Skip to main content

Dependency Auditor

Skill Verified Active

Dependency Auditor

Purpose

To help development teams maintain secure, legally compliant, and up-to-date software projects by providing deep visibility into their dependency ecosystem.

Features

  • Vulnerability scanning and CVE matching
  • License compliance and legal risk assessment
  • Outdated dependency detection and analysis
  • Upgrade path planning and breaking change risk assessment
  • Multi-language support (JavaScript, Python, Go, Rust, Ruby, Java, PHP, C#)
  • Detailed reporting in text and JSON formats

Use Cases

  • Automating security vulnerability checks in CI/CD pipelines
  • Auditing project licenses for legal compliance before distribution
  • Planning and prioritizing dependency upgrades to manage technical debt
  • Identifying and mitigating risks associated with transitive dependencies

Non-Goals

  • Performing actual dependency installation or updates
  • Replacing dedicated package managers or security platforms
  • Providing legal advice on license interpretation beyond compatibility rules

Workflow

  1. Identify project path or dependency inventory file
  2. Run `dep_scanner.py` for vulnerability analysis
  3. Run `license_checker.py` for license compliance
  4. Run `upgrade_planner.py` to generate upgrade plans
  5. Review reports and recommendations for action

Practices

  • Security scanning
  • License auditing
  • Upgrade management
  • Dependency hygiene

Installation

First, add the marketplace

/plugin marketplace add alirezarezvani/claude-skills
/plugin install engineering@claude-code-skills

Quality Score

Verified
97 /100
Analyzed about 18 hours ago

Trust Signals

Last commitabout 21 hours ago
Stars14.6k
LicenseMIT
Status
View Source

Similar Extensions

Soul Guardian

100

Drift detection + baseline integrity guard for agent workspace files with automatic alerting support

Skill
prompt-security

Audit Dependency Versions

100

Audit project dependencies for version staleness, security vulnerabilities, and compatibility issues. Covers lock file analysis, upgrade path planning, and breaking change assessment. Use before a release to ensure dependencies are current and secure, during periodic maintenance reviews, after receiving a security advisory, when upgrading to a new language version, before submitting to CRAN or npm, or when inheriting a project to assess its dependency health.

Skill
pjt222

Codex Diff Develop

100

Revisa el diff de la rama actual frente a develop en proyectos Drupal 11 siguiendo la metodología Codex (lógica de negocio, edge cases de hooks/queries, seguridad, performance, completitud). Genera un informe .md en la carpeta del IDE detectado (.antigravity/, .cursor/, .vscode/ o docs/) con hallazgos por severidad y soluciones accionables. Usar cuando el usuario pida "Revisión diff develop", "revisión diff develop", "diff develop", "revisar diff", "codex diff" o expresiones similares con intención de auditar cambios contra develop. Triggers: diff develop, codex diff, revisión diff, lint diff develop, auditar diff.

Skill
j4rk0r

Clawsec Scanner

100

Automated vulnerability scanner for agent platforms. Performs dependency scanning (npm audit, pip-audit), multi-database CVE lookup (OSV, NVD, GitHub Advisory), SAST analysis (Semgrep, Bandit), and agent-specific DAST hook execution testing for OpenClaw hooks.

Skill
prompt-security

Investigate Capa Root Cause

100

Investigate root causes and manage CAPAs (Corrective and Preventive Actions) for compliance deviations. Covers investigation method selection (5-Why, fishbone, fault tree), structured root cause analysis, corrective vs preventive action design, effectiveness verification, and trend analysis. Use when an audit finding requires a CAPA, when a deviation or incident occurs in a validated system, when a regulatory observation needs a formal response, when a data integrity anomaly requires investigation, or when recurring issues suggest a systemic root cause.

Skill
pjt222

Toprank Weekly Review

100

Run a weekly SEO review for one registered website, write audit artifacts, and choose the next best safe action.

Skill
nowork-studio

© 2025 SkillRepo · Find the right skill, skip the noise.