Dependency Audit
briiirussell/cybersecurity-skills
Audit project dependencies, frameworks, languages, and dev tools for known vulnerabilities, CVEs, and security anti-patterns.
Check dependencies for known vulnerabilities using npm audit, pip-audit, etc.
$ npx skills add alirezarezvani/claude-code-tresor --skill dependency-auditor -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install alirezarezvani/claude-code-tresor dependency-auditor --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/alirezarezvani/claude-code-tresor.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/security/dependency-auditor .claude/skills/dependency-auditor && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "dependency-auditor" agent skill from https://github.com/alirezarezvani/claude-code-tresor/tree/main/skills/security/dependency-auditor into .claude/skills/dependency-auditor/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "dependency-auditor", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/alirezarezvani/claude-code-tresor/tree/main/skills/security/dependency-auditorType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add alirezarezvani/claude-code-tresor --skill dependency-auditor -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install alirezarezvani/claude-code-tresor dependency-auditor --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/alirezarezvani/claude-code-tresor.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/security/dependency-auditor .agents/skills/dependency-auditor && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "dependency-auditor" agent skill from https://github.com/alirezarezvani/claude-code-tresor/tree/main/skills/security/dependency-auditor into .agents/skills/dependency-auditor/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "dependency-auditor", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add alirezarezvani/claude-code-tresor --skill dependency-auditor -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install alirezarezvani/claude-code-tresor dependency-auditor --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/alirezarezvani/claude-code-tresor.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/security/dependency-auditor .cursor/skills/dependency-auditor && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "dependency-auditor" agent skill from https://github.com/alirezarezvani/claude-code-tresor/tree/main/skills/security/dependency-auditor into .cursor/skills/dependency-auditor/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "dependency-auditor", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/alirezarezvani/claude-code-tresor.git --path skills/security/dependency-auditor--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add alirezarezvani/claude-code-tresor --skill dependency-auditor -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install alirezarezvani/claude-code-tresor dependency-auditor --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/alirezarezvani/claude-code-tresor.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/security/dependency-auditor .gemini/skills/dependency-auditor && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "dependency-auditor" agent skill from https://github.com/alirezarezvani/claude-code-tresor/tree/main/skills/security/dependency-auditor into .gemini/skills/dependency-auditor/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "dependency-auditor", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install alirezarezvani/claude-code-tresor dependency-auditorInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add alirezarezvani/claude-code-tresor --skill dependency-auditor -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/alirezarezvani/claude-code-tresor.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/security/dependency-auditor .github/skills/dependency-auditor && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "dependency-auditor" agent skill from https://github.com/alirezarezvani/claude-code-tresor/tree/main/skills/security/dependency-auditor into .github/skills/dependency-auditor/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "dependency-auditor", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add alirezarezvani/claude-code-tresor --skill dependency-auditor -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install alirezarezvani/claude-code-tresor dependency-auditor --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/alirezarezvani/claude-code-tresor.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/security/dependency-auditor .opencode/skills/dependency-auditor && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "dependency-auditor" agent skill from https://github.com/alirezarezvani/claude-code-tresor/tree/main/skills/security/dependency-auditor into .opencode/skills/dependency-auditor/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "dependency-auditor", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
dependency-auditorCheck dependencies for known vulnerabilities using npm audit, pip-audit, etc.
Dependency Auditor is an agent skill from alirezarezvani/claude-code-tresor. Check dependencies for known vulnerabilities using npm audit, pip-audit, etc. Use when package.json or requirements.txt changes, or before deployments. Alerts on vulnerable dependencies. Triggers on dependency file changes, deployment prep, security mentions.
Its SKILL.md is about 1.2k tokens, which your agent loads only when the skill is triggered. The skill folder holds 1 other file (for example `README.md`).
It sits in DevOps & Cloud, covering Deployment, Vulnerability scanning and Dependency management. It works with npm. The repository describes itself as: A world-class collection of Claude Code utilities: autonomous skills, expert agents, slash commands, and prompts that supercharge your development workflow. The licence is MIT.
5 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit 4b68050. It shows what the files ask for, not the result of running them.
