用 Codex 或 Claude 帮你安装 复制这段 Prompt,粘贴到 Codex、Claude 或其他助手里,让它检查 Skill 页面并帮你完成安装。
直接命令不会经过审查 Prompt;运行前请先检查来源。
npx skills add https://github.com/stbenjam/skillsaw --skill audit-dependencies命令会保持在同一行。复制前请横向滚动并检查完整内容。
想先保存到本地?可下载 SkillsMP 当前能够提供的文件。
基于 SOC 职业分类
正在显示 SKILL.md
| name | audit-dependencies |
| description | Dependency audit across the service repositories. |
Reports which services pull a vulnerable or unmaintained dependency, and which of those are reachable from a request path.
depaudit scan --org platform writes one JSON report per repository. The
shape of that report is documented in the report
schema.
Reachability matters more than the raw CVE count. A vulnerable parser that runs only in a build script is not the same risk as one in the request path — see the triage rubric.
File one issue per reachable finding, using the issue template.