npm-supplychain-check
Scan this machine for the Miasma / Phantom Gyp ("TeamPCP") npm supply-chain compromise that plants backdoors in Claude Code (~/.claude/settings.json) and VS Code (.vscode/tasks.json). Use when the user asks to check if their PC/machine is infected, compromised, or affected by the npm/Claude Code backdoor attack, credential-stealing worm, or Shai-Hulud campaign.
What this skill does
# npm Supply-Chain / Claude Code Backdoor Check
Read-only detection for the credential-stealing campaign that weaponizes the
Claude Code **hooks** feature and VS Code tasks for persistence. The attack
vector is always installing a poisoned npm package — there is no Claude Code
vulnerability itself.
## How to run
```bash
# Default: scan $HOME plus global Claude/shell checks
scripts/scan.sh
# Or scan a specific project tree (global checks still run)
scripts/scan.sh /path/to/project
```
Exit code `0` = clean, `1` = suspicious findings.
To regression-check the detector itself after editing `scan.sh`, run the
synthetic-fixture suite: `sh tests/selftest.sh` (exit `0` = all checks pass).
## SAFETY — order matters
This script is **read-only**. It never deletes, modifies, or revokes anything.
That is deliberate: the malware contains a dead-man's switch that wipes the home
directory if it detects its access being cut. **If findings appear, do NOT start
by revoking tokens.** Correct order:
1. Screenshot the offending hook/task for evidence.
2. Disconnect the machine from the network.
3. Remove the injected hook/task.
4. Rotate credentials **from a separate, clean machine** — npm tokens, GitHub
PATs, SSH keys, then cloud (AWS/GCP/Azure), Kubernetes, Vault.
## What it checks
1. **`~/.claude/settings.json`** (+ `.local`) — the primary persistence target;
flags `SessionStart` hooks or network/exec keywords.
2. **`.vscode/tasks.json`** — flags tasks that auto-run on `folderOpen`.
3. **Project `.claude/settings*.json`** — flags `SessionStart` / exfil hooks.
(Legitimate `PostToolUse` / `PreToolUse` project hooks are *not* flagged.)
4. **Affected npm packages** — global installs, `node_modules` dirs, and lockfiles.
Two tiers, because matching a package *name* is not the same as proving compromise:
- `[!]` **Malicious names** (`ai-sdk-ollama`, `node-env-resolver`, `wrangler-deploy`,
`autotel`, `awaitly`, `executable-stories`) — the package itself is the malware;
a match is a real IoC and counts toward the suspicious exit code.
- `[?]` **Targeted scopes** (`@redhat-cloud-services`, `@vapi-ai`) — legitimate,
widely-used scopes where only specific poisoned *versions* were bad. A match is
surfaced for **version review**, not hard-flagged, so a clean install of Red Hat
or Vapi packages doesn't trigger a false alarm. Confirm the installed version
against the advisory before acting.
5. **Worm artifacts** — `shai-hulud` / `miasma` GitHub workflow files.
6. **Shell rc files** — `curl|wget|base64 -d` piped into a shell, or `/dev/tcp`.
7. **`npm audit`** (only when scanning a single project with a `package.json`) —
a database lookup against published advisories. This is **complementary**, not
redundant: checks 1–6 catch the *persistence backdoor* and known *names* that
audit can't see, while audit is **version-precise and auto-updating** — it
confirms a known-bad *installed version* and stays current as new advisories
land, which a frozen hardcoded list cannot. It is blind to zero-days (it found
nothing during this campaign's first hours) and to the config backdoor, so it
never stands alone. Read-only locally; we never run `npm audit fix`. Audit hits
that name a campaign family are hard `[!]` findings; overall critical/high
counts are surfaced as `[i]` general hygiene, not campaign signal.
## Interpreting results
- **CLEAN** — no IoCs; no cleanup needed. The user does not need the revoke
sequence.
- **CLEAN of hard IoCs + `[?]` review items** — a legitimate-but-targeted scope
was found. Exit code is still `0`. Check the installed version against the
advisory's bad-version list; only escalate if it matches.
