agentsclimarketplace

Dependency auditor

Skill Yue-Zhou1/zkcrypto-audit/plugins/implementation-safety/skills/dependency-auditor

Audit cryptographic dependency sets for vulnerable versions, security-significant feature flags, advisory coverage, transitive risk, and stale fork provenance.From its SKILL.md

Install
npx -y skills add Yue-Zhou1/zkcrypto-audit --skill dependency-auditor

Assembled from the repository path, not quoted from the project. Check it against their README if it does not work.

One thing to look at

  • 2 stars2 stars. Stars are a popularity signal and not a quality one, but at this level it is likely that nobody has read this closely except its author, and you would be relying on your own review.

SKILL.md

2.5 KB, 453 tokens by cl100k_base, as published. Nobody here has run it

dependency-auditor

Domain auditor for crypto dependency hygiene and supply-chain risk.

When to Use

  • Auditing lockfiles and dependency graphs for vulnerable cryptographic crates/libs
  • Reviewing security-significant feature-flag semantics
  • Checking transitive dependency duplication and semantic drift
  • Validating fork provenance and patch divergence from upstream

When NOT to Use

  • Primitive-level cryptographic correctness audits without dependency concerns
  • Runtime side-channel analysis detached from dependency configuration
  • Declaring dependency risk confirmed without advisory and code-path verification

Core Review Areas

  1. Dependency lockfile completeness and version provenance
  2. Advisory coverage for direct and transitive crypto dependencies
  3. Security-significant feature-flag behavior
  4. Fork provenance, patch drift, and vendored dependency auditability
  5. Toolchain/MSRV drift and duplicate crypto stack semantics

Workflow

Phase 1: Graph and inventory

  • Read references/dependency-checklist.md
  • Execute workflows/advisory-review.md
  • Enumerate direct/transitive crypto dependencies and active feature sets

Phase 2: Advisory and feature review

  • Compare dependency graph against known advisories/changelogs
  • Validate security semantics for enabled/disabled feature-flag combinations
  • Identify duplicate crates/libs with incompatible behavior expectations

Phase 3: Pattern hunt

  • Read references/finding-patterns.md
  • Prioritize vulnerable transitive pins, feature regressions, and stale fork drift

Phase 4: Handoff

  • Send surviving findings to crypto-fp-check
  • Use zkbugs-index only after the finding survives verification

Output Contract

Produce a dependency-specific handoff that includes:

  • The affected dependency path (direct/transitive/fork)
  • The advisory, feature-flag, or provenance invariant at risk
  • Whether the issue is versioning, feature semantics, duplicate stacks, or fork drift
  • The next verification or reporting route

Reference Index

What ships with it: 4 files

3.3 KB alongside SKILL.md

agents/

workflows/

Keep looking

Skills are one crate of 326,852. Ordering is by how many stacks a row turns up in, so the top of any crate is what has actually been picked rather than what has the most stars.