agentsclimarketplace

Dependency audit

Skill KhaledSaeed18/dotclaude/skills/security/dependency-audit

Reusable Claude Code extension registry. skills, subagents, slash commands, and hooks for engineering, git, testing, and security workflows. Distributed as a shadcn GitHub registry and as installable plugins.

Install
npx -y skills add KhaledSaeed18/dotclaude --skill dependency-audit

Assembled from the repository path, not quoted from the project. Check it against their README if it does not work.

One thing to look at

  • 4 stars4 stars. Stars are a popularity signal and not a quality one, but at this level it is likely that nobody has read this closely except its author, and you would be relying on your own review.

What its author says it does

Copied from the file, not written here

Audit a project's dependencies for outdated and vulnerable packages and surface breaking-change notes for upgrades. Works with any ecosystem, including npm/pnpm/yarn, pip/Poetry/uv, Cargo, Go modules, Maven/Gradle, Bundler, Composer, and others. Use when checking a project's dependency health, planning upgrades, or responding to a vulnerability report.

SKILL.md

2.2 KB, as published. Nobody here has run it

Audit this project's dependencies for risk and staleness, then recommend a safe upgrade path. Detect the ecosystem before running anything.

Detect the ecosystem

Identify the package manager(s) from the manifests and lockfiles present, then use that ecosystem's native tooling. Common cases:

  • JS/TS: npm audit / pnpm audit / yarn npm audit; npm outdated.
  • Python: pip list --outdated, pip-audit; Poetry/uv equivalents.
  • Rust: cargo outdated, cargo audit.
  • Go: go list -m -u all, govulncheck.
  • Java: mvn versions:display-dependency-updates, OWASP dependency-check; Gradle equivalents.
  • Ruby: bundle outdated, bundle-audit.
  • PHP: composer outdated, composer audit.

If a tool isn't installed, say so and give the exact command to run rather than guessing results. Never invent advisory IDs or version numbers; quote them from real tool output.

Assess

  • Vulnerabilities: list affected package, installed version, fixed version, severity, and advisory ID. Prioritise by severity and by whether the vulnerable code path is actually reachable from this project.
  • Outdated: separate patch/minor (low-risk) from major (potentially breaking).
  • Breaking changes: for the upgrades you recommend, pull the relevant changelog / release notes / migration guide and summarise what would break.

Report

  1. Critical: security fixes to apply now, each with the upgrade command.
  2. Recommended: safe patch/minor bumps.
  3. Needs review: major upgrades, each with its breaking-change summary and a rough effort estimate.
  4. A suggested upgrade order that minimises churn and conflicts.

Keep findings factual and grounded in tool output; quote versions and advisory IDs exactly.

Keep looking

Skills are one crate of 328,083. Ordering is by how many stacks a row turns up in, so the top of any crate is what has actually been picked rather than what has the most stars.