Dependency Scanning
sickn33/agentic-awesome-skills
Scan package dependencies for known vulnerabilities using Snyk, Dependabot, and OWASP Dependency-Check.
依赖关系分析技能:回答"改这里会影响哪里". An agent skill from 312362115/claude.
$ npx skills add 312362115/claude --skill dependency-map -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install 312362115/claude dependency-map --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/312362115/claude.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/dependency-map .claude/skills/dependency-map && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "dependency-map" agent skill from https://github.com/312362115/claude/tree/main/skills/dependency-map into .claude/skills/dependency-map/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "dependency-map", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/312362115/claude/tree/main/skills/dependency-mapType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add 312362115/claude --skill dependency-map -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install 312362115/claude dependency-map --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/312362115/claude.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/dependency-map .agents/skills/dependency-map && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "dependency-map" agent skill from https://github.com/312362115/claude/tree/main/skills/dependency-map into .agents/skills/dependency-map/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "dependency-map", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add 312362115/claude --skill dependency-map -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install 312362115/claude dependency-map --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/312362115/claude.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/dependency-map .cursor/skills/dependency-map && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "dependency-map" agent skill from https://github.com/312362115/claude/tree/main/skills/dependency-map into .cursor/skills/dependency-map/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "dependency-map", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/312362115/claude.git --path skills/dependency-map--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add 312362115/claude --skill dependency-map -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install 312362115/claude dependency-map --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/312362115/claude.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/dependency-map .gemini/skills/dependency-map && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "dependency-map" agent skill from https://github.com/312362115/claude/tree/main/skills/dependency-map into .gemini/skills/dependency-map/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "dependency-map", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install 312362115/claude dependency-mapInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add 312362115/claude --skill dependency-map -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/312362115/claude.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/dependency-map .github/skills/dependency-map && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "dependency-map" agent skill from https://github.com/312362115/claude/tree/main/skills/dependency-map into .github/skills/dependency-map/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "dependency-map", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add 312362115/claude --skill dependency-map -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install 312362115/claude dependency-map --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/312362115/claude.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/dependency-map .opencode/skills/dependency-map && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "dependency-map" agent skill from https://github.com/312362115/claude/tree/main/skills/dependency-map into .opencode/skills/dependency-map/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "dependency-map", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
dependency-map依赖关系分析技能:回答"改这里会影响哪里". An agent skill from 312362115/claude.
Dependency Map is an agent skill from 312362115/claude. 依赖关系分析技能:回答"改这里会影响哪里"。 追踪调用链、数据流、副作用,评估改动的影响面。 和 code-walkthrough 的区别:walkthrough 关注"是什么",dependency-map 关注"改了影响谁"。 触发词:影响面、改这个会影响哪里、依赖关系、调用链、影响分析、谁在用这个。 触发场景:改动前评估影响、重构前分析依赖、删代码前确认安全、API 变更前评估调用方。 即使用户没有说"依赖分析",只要意图是"评估改动的影响范围",都应触发此技能。
Its SKILL.md is about 890 tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
The licence is MIT.
Read from SKILL.md and the folder at commit 2d4fa49. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md (its code samples are markdown and bash).
From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Dependency Map loads about 888 tokens when it runs. Until then it costs about 63 tokens; SKILL.md has 63 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from 312362115/claude at commit 2d4fa49, republished under its MIT licence (© 312362115). 63 words, ~888 tokens.
.claude/skills/dependency-map/SKILL.md (or your agent's skills folder).代码改动最怕的不是改错,而是不知道改动波及到了哪里。 本 skill 的使命:在改动之前,画出影响面地图。
用 AskUserQuestion 确认:
分析请求
│
├─ 改函数签名 → 追踪所有调用方
├─ 改数据结构 → 追踪数据的读写点
├─ 删文件/模块 → 追踪所有 import
├─ 改 API 接口 → 追踪前端调用 + 外部消费方
└─ 改配置/环境变量 → 追踪所有引用点# 找到谁引用了目标文件
grep -r "import.*from.*'目标模块'" src/
grep -r "require('目标模块')" src/
# 或用 Grep 工具搜索输出格式:
## 引用关系
### 被谁引用(上游,改目标会影响他们)
- `src/api/auth.ts:3` — import { login } from './services/auth'
- `src/api/user.ts:5` — import { validateToken } from './services/auth'
- `tests/auth.test.ts:1` — import { login, logout } from '../services/auth'
