The author releases a Claude Code plugin marketplace with two named Skills: dev-flow for resumable engineering changes across multiple pull requests, and dependency-audit for reviewing CVEs and outdated packages.
dependency-audit
Audit a project's dependencies for known vulnerabilities (CVEs) and outdated packages across npm/pnpm/yarn, Go, Python, and Cargo, then produce a prioritized, read-only remediation report. Use when the teammate asks to audit or check dependencies, scan for vulnerable or outdated packages, run a supply-chain / dependency security check, or mentions npm audit, govulncheck, pip-audit, or cargo audit. Read-only — it never edits files or upgrades anything.
معلومات المصدر
- المستودع
- PramodTKodag/claude-code-skills
- آخر نشاط في المصدر
- ٢٩ سبتمبر ٢٠٢٦ في ١١:٢١
- لغة SKILL.md المكتشفة
- الإنجليزية
- النجوم
- ١
- التفرعات
- ٠
dependency-audit: report vulnerable and outdated dependencies
Inspect a project’s dependency ecosystems, run their vulnerability and outdated-package tools, and produce a prioritized remediation report. The audit itself keeps manifests, lockfiles and code unchanged.
Prerequisites
The source covers npm/pnpm/yarn, Go, Python and Cargo projects. Each detected ecosystem needs its corresponding audit tool; unavailable tools are reported as not run.
How to use
Provide the project to audit or ask to check its dependencies. The workflow detects manifests and lockfiles, runs the native tools once, and summarizes severity, installed and fixed versions, advisory IDs and dependency paths. It separates patch or minor recommendations from changes needing review.
Limitations
The Skill reports and proposes; it does not install upgrades or apply fixes. A missing audit tool is not a passing result. Advisory IDs, severities and fixed versions must come from the actual tool output.
خيارات التثبيت
يُحدَّد Prompt الذي يراجع المصدر أولًا بشكل افتراضي. يمكنك التبديل إلى أمر مباشر أو تنزيل نسخة محلية.
مراجعة ملفات المصدر
اقرأ SKILL.md وأي ملفات مرافقة يعرضها SkillsMP قبل أن تقرر التثبيت.
عرض SKILL.md
- name
- dependency-audit
- description
- Audit a project's dependencies for known vulnerabilities (CVEs) and outdated packages across npm/pnpm/yarn, Go, Python, and Cargo, then produce a prioritized, read-only remediation report. Use when the teammate asks to audit or check dependencies, scan for vulnerable or outdated packages, run a supply-chain / dependency security check, or mentions npm audit, govulncheck, pip-audit, or cargo audit. Read-only — it never edits files or upgrades anything.
- user-invocable
- true
- allowed-tools
- ["Read","Grep","Glob","Bash(npm audit*)","Bash(npm outdated*)","Bash(pnpm audit*)","Bash(pnpm outdated*)","Bash(yarn audit*)","Bash(yarn outdated*)","Bash(govulncheck*)","Bash(go list*)","Bash(pip-audit*)","Bash(pip list*)","Bash(uv*)","Bash(cargo audit*)","Bash(cargo outdated*)","Bash(jq*)"]
- effort
- medium