Agent skill

Dependency Audit

by agulli in agulli/atlas-agents

Audit project dependencies for vulnerabilities, license issues, and bloat.

MITAuto-check passedFrontend & Design

Install Dependency Audit

skills CLI
$ npx skills add agulli/atlas-agents --skill dependency-audit -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install agulli/atlas-agents dependency-audit --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/agulli/atlas-agents.git skills-src && mkdir -p .claude/skills && cp -r skills-src/ch09_agent_skills/skills/dependency-audit .claude/skills/dependency-audit && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
dependency-audit
GitHub stars
579
Token cost
~477 tokens
SKILL.md length
189 words
Files
1
Skills in repo
12
Repo updated
First seen
Licence
MIT

At a glance

Audit project dependencies for vulnerabilities, license issues, and bloat.

  • Works in 6 steps: Identify the package manager. Look for → Run vulnerability scan. → Check for outdated packages. → …
  • Asked to check dependencies
  • SKILL.md covers Process, Rationalizations and Verification
  • Calls npx, pip and uvx

What it does

Dependency Audit is an agent skill from agulli/atlas-agents. Audit project dependencies for vulnerabilities, license issues, and bloat. Use when asked to check dependencies, audit packages, find vulnerable libraries, or reduce bundle size.

Its SKILL.md is about 480 tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts. Compatibility notes: Requires pip or npm/yarn/pnpm

It sits in Frontend & Design, covering Web performance. It works with npm, Python and Node.js. The licence is MIT.

When your agent uses it

  • Asked to check dependencies
  • Find vulnerable libraries
  • Reduce bundle size

Example prompts

  • “/dependency-audit”

Requirements

  • Python 3
  • Node.js
  • Compatibility (from SKILL.md): Requires pip or npm/yarn/pnpm

Workflow steps

6 steps, taken from the first numbered list in SKILL.md.

  1. Identify the package manager. Look for
  2. Run vulnerability scan.
  3. Check for outdated packages.
  4. License audit. Check that no dependency uses a copyleft license (GPL, AGPL) in a proprietary project
  5. Identify unused dependencies.
  6. Write the report as a markdown table with columns: Package, Current Version, Latest Version, Vulnerabilities, License, Status…

What it can do on your machine

Read from SKILL.md and the folder at commit 2b21998. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • npx
    • pip
    • uvx
    • npm

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use npx, pip, uvx and npm, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

  • Compatibility

    Requires pip or npm/yarn/pnpm

    From compatibility in the SKILL.md frontmatter.

Context cost

Dependency Audit loads about 477 tokens when it runs. Until then it costs about 49 tokens; SKILL.md has 189 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~49
When it runs · the whole SKILL.md, loaded when a task matches
~477

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from agulli/atlas-agents at commit 2b21998, republished under its MIT licence (© agulli). 189 words, ~477 tokens.

Download SKILL.mdSave it as .claude/skills/dependency-audit/SKILL.md (or your agent's skills folder).
name
dependency-audit
description
Audit project dependencies for vulnerabilities, license issues, and bloat. Use when asked to check dependencies, audit packages, find vulnerable libraries, or reduce bundle size.
compatibility
Requires pip or npm/yarn/pnpm
license
MIT

Process

  1. Identify the package manager. Look for:

    • requirements.txt / pyproject.toml / Pipfile → Python (pip/uv)
    • package.json → Node.js (npm/yarn/pnpm)
    • go.mod → Go
    • Cargo.toml → Rust
  2. Run vulnerability scan.

    • Python: pip audit or uvx pip-audit
    • Node.js: npm audit or npx better-npm-audit audit
    • Go: govulncheck ./...
  3. Check for outdated packages.

    • Python: pip list --outdated
    • Node.js: npm outdated
  4. License audit. Check that no dependency uses a copyleft license (GPL, AGPL) in a proprietary project:

    • Python: uvx pip-licenses --order=license
    • Node.js: npx license-checker --summary
  5. Identify unused dependencies.

    • Python: Check each import with grep -r "import <package>" src/
    • Node.js: npx depcheck
  6. Write the report as a markdown table with columns: Package, Current Version, Latest Version, Vulnerabilities, License, Status (keep/update/remove).

Rationalizations

ExcuseRebuttal
"We'll update dependencies later"Known vulnerabilities are actively exploited. Flag them now.
"It's a dev dependency, it doesn't matter"Dev dependencies run in CI and on developer machines — they are attack surface.
"Removing unused deps might break something"If nothing imports it, nothing uses it. Remove it.

Verification

  • Vulnerability scan was executed (not estimated)
  • Every critical/high vulnerability has a recommended action (update version or replace package)
  • License compatibility was checked against the project's license

© agulli, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in ch09_agent_skills/skills/dependency-audit of agulli/atlas-agents.

Open the folder on GitHubat commit 2b21998

Compare with similar skills

Dependency Audit next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Dependency Audit compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Dependency Audit this skillagulli/atlas-agents579—~477Automated safety check: PassMIT
Performance Profileralirezarezvani/claude-skills28k—~684Automated safety check: PassMIT
Sap Extension Creatorheshengtao/super-agent-party2.7k—~6kAutomated safety check: PassAGPL-3.0
Core Web VitalsvmDeshpande/ai-agent-automation1784 repos~3.6kAutomated safety check: PassMIT
Orchardcore Asset ManagerOrchardCMS/OrchardCore8.2k—~1.5kAutomated safety check: PassBSD-3-Clause
CI Pipeline Synthesizerkajisho5/ffmpeg-skill1.9k1 repos~1.1kAutomated safety check: PassMIT

Similar skills

  • Performance Profiler

    alirezarezvani/claude-skills

    Systematic performance profiling for Node.js, Python, and Go applications.