### 引用了谁(下游,目标依赖他们)
- `src/models/user.ts` — UserModel
- `src/utils/jwt.ts` — signToken, verifyToken
- `bcrypt` — 外部依赖对于函数级分析,追踪更精细的调用关系:
# 搜索函数名的所有调用
grep -rn "目标函数名(" src/ --include="*.ts" --include="*.js"输出格式:
## 调用链:validateToken()
定义:src/services/auth.ts:45
调用方:
├─ src/middleware/auth.ts:12 — authMiddleware() 每个请求都会调用
│ └─ 被 src/api/index.ts:8 的 app.use(authMiddleware) 注册为全局中间件
├─ src/api/user.ts:23 — getUserProfile() 手动调用做额外校验
└─ tests/auth.test.ts:34 — 测试用例
影响面评估:
- authMiddleware 是全局中间件 → 改签名会影响所有需要认证的接口
- 测试需要同步更新当改动涉及数据结构时,追踪数据从哪来、到哪去:
## 数据流:User 类型
### 定义位置
`src/types/user.ts:5` — interface User { id, name, email, role }
### 创建点(写入)
- `src/services/user.ts:createUser()` — 注册时创建
- `src/services/auth.ts:oauthCallback()` — OAuth 登录时创建
### 读取点
- `src/api/user.ts:getUserProfile()` — 返回给前端
- `src/middleware/auth.ts:12` — 从 token 解析出 user
- `src/services/order.ts:45` — 创建订单时读取 user.id
### 持久化
- `src/models/user.ts` — 数据库 users 表
- `src/utils/cache.ts:getUserCache()` — Redis 缓存
### 影响评估
如果给 User 加字段:
- 数据库需要 migration
- 缓存的序列化/反序列化需要兼容
- API 响应自动包含(如果没有字段过滤的话)
如果删 User 字段:
- 检查所有读取点是否还在用
- 前端是否依赖这个字段## 影响面评估:<改动描述>
### 直接影响(必须改)
| 文件 | 行号 | 影响原因 | 改动类型 |
|------|------|---------|---------|
| src/api/auth.ts | 23 | 调用了要修改的函数 | 同步更新参数 |
| src/middleware/auth.ts | 12 | 依赖返回值结构 | 适配新结构 |
### 间接影响(需要验证)
| 文件 | 行号 | 风险点 | 验证方式 |
|------|------|--------|---------|
| src/api/user.ts | 45 | 使用了相同的类型 | 跑测试确认 |
### 不受影响(确认安全)
- src/services/order.ts — 虽然在同目录,但无依赖关系
- src/utils/format.ts — 纯工具函数,不涉及
### 测试影响
- tests/auth.test.ts — 需要更新测试用例
- tests/user.test.ts — 需要回归验证| 等级 | 判断标准 |
|---|---|
| 低风险 | 只影响内部实现,公共接口不变,有测试覆盖 |
| 中风险 | 影响多个文件但不影响外部接口,有部分测试覆盖 |
| 高风险 | 影响公共接口/全局中间件/数据结构,测试覆盖不足 |
code-walkthrough(理解代码)→ dependency-map(评估影响)→ refactoring(执行改动)dependency-map vs code-walkthrough:
© 312362115, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in skills/dependency-map of 312362115/claude.
Open the folder on GitHubat commit 2d4fa49
Dependency Map next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Dependency Map this skill312362115/claude | 107 | — | ~888 | Automated safety check: Pass | MIT | |
| Dependency Scanningsickn33/agentic-awesome-skills | 47k | 1 repos | ~2.4k | Automated safety check: Pass | MIT | |
| Dependency Checkruvnet/ruflo | 74k | — | ~258 | Automated safety check: Pass | MIT | |
| When Mapping Dependencies Use Dependency Mapperaiskillstore/marketplace | 430 | 1 repos | ~1.6k | Automated safety check: Pass | None | |
| Dependency Mapborghei/Claude-Skills | 881 | — | ~1.7k | Automated safety check: Pass | MIT | |
| Dependency Updatecodewhale-hq/Codewhale | 41k | — | ~142 | Automated safety check: Pass | MIT |
sickn33/agentic-awesome-skills
Scan package dependencies for known vulnerabilities using Snyk, Dependabot, and OWASP Dependency-Check.
ruvnet/ruflo
Scan project dependencies for known vulnerabilities and CVEs.
aiskillstore/marketplace
Comprehensive dependency mapping, analysis, and visualization tool for software projects
borghei/Claude-Skills
Cross-team dependency tracking with critical path analysis and Mermaid dependency graphs for program coordination.
codewhale-hq/Codewhale
Read release notes/changelogs, update a defined dependency scope, handle breaking changes, and verify.
nexu-io/open-design
Map an extracted Figma / source-code token bag onto the active OD design system, producing a deterministic mapping the generate stage can consume.
312362115/claude
专业图表生成技能:根据需求自动选择合适的图表类型,生成符合设计规范的 PNG 图表. An agent skill from 312362115/claude.
312362115/claude
深度调研技能:对任意命题进行系统性调研并输出专业研究报告. An agent skill from 312362115/claude.
312362115/claude
MD 文件浏览器预览:GitHub 风格渲染 + 左侧自动目录. An agent skill from 312362115/claude.
312362115/claude
通用写作技能:以"内容→组件→组合"的方式产出技术文档、产品文档、汇报材料. An agent skill from 312362115/claude.
312362115/claude
代码导读技能:帮助快速理解不熟悉的项目或模块,建立心智模型. An agent skill from 312362115/claude.
312362115/claude
数据库代码审查 + Migration 安全检查. An agent skill from 312362115/claude.
依赖关系分析技能:回答"改这里会影响哪里". An agent skill from 312362115/claude. Dependency Map is an agent skill from 312362115/claude.
Run `npx skills add 312362115/claude --skill dependency-map -a claude-code`. Or copy the skill folder (skills/dependency-map in 312362115/claude) into .claude/skills/dependency-map in your project. Claude Code loads it when a task matches its description.
Run `npx skills add 312362115/claude --skill dependency-map -a codex`. Or copy the skill folder (skills/dependency-map in 312362115/claude) into .agents/skills/dependency-map in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add 312362115/claude --skill dependency-map -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/dependency-map, .gemini/skills/dependency-map, .github/skills/dependency-map and .opencode/skills/dependency-map in your project.
SKILL.md names no scripts, command-line tools or credentials: Dependency Map is instructions for the agent only.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Dependency Map is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 888 tokens (SKILL.md is roughly 3.6k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Dependency Map: Dependency Scanning (sickn33/agentic-awesome-skills, 47k stars), Dependency Check (ruvnet/ruflo, 74k stars), When Mapping Dependencies Use Dependency Mapper (aiskillstore/marketplace, 430 stars) and Dependency Map (borghei/Claude-Skills, 881 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
312362115 (a GitHub user) maintains it in 312362115/claude, which has 107 GitHub stars. The repository holds 20 skills in this directory. The repository was last updated on May 14, 2026.
Source: 312362115/claude on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.