Agent skill

Dependency Auditor

by alirezarezvani in alirezarezvani/claude-code-tresor

Check dependencies for known vulnerabilities using npm audit, pip-audit, etc.

MITAuto-check: notesDevOps & Cloud

Install Dependency Auditor

skills CLI
$ npx skills add alirezarezvani/claude-code-tresor --skill dependency-auditor -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install alirezarezvani/claude-code-tresor dependency-auditor --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/alirezarezvani/claude-code-tresor.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/security/dependency-auditor .claude/skills/dependency-auditor && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
dependency-auditor
GitHub stars
777
Token cost
~1.2k tokens
SKILL.md length
224 words
Files
2
Skills in repo
7
Repo updated
First seen
Licence
MIT

At a glance

Check dependencies for known vulnerabilities using npm audit, pip-audit, etc.

  • Works in 5 steps: Regular audits: Run weekly or on every… → Update frequently: Keep dependencies… → Review breaking changes: Test before… → …
  • Requirements.txt changes
  • SKILL.md covers When I Activate, What I Check, Example Alerts and Automatic Actions, plus 7 more sections
  • Calls npm, bundle and mvn; reaches nvd.nist.gov

What it does

Dependency Auditor is an agent skill from alirezarezvani/claude-code-tresor. Check dependencies for known vulnerabilities using npm audit, pip-audit, etc. Use when package.json or requirements.txt changes, or before deployments. Alerts on vulnerable dependencies. Triggers on dependency file changes, deployment prep, security mentions.

Its SKILL.md is about 1.2k tokens, which your agent loads only when the skill is triggered. The skill folder holds 1 other file (for example `README.md`).

It sits in DevOps & Cloud, covering Deployment, Vulnerability scanning and Dependency management. It works with npm. The repository describes itself as: A world-class collection of Claude Code utilities: autonomous skills, expert agents, slash commands, and prompts that supercharge your development workflow. The licence is MIT.

When your agent uses it

  • Requirements.txt changes
  • Before deployments
  • Dependency file changes
  • Deployment prep

Example prompts

  • “/dependency-auditor”

Requirements

  • Python 3
  • Node.js
  • Pre-approved tools (allowed-tools): Bash, Read

Workflow steps

5 steps, taken from the first numbered list in SKILL.md.

  1. Regular audits: Run weekly or on every dependency change
  2. Update frequently: Keep dependencies current
  3. Review breaking changes: Test before major updates
  4. Pin versions: Use exact versions in production
  5. Audit lock files: Commit and audit lock files

What it can do on your machine

Read from SKILL.md and the folder at commit 4b68050. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Bash
    • Read

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • npm
    • bundle
    • mvn

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • nvd.nist.gov

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Dependency Auditor loads about 1.2k tokens when it runs. Until then it costs about 70 tokens; SKILL.md has 224 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~70
When it runs · the whole SKILL.md, loaded when a task matches
~1.2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NotePre-approves every shell command (allowed-tools: Bash)SKILL.md
    allowed-tools: Bash, Read

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from alirezarezvani/claude-code-tresor at commit 4b68050, republished under its MIT licence (© alirezarezvani). 224 words, ~1,240 tokens.

Download SKILL.mdSave it as .claude/skills/dependency-auditor/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
dependency-auditor
description
Check dependencies for known vulnerabilities using npm audit, pip-audit, etc. Use when package.json or requirements.txt changes, or before deployments. Alerts on vulnerable dependencies. Triggers on dependency file changes, deployment prep, security mentions.
allowed-tools
Bash, Read

Dependency Auditor Skill

Automatic dependency vulnerability checking.

When I Activate

  • ✅ package.json modified
  • ✅ requirements.txt changed
  • ✅ Gemfile or pom.xml modified
  • ✅ User mentions dependencies or vulnerabilities
  • ✅ Before deployments
  • ✅ yarn.lock or package-lock.json changes

What I Check

Dependency Vulnerabilities
  • Known CVEs in packages
  • Outdated dependencies with security fixes
  • Malicious packages
  • License compatibility issues
  • Deprecated packages
Package Managers Supported
  • Node.js: npm, yarn, pnpm
  • Python: pip, pipenv, poetry
  • Ruby: bundler
  • Java: Maven, Gradle
  • Go: go modules
  • PHP: composer

Example Alerts

NPM Vulnerability
bash
# You run: npm install lodash

# I automatically audit:
🚨 HIGH: Prototype Pollution in lodash
📍 Package: lodash@4.17.15
📦 Vulnerable versions: < 4.17.21
🔧 Fix: npm update lodash
📖 CVE-2020-8203
   https://nvd.nist.gov/vuln/detail/CVE-2020-8203

Recommendation: Update to lodash@4.17.21 or higher
Python Vulnerability
bash
# You modify requirements.txt: django==2.2.0

# I alert:
🚨 CRITICAL: Multiple vulnerabilities in Django 2.2.0
📍 Package: Django@2.2.0
📦 Vulnerable versions: < 2.2.28
🔧 Fix: Update requirements.txt to Django==2.2.28
📖 CVEs: CVE-2021-33203, CVE-2021-33571