- **SUSPICIOUS** (`[!]`) — read each flagged file before acting; distinguish your
own legitimate hooks from injected ones, then follow the order above.
## Hardening to suggest afterward
- `npm config set ignore-scripts true` (relax per-package for native builds).
- Commit `package-lock.json`; use `npm ci` (not `npm install`) in automation.
- Scope CI/CD tokens to least privilege.
Related in Ads & Marketing
ads
IncludedMulti-platform paid advertising audit and optimization skill. Analyzes Google, Meta, YouTube, LinkedIn, TikTok, Microsoft, and Apple Ads. 250+ checks with scoring, parallel agents, industry templates, and AI creative generation.
banana
IncludedAI image generation Creative Director powered by Google Gemini Nano Banana models. Use this skill for ANY request involving image creation, editing, visual asset production, or creative direction. Triggers on: generate an image, create a photo, edit this picture, design a logo, make a banner, visual for my anything, and all /banana commands. Handles text-to-image, image editing, multi-turn creative sessions, batch workflows, and brand presets.
rpg-migration-analyzer
IncludedAnalyzes legacy RPG (Report Program Generator) programs from AS/400 and IBM i systems for migration to modern Java applications. Extracts business logic from RPG III/IV/ILE source code, identifies data structures (D-specs), file operations (F-specs), program dependencies (CALLB/CALLP), and converts RPG constructs to Java equivalents. Generates migration reports, complexity estimates, and Java implementation strategies with POJO classes, JPA entities, and service methods. Use when modernizing AS/400 or IBM i legacy systems, analyzing RPG source files (.rpg, .rpgle, .RPGLE), converting RPG to Java, mapping data specifications to Java classes, planning legacy system migration, or when user mentions RPG analysis, Report Program Generator, RPG III/IV/ILE, AS/400 modernization, IBM i migration, packed decimal conversion, or mainframe application rewrite.
brand-library-architect
IncludedBuild a complete brand library for a product — visual asset render pipeline, brand documentation set (BRAND, COPY, MANIFESTO, BIOS, FAQ, GLOSSARY, TONE, PRICING), open-source convention files (README, CONTRIBUTING, SECURITY, CODE_OF_CONDUCT), and a self-contained press kit. This skill should be used when the user asks to "build a brand library / brand kit / press kit / brand assets" for a product, "set up a brand library workflow," "create a positioning manifesto plus visual identity," or any combination of brand documentation + visual asset pipeline. Apply phase-by-phase or run end-to-end. Templates are product-agnostic and use {{TOKEN}} placeholders the skill prompts the user to fill.
writing-tech-post
IncludedAuthors engineering blog posts end-to-end: launch deep-dives, incident postmortems, architecture migrations, performance case studies, tutorials, AI/agent system writeups, security disclosures, and research-to-product translations. Picks the correct archetype, plans the abstraction ladder, enforces an evidence cadence (diagrams, benchmarks, profiles, traces, code, ablations), tunes voice against publisher house styles (Datadog, Vercel, GitHub, AWS, Meta, Cloudflare, Jane Street), and runs a pre-publish gate for narrative momentum and disclosure ethics. Use when drafting a new engineering post, restructuring a draft that feels flat, deciding which evidence form belongs where, validating that depth and product context are balanced, or preparing a postmortem, migration, or performance narrative for external publication. Do not use for API reference documentation, README authoring, marketing copy, release notes, generic SEO content, ghost-written executive thought leadership, or non-engineering long-form essays.
blog-google
IncludedGoogle API integration for blog performance: PageSpeed Insights, CrUX Core Web Vitals with 25-week history, Search Console performance, URL Inspection, Indexing API, GA4 organic traffic, NLP entity analysis for E-E-A-T, YouTube video search for embedding, and Google Ads Keyword Planner. Progressive feature availability based on credential tier (API key, OAuth/service account, GA4, Ads). Shares config with claude-seo at ~/.config/claude-seo/google-api.json. Use when user says "google data", "page speed", "core web vitals", "search console", "indexation", "GA4", "keyword research", "nlp entities", "blog performance", "youtube search", "google api setup".