Pre-approves these tools, so the agent can use them without asking each time:
BashReadFrom allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
npmbundlemvnFrom the folder's file list and the shell code blocks in SKILL.md.
Hosts in commands or code, which the agent is likely to contact:
nvd.nist.govFrom URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Dependency Auditor loads about 1.2k tokens when it runs. Until then it costs about 70 tokens; SKILL.md has 224 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check noted patterns worth knowing about, such as sudo or a known installer.
allowed-tools: Bash, ReadAutomated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from alirezarezvani/claude-code-tresor at commit 4b68050, republished under its MIT licence (© alirezarezvani). 224 words, ~1,240 tokens.
.claude/skills/dependency-auditor/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.Automatic dependency vulnerability checking.
# You run: npm install lodash
# I automatically audit:
🚨 HIGH: Prototype Pollution in lodash
📍 Package: lodash@4.17.15
📦 Vulnerable versions: < 4.17.21
🔧 Fix: npm update lodash
📖 CVE-2020-8203
https://nvd.nist.gov/vuln/detail/CVE-2020-8203
Recommendation: Update to lodash@4.17.21 or higher# You modify requirements.txt: django==2.2.0
# I alert:
🚨 CRITICAL: Multiple vulnerabilities in Django 2.2.0
📍 Package: Django@2.2.0
📦 Vulnerable versions: < 2.2.28
🔧 Fix: Update requirements.txt to Django==2.2.28
📖 CVEs: CVE-2021-33203, CVE-2021-33571
Affected: SQL injection, XSS vulnerabilities
Recommendation: Update immediately to Django@2.2.28+# After npm install:
🚨 Dependency audit found 8 vulnerabilities:
- 3 CRITICAL
- 2 HIGH
- 2 MEDIUM
- 1 LOW
Critical issues:
1. axios@0.21.0 - SSRF vulnerability
Fix: npm install axios@latest
2. ajv@6.10.0 - Prototype pollution
Fix: npm install ajv@^8.0.0
3. node-fetch@2.6.0 - Information disclosure
Fix: npm install node-fetch@^2.6.7
Run 'npm audit fix' to automatically fix 6/8 issues1. Detect package manager (npm, pip, etc.)
2. Run security audit command
3. Parse vulnerability results
4. Categorize by severity
5. Suggest fixes
6. Flag breaking changes# Node.js
npm audit
npm audit --json # Structured output
# Python
pip-audit
safety check
# Ruby
bundle audit
# Java (Maven)
mvn dependency-check:check# Safe automatic fixes
npm audit fix
# May include breaking changes
npm audit fix --force# Check what will change
npm outdated
# Update specific package
npm update lodash
# Major version update
npm install lodash@latestVulnerable: request@2.88.0 (deprecated)
Alternative: axios or node-fetch
Migration guide: [link]# .github/workflows/security.yml
- name: Dependency audit
run: |
npm audit --audit-level=high
# Fails if HIGH or CRITICAL found# Weekly dependency check
on:
schedule:
- cron: '0 0 * * 0'
jobs:
audit:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v2
- run: npm auditWorks without sandboxing: ✅ Yes Works with sandboxing: ⚙️ Needs npm/pip registry access
Sandbox config:
{
"network": {
"allowedDomains": [
"registry.npmjs.org",
"pypi.org",
"rubygems.org",
"repo.maven.apache.org"
]
}
}I also check license compatibility:
⚠️ License issue: GPL-3.0 package in commercial project
📦 Package: some-gpl-package@1.0.0
📖 GPL-3.0 requires source code disclosure
🔧 Consider: Find MIT/Apache-2.0 alternative© alirezarezvani, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 1 other file in skills/security/dependency-auditor of alirezarezvani/claude-code-tresor.