Affected: SQL injection, XSS vulnerabilities
Recommendation: Update immediately to Django@2.2.28+
Multiple Vulnerabilities
bash
# After npm install:
🚨 Dependency audit found 8 vulnerabilities:
  - 3 CRITICAL
  - 2 HIGH
  - 2 MEDIUM
  - 1 LOW

Critical issues:
  1. axios@0.21.0 - SSRF vulnerability
     Fix: npm install axios@latest

  2. ajv@6.10.0 - Prototype pollution
     Fix: npm install ajv@^8.0.0

  3. node-fetch@2.6.0 - Information disclosure
     Fix: npm install node-fetch@^2.6.7

Run 'npm audit fix' to automatically fix 6/8 issues

Automatic Actions

On Dependency Changes
yaml
1. Detect package manager (npm, pip, etc.)
2. Run security audit command
3. Parse vulnerability results
4. Categorize by severity
5. Suggest fixes
6. Flag breaking changes
Audit Commands
bash
# Node.js
npm audit
npm audit --json  # Structured output

# Python
pip-audit
safety check

# Ruby
bundle audit

# Java (Maven)
mvn dependency-check:check

Severity Classification

CRITICAL 🚨
  • Remote code execution
  • SQL injection
  • Authentication bypass
  • Publicly exploitable
HIGH ⚠️
  • Cross-site scripting
  • Denial of service
  • Information disclosure
  • Wide attack surface
MEDIUM 📋
  • Limited impact vulnerabilities
  • Requires specific conditions
  • Difficult to exploit
LOW 💡
  • Minor security improvements
  • Best practice violations
  • Minimal risk

Fix Strategies

Automatic Updates
bash
# Safe automatic fixes
npm audit fix

# May include breaking changes
npm audit fix --force
Manual Updates
bash
# Check what will change
npm outdated

# Update specific package
npm update lodash

# Major version update
npm install lodash@latest
Alternative Packages
Vulnerable: request@2.88.0 (deprecated)
Alternative: axios or node-fetch
Migration guide: [link]

Integration with CI/CD

Block Deployments
yaml
# .github/workflows/security.yml
- name: Dependency audit
  run: |
    npm audit --audit-level=high
    # Fails if HIGH or CRITICAL found
Scheduled Audits
yaml
# Weekly dependency check
on:
  schedule:
    - cron: '0 0 * * 0'
jobs:
  audit:
    runs-on: ubuntu-latest
    steps:
      - uses: actions/checkout@v2
      - run: npm audit

Sandboxing Compatibility

Works without sandboxing: ✅ Yes Works with sandboxing: ⚙️ Needs npm/pip registry access

Sandbox config:

json
{
  "network": {
    "allowedDomains": [
      "registry.npmjs.org",
      "pypi.org",
      "rubygems.org",
      "repo.maven.apache.org"
    ]
  }
}

License Checking

I also check license compatibility:

⚠️ License issue: GPL-3.0 package in commercial project
📦 Package: some-gpl-package@1.0.0
📖 GPL-3.0 requires source code disclosure
🔧 Consider: Find MIT/Apache-2.0 alternative

Best Practices

  1. Regular audits: Run weekly or on every dependency change
  2. Update frequently: Keep dependencies current
  3. Review breaking changes: Test before major updates
  4. Pin versions: Use exact versions in production
  5. Audit lock files: Commit and audit lock files
  • security-auditor skill: Code vulnerability detection
  • @architect sub-agent: Dependency strategy
  • /review command: Pre-deployment security check

© alirezarezvani, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file in skills/security/dependency-auditor of alirezarezvani/claude-code-tresor.

  • SKILL.md
  • README.md

Open the folder on GitHubat commit 4b68050

Compare with similar skills

Dependency Auditor next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Dependency Auditor compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Dependency Auditor this skillalirezarezvani/claude-code-tresor777—~1.2kAutomated safety check: NotesMIT
Dependency Auditbriiirussell/cybersecurity-skills412—~3.2kAutomated safety check: WarnMIT
Dependency Checkruvnet/ruflo74k—~258Automated safety check: PassMIT
npm Supply Chain Checkmajiayu000/spellbook286—~1.5kAutomated safety check: PassMIT
Dep Securitytinyfish-io/tinyfish-cookbook2.2k—~2.4kAutomated safety check: PassMIT
Cve Scansoftspark/ai-toolkit179—~1.3kAutomated safety check: NotesApache-2.0

Similar skills

  • Dependency Audit

    briiirussell/cybersecurity-skills

    Audit project dependencies, frameworks, languages, and dev tools for known vulnerabilities, CVEs, and security anti-patterns.

    412 GitHub stars~3.2k tokensUpdated 4 mo ago
    SecurityAuto-check: warnings
  • Dependency Check

    ruvnet/ruflo

    Scan project dependencies for known vulnerabilities and CVEs.

    74k GitHub stars~258 tokensUpdated today
    SecurityAuto-check passed
  • npm Supply Chain Check

    majiayu000/spellbook

    Scans a repository, its lockfiles and node_modules for known malicious npm package versions and install-time indicators, using a read-only Python scanner.

