一键导入
dependency-audit
Scan dependencies for CVEs, outdated packages, license issues, and unused deps to produce a prioritized remediation list
用 Codex 或 Claude 帮你安装 复制这段 Prompt,粘贴到 Codex、Claude 或其他助手里,让它检查 Skill 页面并帮你完成安装。
菜单
Scan dependencies for CVEs, outdated packages, license issues, and unused deps to produce a prioritized remediation list
用 Codex 或 Claude 帮你安装 复制这段 Prompt,粘贴到 Codex、Claude 或其他助手里,让它检查 Skill 页面并帮你完成安装。
基于 SOC 职业分类
Create Architecture Decision Records using the Michael Nygard template with context, decision, alternatives, and consequences
Generate or validate OpenAPI and AsyncAPI specs from code or requirements with consistent naming, errors, and pagination
Generate CHANGELOG.md from git history in Keep a Changelog format with Added, Changed, Deprecated, Removed, Fixed, and Security categories
Generate CI/CD pipeline config for detected platform with lint, test, build, and deploy stages
Guide deployment processes including CI/CD pipeline creation, environment setup, and rollback procedures
Analyze Dockerfile and produce optimized version with multi-stage builds, layer caching, minimal base, and security hardening
| name | dependency-audit |
| description | Scan dependencies for CVEs, outdated packages, license issues, and unused deps to produce a prioritized remediation list |
| license | MIT |
| compatibility | opencode |
| metadata | {"audience":"developers","workflow":"general"} |
Use this skill when you need to:
Detect: Identify package manager and lockfiles
package-lock.json / yarn.lock / pnpm-lock.yaml (Node.js)requirements.txt / poetry.lock / Pipfile.lock (Python)pom.xml / build.gradle (Java)go.sum (Go)Cargo.lock (Rust)Scan for vulnerabilities: Run the appropriate audit command
# Node.js
npm audit --json
# Python
pip-audit --format=json
# Go
govulncheck ./...
Check for outdated packages: List packages behind latest
npm outdated --json
pip list --outdated --format=json
Detect unused dependencies: Cross-reference imports against declared deps
License audit: Extract license from each dependency
Prioritize findings: Produce a remediation table
## Dependency Audit Report
### Critical Vulnerabilities
| Package | Version | CVE | Severity | Fix Version |
|---------|---------|-----|----------|-------------|
| example | 1.2.3 | CVE-2024-XXXXX | Critical | 1.2.4 |
### Outdated Packages
| Package | Current | Latest | Type |
|---------|---------|--------|------|
| example | 1.0.0 | 2.0.0 | Major |
### License Issues
| Package | License | Issue |
|---------|---------|-------|
| example | GPL-3.0 | Incompatible with MIT project |
### Unused Dependencies
- `unused-pkg` — not imported anywhere in source