一键导入
deps-audit
Scan one or more projects for dependency vulnerabilities, outdated packages, and cross-project version conflicts.
用 Codex 或 Claude 帮你安装 复制这段 Prompt,粘贴到 Codex、Claude 或其他助手里,让它检查 Skill 页面并帮你完成安装。
菜单
Scan one or more projects for dependency vulnerabilities, outdated packages, and cross-project version conflicts.
用 Codex 或 Claude 帮你安装 复制这段 Prompt,粘贴到 Codex、Claude 或其他助手里,让它检查 Skill 页面并帮你完成安装。
基于 SOC 职业分类
Scan project, then generate or reconcile .primeignore patterns for smarter /prime loading
Run WCAG accessibility audits on frontend projects. Checks HTML semantics, ARIA usage, color contrast, and keyboard navigation patterns.
Generate OpenAPI specs from code, validate API contracts, and check for breaking changes between versions.
Backend architecture patterns, API design, database optimization, and server-side best practices for Node.js, Express, and Next.js API routes.
Incrementally fix TypeScript and build errors one at a time with verification. Invokes the build-error-resolver agent.
Create or verify a checkpoint in your workflow
| name | deps-audit |
| description | Scan one or more projects for dependency vulnerabilities, outdated packages, and cross-project version conflicts. |
| argument-hint | [--python|--node|--all|<project-path>] |
Scan one or more projects for dependency vulnerabilities, outdated packages, and cross-project version inconsistencies.
Decide what to audit, in this order:
~/projects), scan each immediate subdirectory that contains a dependency manifest.Ask the user which scope they want if it is ambiguous.
Parse $ARGUMENTS:
--all: Audit every discovered project (default)--python: Only audit Python projects--node: Only audit Node.js projects<project-path>: Audit a specific project directoryFor each project in scope, check which dependency manifests exist:
# Python manifests
test -f <path>/requirements.txt && echo "requirements.txt"
test -f <path>/pyproject.toml && echo "pyproject.toml"
# Node manifests (check root and common subdirs like frontend/, web/, apps/)
test -f <path>/package.json && echo "package.json"
test -f <path>/frontend/package.json && echo "frontend/package.json"
test -f <path>/web/package.json && echo "web/package.json"
test -f <path>/apps/web/package.json && echo "apps/web/package.json"
test -f <path>/apps/api/package.json && echo "apps/api/package.json"
# Go manifests
test -f <path>/go.mod && echo "go.mod"
Skip projects with no manifests.
Output a discovery table first:
## Manifest Discovery
| Project | Python | Node | Go |
|---------|--------|------|----|
| api-service | requirements.txt | — | — |
| web-app | pyproject.toml | frontend/package.json | — |
| platform | pyproject.toml | web/package.json | — |
| dashboard | — | apps/web/package.json, apps/api/package.json | — |
| cli-tool | — | package.json (pnpm) | — |
For each project with Python dependencies:
Option A — pip-audit available:
cd <path> && pip-audit -r requirements.txt 2>&1
# OR
cd <path> && pip-audit 2>&1 # (uses pyproject.toml)
Option B — pip-audit not available (fallback):
# Check if pip-audit is installed
pip-audit --version 2>/dev/null || python3 -m pip_audit --version 2>/dev/null
If pip-audit is not installed, use safety or manual checking:
# Try safety
safety check -r <path>/requirements.txt 2>&1
# If neither available, report
echo "Neither pip-audit nor safety installed. Install with: pip install pip-audit"
Option C — Read and report versions manually:
If no audit tool is available, read the requirements file and report the dependency list with a note that automated vulnerability scanning needs pip-audit installed:
cat <path>/requirements.txt | grep -v "^#" | grep -v "^$" | head -30
For each project with Node.js dependencies:
Detect the package manager first:
test -f <path>/pnpm-lock.yaml && echo "pnpm"
test -f <path>/yarn.lock && echo "yarn"
test -f <path>/bun.lockb && echo "bun"
test -f <path>/package-lock.json && echo "npm"
Then run the appropriate audit:
# npm
cd <path> && npm audit --json 2>/dev/null | python3 -c "
import sys,json
try:
d=json.load(sys.stdin)
v=d.get('metadata',{}).get('vulnerabilities',{})
print(f\" critical: {v.get('critical',0)}, high: {v.get('high',0)}, moderate: {v.get('moderate',0)}, low: {v.get('low',0)}\")
except: print(' Could not parse audit output')
"
# pnpm
cd <path> && pnpm audit --json 2>/dev/null | python3 -c "
import sys,json
try:
d=json.load(sys.stdin)
advisories=d.get('advisories',{})
by_severity={'critical':0,'high':0,'moderate':0,'low':0}
for a in advisories.values():
sev=a.get('severity','low')
by_severity[sev]=by_severity.get(sev,0)+1
print(f\" critical: {by_severity['critical']}, high: {by_severity['high']}, moderate: {by_severity['moderate']}, low: {by_severity['low']}\")
except: print(' Could not parse audit output')
"
If lock file doesn't exist, note: "No lock file — run <pm> install first to generate one."
For each project, check for outdated major versions:
Python:
cd <path> && pip list --outdated --format=json 2>/dev/null | python3 -c "
import sys,json
try:
pkgs=json.load(sys.stdin)
major=[p for p in pkgs if p['latest_version'].split('.')[0] != p['version'].split('.')[0]]
if major:
for p in major[:10]:
print(f\" {p['name']}: {p['version']} -> {p['latest_version']} (MAJOR)\")
print(f' {len(pkgs)} total outdated, {len(major)} major version bumps')
except: print(' Could not check outdated packages')
" 2>/dev/null
Node.js:
cd <path> && npm outdated --json 2>/dev/null | python3 -c "
import sys,json
try:
d=json.load(sys.stdin)
major=[(k,v) for k,v in d.items() if v.get('current','0').split('.')[0] != v.get('latest','0').split('.')[0]]
for name,v in major[:10]:
print(f\" {name}: {v.get('current','?')} -> {v.get('latest','?')} (MAJOR)\")
print(f' {len(d)} total outdated, {len(major)} major version bumps')
except: print(' Could not check outdated packages')
" 2>/dev/null
If auditing more than one project, compare shared dependencies:
Output format:
## Cross-Project Version Conflicts
| Package | Project A (version) | Project B (version) | Risk |
|---------|-------------------|-------------------|------|
| react | dashboard (18.2.0) | platform (19.0.0) | Major mismatch |
| anthropic | api-service (0.28.0) | web-app (0.31.0) | Minor mismatch |
If no conflicts: "No cross-project version conflicts found."
Output a final summary:
## Dependency Audit Summary
| Project | Vulnerabilities | Outdated | Action Needed |
|---------|----------------|----------|---------------|
| api-service | 0 critical, 2 high | 5 major bumps | YES |
| web-app (py) | 1 critical | 3 major bumps | YES |
| web-app (node) | 0 critical, 1 high | 8 major bumps | REVIEW |
| platform (py) | 0 | 2 major bumps | LOW |
| dashboard (node) | 0 | 4 major bumps | LOW |
| cli-tool (node) | 3 high | 12 major bumps | YES |
Cross-project conflicts: X found
Action items:
1. [CRITICAL] web-app: 1 critical Python vulnerability — fix immediately
2. [HIGH] api-service: 2 high vulnerabilities — schedule fix
3. [INFO] 5 projects have major version bumps available
npm audit fix, pip install --upgrade, or manual intervention