The author releases a Claude Code plugin marketplace with two named Skills: dev-flow for resumable engineering changes across multiple pull requests, and dependency-audit for reviewing CVEs and outdated packages.
dependency-audit
Audit a project's dependencies for known vulnerabilities (CVEs) and outdated packages across npm/pnpm/yarn, Go, Python, and Cargo, then produce a prioritized, read-only remediation report. Use when the teammate asks to audit or check dependencies, scan for vulnerable or outdated packages, run a supply-chain / dependency security check, or mentions npm audit, govulncheck, pip-audit, or cargo audit. Read-only — it never edits files or upgrades anything.
Datos de origen
- Repositorio
- PramodTKodag/claude-code-skills
- Última actividad en el origen
- 29 de septiembre de 2026 a las 11:21
- Idioma detectado de SKILL.md
- inglés
- Estrellas
- 1
- Forks
- 0
dependency-audit: report vulnerable and outdated dependencies
Inspect a project’s dependency ecosystems, run their vulnerability and outdated-package tools, and produce a prioritized remediation report. The audit itself keeps manifests, lockfiles and code unchanged.
Prerequisites
The source covers npm/pnpm/yarn, Go, Python and Cargo projects. Each detected ecosystem needs its corresponding audit tool; unavailable tools are reported as not run.
How to use
Provide the project to audit or ask to check its dependencies. The workflow detects manifests and lockfiles, runs the native tools once, and summarizes severity, installed and fixed versions, advisory IDs and dependency paths. It separates patch or minor recommendations from changes needing review.
Limitations
The Skill reports and proposes; it does not install upgrades or apply fixes. A missing audit tool is not a passing result. Advisory IDs, severities and fixed versions must come from the actual tool output.
Opciones de instalación
De forma predeterminada está seleccionado el prompt que primero revisa el origen. Puedes cambiar a un comando directo o descargar una copia local.
Revisa los archivos de origen
Lee SKILL.md y los archivos complementarios que muestra SkillsMP antes de decidir si quieres instalarlo.
Mostrando SKILL.md
- name
- dependency-audit
- description
- Audit a project's dependencies for known vulnerabilities (CVEs) and outdated packages across npm/pnpm/yarn, Go, Python, and Cargo, then produce a prioritized, read-only remediation report. Use when the teammate asks to audit or check dependencies, scan for vulnerable or outdated packages, run a supply-chain / dependency security check, or mentions npm audit, govulncheck, pip-audit, or cargo audit. Read-only — it never edits files or upgrades anything.
- user-invocable
- true
- allowed-tools
- ["Read","Grep","Glob","Bash(npm audit*)","Bash(npm outdated*)","Bash(pnpm audit*)","Bash(pnpm outdated*)","Bash(yarn audit*)","Bash(yarn outdated*)","Bash(govulncheck*)","Bash(go list*)","Bash(pip-audit*)","Bash(pip list*)","Bash(uv*)","Bash(cargo audit*)","Bash(cargo outdated*)","Bash(jq*)"]
- effort
- medium