Open the folder on GitHubat commit 4b68050
Dependency Auditor next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Dependency Auditor this skillalirezarezvani/claude-code-tresor | 777 | — | ~1.2k | Automated safety check: Notes | MIT | |
| Dependency Auditbriiirussell/cybersecurity-skills | 412 | — | ~3.2k | Automated safety check: Warn | MIT | |
| Dependency Checkruvnet/ruflo | 74k | — | ~258 | Automated safety check: Pass | MIT | |
| npm Supply Chain Checkmajiayu000/spellbook | 286 | — | ~1.5k | Automated safety check: Pass | MIT | |
| Dep Securitytinyfish-io/tinyfish-cookbook | 2.2k | — | ~2.4k | Automated safety check: Pass | MIT | |
| Cve Scansoftspark/ai-toolkit | 179 | — | ~1.3k | Automated safety check: Notes | Apache-2.0 |
briiirussell/cybersecurity-skills
Audit project dependencies, frameworks, languages, and dev tools for known vulnerabilities, CVEs, and security anti-patterns.
ruvnet/ruflo
Scan project dependencies for known vulnerabilities and CVEs.
majiayu000/spellbook
Scans a repository, its lockfiles and node_modules for known malicious npm package versions and install-time indicators, using a read-only Python scanner.
tinyfish-io/tinyfish-cookbook
Check every dependency in a package.json against live CVE databases and security advisories in real time — specifically targeting vulnerabilities disclosed in the last 48 hours, the window that…
softspark/ai-toolkit
Scans deps for known CVEs via native audit (npm, pip, composer, cargo, go, bundler, dart).
cobusgreyling/loop-engineering
Scan package manifests and lockfiles for outdated and vulnerable dependencies.
alirezarezvani/claude-code-tresor
Auto-generate API documentation from code and comments. An agent skill from alirezarezvani/claude-code-tresor.
alirezarezvani/claude-code-tresor
Automatic code quality and best practices analysis. An agent skill from alirezarezvani/claude-code-tresor.
alirezarezvani/claude-code-tresor
Generate conventional commit messages automatically. An agent skill from alirezarezvani/claude-code-tresor.
alirezarezvani/claude-code-tresor
Keep README files current with project changes. An agent skill from alirezarezvani/claude-code-tresor.
alirezarezvani/claude-code-tresor
Automatically suggest tests for new functions and components.
alirezarezvani/claude-code-tresor
Detect exposed secrets, API keys, credentials, and tokens in code.
Works with
Categories
Check dependencies for known vulnerabilities using npm audit, pip-audit, etc. Dependency Auditor is an agent skill from alirezarezvani/claude-code-tresor. Check dependencies for known vulnerabilities using npm audit, pip-audit, etc.
Dependency Auditor fits situations like: requirements.txt changes; before deployments; dependency file changes; deployment prep.
Run `npx skills add alirezarezvani/claude-code-tresor --skill dependency-auditor -a claude-code`. Or copy the skill folder (skills/security/dependency-auditor in alirezarezvani/claude-code-tresor) into .claude/skills/dependency-auditor in your project. Claude Code loads it when a task matches its description.
Run `npx skills add alirezarezvani/claude-code-tresor --skill dependency-auditor -a codex`. Or copy the skill folder (skills/security/dependency-auditor in alirezarezvani/claude-code-tresor) into .agents/skills/dependency-auditor in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add alirezarezvani/claude-code-tresor --skill dependency-auditor -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/dependency-auditor, .gemini/skills/dependency-auditor, .github/skills/dependency-auditor and .opencode/skills/dependency-auditor in your project.
Going by SKILL.md and its folder, Dependency Auditor needs the command-line tools its instructions call (npm, bundle and mvn). Our summary lists: Python 3; Node.js. Its frontmatter pre-approves these tools: Bash, Read.
SKILL.md names 1 domain. In commands or code: nvd.nist.gov; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found notes only (pre-approves every shell command (allowed-tools: bash)), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.
Dependency Auditor is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 1.2k tokens (SKILL.md is roughly 5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Dependency Auditor: Dependency Audit (briiirussell/cybersecurity-skills, 412 stars), Dependency Check (ruvnet/ruflo, 74k stars), npm Supply Chain Check (majiayu000/spellbook, 286 stars) and Dep Security (tinyfish-io/tinyfish-cookbook, 2.2k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
alirezarezvani (a GitHub user) maintains it in alirezarezvani/claude-code-tresor, which has 777 GitHub stars. The repository holds 7 skills in this directory. The repository was last updated on July 3, 2026.
Source: alirezarezvani/claude-code-tresor on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.