    28k GitHub stars~684 tokensUpdated 1 mo ago
    DevelopmentAuto-check passed
  • Sap Extension Creator

    heshengtao/super-agent-party

    Create Super Agent Party (SAP) extensions. An agent skill from heshengtao/super-agent-party.

    2.7k GitHub stars~6k tokensUpdated 1 mo ago
    Frontend & DesignAuto-check passed
  • Core Web Vitals

    vmDeshpande/ai-agent-automation

    Optimize Core Web Vitals (LCP, INP, CLS) for better page experience and search ranking.

    178 GitHub starsUsed in 4 repos~3.6k tokens
    Frontend & DesignAuto-check passed
  • Orchardcore Asset Manager

    OrchardCMS/OrchardCore

    Builds, watches, and manages frontend assets in OrchardCore.

    8.2k GitHub stars~1.5k tokensUpdated today
    Frontend & DesignAuto-check passed
  • CI Pipeline Synthesizer

    kajisho5/ffmpeg-skill

    Generate GitHub Actions CI/CD pipeline configurations for automated building and testing of library and package projects.

    1.9k GitHub starsUsed in 1 repo~1.1k tokens
    DevOps & CloudAuto-check passed
  • Compare Array Bundle Size

    PostHog/posthog-js

    Official

    Quickly compare the posthog-js array.js bundle size in the current working tree against a git baseline using the repository's esbuild proxy.

    613 GitHub stars~599 tokensUpdated today
    Frontend & DesignAuto-check passed

More from agulli/atlas-agents

All 12 skills in this repo
  • API Design

    agulli/atlas-agents

    Design or review REST and GraphQL API interfaces. An agent skill from agulli/atlas-agents.

    579 GitHub stars~539 tokensUpdated 2 mo ago
    Auto-check passed
  • Data Pipeline

    agulli/atlas-agents

    Design, build, or debug data processing pipelines. An agent skill from agulli/atlas-agents.

    579 GitHub stars~714 tokensUpdated 2 mo ago
    Auto-check passed
  • Database Migration

    agulli/atlas-agents

    Safely run database schema migrations. An agent skill from agulli/atlas-agents.

    579 GitHub stars~702 tokensUpdated 2 mo ago
    Auto-check passed
  • Deploy Checklist

    agulli/atlas-agents

    Execute a structured deployment to staging or production. An agent skill from agulli/atlas-agents.

    579 GitHub stars~756 tokensUpdated 2 mo ago
    Auto-check passed
  • Documentation Writer

    agulli/atlas-agents

    Write or update technical documentation for code, APIs, or systems.

    579 GitHub stars~639 tokensUpdated 2 mo ago
    Auto-check passed
  • Git Commit

    agulli/atlas-agents

    Create well-structured git commits with conventional commit messages.

    579 GitHub stars~463 tokensUpdated 2 mo ago
    Auto-check: notes

Questions about Dependency Audit

What does Dependency Audit do?

Audit project dependencies for vulnerabilities, license issues, and bloat. Dependency Audit is an agent skill from agulli/atlas-agents. Audit project dependencies for vulnerabilities, license issues, and bloat.

When should I use Dependency Audit?

Dependency Audit fits situations like: asked to check dependencies; find vulnerable libraries; reduce bundle size.

How do I install Dependency Audit in Claude Code?

Run `npx skills add agulli/atlas-agents --skill dependency-audit -a claude-code`. Or copy the skill folder (ch09_agent_skills/skills/dependency-audit in agulli/atlas-agents) into .claude/skills/dependency-audit in your project. Claude Code loads it when a task matches its description.

How do I install Dependency Audit in Codex?

Run `npx skills add agulli/atlas-agents --skill dependency-audit -a codex`. Or copy the skill folder (ch09_agent_skills/skills/dependency-audit in agulli/atlas-agents) into .agents/skills/dependency-audit in your project. Codex loads it when a task matches its description.

Can I use Dependency Audit in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add agulli/atlas-agents --skill dependency-audit -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/dependency-audit, .gemini/skills/dependency-audit, .github/skills/dependency-audit and .opencode/skills/dependency-audit in your project.

What does Dependency Audit need to run?

Going by SKILL.md and its folder, Dependency Audit needs the command-line tools its instructions call (npx, pip, uvx and npm). Our summary lists: Python 3; Node.js. Compatibility (from SKILL.md): Requires pip or npm/yarn/pnpm.

Does Dependency Audit access the network?

SKILL.md contains no URLs. Its commands use npx, pip, uvx and npm, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Dependency Audit safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Dependency Audit use?

Dependency Audit is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Dependency Audit use?

About 477 tokens (SKILL.md is roughly 1.9k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Dependency Audit?

Skills that share tags, products or a category with Dependency Audit: Performance Profiler (alirezarezvani/claude-skills, 28k stars), Sap Extension Creator (heshengtao/super-agent-party, 2.7k stars), Core Web Vitals (vmDeshpande/ai-agent-automation, 178 stars) and Orchardcore Asset Manager (OrchardCMS/OrchardCore, 8.2k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Dependency Audit?

agulli (a GitHub user) maintains it in agulli/atlas-agents, which has 579 GitHub stars. The repository holds 12 skills in this directory. The repository was last updated on July 17, 2026.

Source: agulli/atlas-agents on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.