So the audit was mostly about nom the website and the service for maintaining npm packages? That's a good first step.
Has there been any talk within the node community about auditing node modules themselves? Maybe start with the most popular? I could see this being popular with enterprise development, etc.
I want to say that Strong Loop made noise about doing something like this, but I haven't seen much on it of late.