Dependency auditor
Skill Yue-Zhou1/zkcrypto-audit/plugins/implementation-safety/skills/dependency-auditor
Audit cryptographic dependency sets for vulnerable versions, security-significant feature flags, advisory coverage, transitive risk, and stale fork provenance.From its SKILL.md
npx -y skills add Yue-Zhou1/zkcrypto-audit --skill dependency-auditorAssembled from the repository path, not quoted from the project. Check it against their README if it does not work.
One thing to look at
- 2 stars2 stars. Stars are a popularity signal and not a quality one, but at this level it is likely that nobody has read this closely except its author, and you would be relying on your own review.
SKILL.md
2.5 KB, 453 tokens by cl100k_base, as published. Nobody here has run it
dependency-auditor
Domain auditor for crypto dependency hygiene and supply-chain risk.
When to Use
- Auditing lockfiles and dependency graphs for vulnerable cryptographic crates/libs
- Reviewing security-significant feature-flag semantics
- Checking transitive dependency duplication and semantic drift
- Validating fork provenance and patch divergence from upstream
When NOT to Use
- Primitive-level cryptographic correctness audits without dependency concerns
- Runtime side-channel analysis detached from dependency configuration
- Declaring dependency risk confirmed without advisory and code-path verification
Core Review Areas
- Dependency lockfile completeness and version provenance
- Advisory coverage for direct and transitive crypto dependencies
- Security-significant feature-flag behavior
- Fork provenance, patch drift, and vendored dependency auditability
- Toolchain/MSRV drift and duplicate crypto stack semantics
Workflow
Phase 1: Graph and inventory
- Read
references/dependency-checklist.md - Execute
workflows/advisory-review.md - Enumerate direct/transitive crypto dependencies and active feature sets
Phase 2: Advisory and feature review
- Compare dependency graph against known advisories/changelogs
- Validate security semantics for enabled/disabled feature-flag combinations
- Identify duplicate crates/libs with incompatible behavior expectations
Phase 3: Pattern hunt
- Read
references/finding-patterns.md - Prioritize vulnerable transitive pins, feature regressions, and stale fork drift
Phase 4: Handoff
- Send surviving findings to
crypto-fp-check - Use
zkbugs-indexonly after the finding survives verification
Output Contract
Produce a dependency-specific handoff that includes:
- The affected dependency path (direct/transitive/fork)
- The advisory, feature-flag, or provenance invariant at risk
- Whether the issue is versioning, feature semantics, duplicate stacks, or fork drift
- The next verification or reporting route
Reference Index
What ships with it: 4 files
3.3 KB alongside SKILL.md
agents/
- openai.yaml432 B
references/
- dependency-checklist.md1.2 KB
- finding-patterns.md648 B
workflows/
- advisory-review.md1.1 KB