Provides a quick 1-minute script to detect and handle malicious axios versions and backdoor dependencies in front-end projects. It is an AI Agent Skill for Claude Code / OpenClaw, with 97 downloads so far.
How do I install axios-supply-chain-attack-check?
Run "/install axios-supply-chain-attack-check" in the OpenClaw or Claude Code chat to install it in one step — no extra setup required.
Is axios-supply-chain-attack-check free?
Yes, axios-supply-chain-attack-check is completely free, licensed under MIT-0. You can download, install and use it at no cost.
Which platforms does axios-supply-chain-attack-check support?
axios-supply-chain-attack-check is cross-platform and runs anywhere OpenClaw / Claude Code is available (cross-platform).
Who created axios-supply-chain-attack-check?
It is built and maintained by hometown (@preciousdust); the current version is v1.0.0.