Dependency audit
Skill byerlikaya/claude-starter-kit/claude-starter/skills/dependency-audit
Enterprise engineering workflow for Claude Code — not just prompts. AI agents that plan, build, audit, and ship with security gates, privacy checks, and approval-controlled commits. Safely adopt it into new or existing repositories.
npx -y skills add byerlikaya/claude-starter-kit --skill dependency-auditAssembled from the repository path, not quoted from the project. Check it against their README if it does not work.
One thing to look at
- 20 stars20 stars. Stars are a popularity signal and not a quality one, but at this level it is likely that nobody has read this closely except its author, and you would be relying on your own review.
What its author says it does
Copied from the file, not written here
Dependency audit: known CVEs, licence compliance, abandoned/outdated packages, lockfile integrity, and a justification for every new dependency. Trigger phrases: "dependency", "dependency audit", "npm audit", "package security", "CVE", "license"
SKILL.md
1.3 KB, as published. Nobody here has run it
Dependency Audit
Audit axes
- Known vulnerabilities (CVE): audit appropriate to the ecosystem
npm audit --production # Node dotnet list package --vulnerable # .NET pip-audit # Python - License compliance: flag licenses incompatible with the project such as copyleft/GPL (a risk in commercial closed source).
- Maintenance status: note abandoned / long-unmaintained / single-maintainer packages.
- Transitive dependencies: also scan vulnerabilities in indirect dependencies.
- Lockfile integrity: lockfile committed and consistent with the manifest; versions pinned.
- Justification for new dependencies: is it actually needed? Don't add a heavy package for a single small function (supply-chain surface).
Output
Severity-sorted list: package · version · issue (CVE/license/maintenance) · upgrade path.
DoD
- 0 known HIGH/CRITICAL vulnerabilities; licenses compliant; lockfile consistent; every new package justified.