MCWorkflow
← All workflows
General

NPM Supply-Chain Risk Graph with Statistical Scoring

npm-sentinel analyses packages for vulnerabilities, maintenance health, and license risks; -code-interpreter computes statistical risk scores (CVSS aggregation, maintenance decay curves, license compatibility matrices) in Python; neo4j-cypher stores the scored dependency graph for traversal queries. The product produces a continuously updated, statistically rigorous supply-chain risk map that security teams can query by blast radius, risk score, or license type.

Tools connected

  • Docker

What it automates

raw_risk_signals → -code-interpreter.compute_risk_scores → scored_nodes → neo4j-cypher.write_graph + cypher_traversal_query

Want this one built?

Schedule it and we'll build it in the next 24 hours — you'll get an email the moment it goes live.