    286 GitHub stars~1.5k tokensUpdated yesterday
    SecurityAuto-check passed
  • Dep Security

    tinyfish-io/tinyfish-cookbook

    Check every dependency in a package.json against live CVE databases and security advisories in real time — specifically targeting vulnerabilities disclosed in the last 48 hours, the window that…

    2.2k GitHub stars~2.4k tokensUpdated 6 days ago
    SecurityAuto-check passed
  • Cve Scan

    softspark/ai-toolkit

    Scans deps for known CVEs via native audit (npm, pip, composer, cargo, go, bundler, dart).

    179 GitHub stars~1.3k tokensUpdated yesterday
    SecurityAuto-check: notes
  • Dependency Triage

    cobusgreyling/loop-engineering

    Scan package manifests and lockfiles for outdated and vulnerable dependencies.

    11k GitHub stars~206 tokensUpdated yesterday
    SecurityAuto-check passed

More from alirezarezvani/claude-code-tresor

  • API Documenter

    alirezarezvani/claude-code-tresor

    Auto-generate API documentation from code and comments. An agent skill from alirezarezvani/claude-code-tresor.

    777 GitHub stars~1.5k tokensUpdated 3 mo ago
    Auto-check passed
  • Code Reviewer

    alirezarezvani/claude-code-tresor

    Automatic code quality and best practices analysis. An agent skill from alirezarezvani/claude-code-tresor.

    777 GitHub stars~1.8k tokensUpdated 3 mo ago
    Auto-check passed
  • Git Commit Helper

    alirezarezvani/claude-code-tresor

    Generate conventional commit messages automatically. An agent skill from alirezarezvani/claude-code-tresor.

    777 GitHub stars~1.9k tokensUpdated 3 mo ago
    Auto-check: notes
  • Readme Updater

    alirezarezvani/claude-code-tresor

    Keep README files current with project changes. An agent skill from alirezarezvani/claude-code-tresor.

    777 GitHub stars~1.5k tokensUpdated 3 mo ago
    Auto-check passed
  • Test Generator

    alirezarezvani/claude-code-tresor

    Automatically suggest tests for new functions and components.

    777 GitHub stars~1.6k tokensUpdated 3 mo ago
    Auto-check passed
  • Secret Scanner

    alirezarezvani/claude-code-tresor

    Detect exposed secrets, API keys, credentials, and tokens in code.

    777 GitHub stars~1.4k tokensUpdated 3 mo ago
    Auto-check: warnings

Works with

Questions about Dependency Auditor

What does Dependency Auditor do?

Check dependencies for known vulnerabilities using npm audit, pip-audit, etc. Dependency Auditor is an agent skill from alirezarezvani/claude-code-tresor. Check dependencies for known vulnerabilities using npm audit, pip-audit, etc.

When should I use Dependency Auditor?

Dependency Auditor fits situations like: requirements.txt changes; before deployments; dependency file changes; deployment prep.

How do I install Dependency Auditor in Claude Code?

Run `npx skills add alirezarezvani/claude-code-tresor --skill dependency-auditor -a claude-code`. Or copy the skill folder (skills/security/dependency-auditor in alirezarezvani/claude-code-tresor) into .claude/skills/dependency-auditor in your project. Claude Code loads it when a task matches its description.

How do I install Dependency Auditor in Codex?

Run `npx skills add alirezarezvani/claude-code-tresor --skill dependency-auditor -a codex`. Or copy the skill folder (skills/security/dependency-auditor in alirezarezvani/claude-code-tresor) into .agents/skills/dependency-auditor in your project. Codex loads it when a task matches its description.

Can I use Dependency Auditor in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add alirezarezvani/claude-code-tresor --skill dependency-auditor -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/dependency-auditor, .gemini/skills/dependency-auditor, .github/skills/dependency-auditor and .opencode/skills/dependency-auditor in your project.

What does Dependency Auditor need to run?

Going by SKILL.md and its folder, Dependency Auditor needs the command-line tools its instructions call (npm, bundle and mvn). Our summary lists: Python 3; Node.js. Its frontmatter pre-approves these tools: Bash, Read.

Does Dependency Auditor access the network?

SKILL.md names 1 domain. In commands or code: nvd.nist.gov; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.

Is Dependency Auditor safe to install?

Our automated static check of SKILL.md found notes only (pre-approves every shell command (allowed-tools: bash)), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Dependency Auditor use?

Dependency Auditor is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Dependency Auditor use?

About 1.2k tokens (SKILL.md is roughly 5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Dependency Auditor?

Skills that share tags, products or a category with Dependency Auditor: Dependency Audit (briiirussell/cybersecurity-skills, 412 stars), Dependency Check (ruvnet/ruflo, 74k stars), npm Supply Chain Check (majiayu000/spellbook, 286 stars) and Dep Security (tinyfish-io/tinyfish-cookbook, 2.2k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Dependency Auditor?

alirezarezvani (a GitHub user) maintains it in alirezarezvani/claude-code-tresor, which has 777 GitHub stars. The repository holds 7 skills in this directory. The repository was last updated on July 3, 2026.

Source: alirezarezvani/claude-code-tresor on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.