Agent skill

Dependency Auditor

by borghei in borghei/Claude-Skills

Scan project dependencies for vulnerabilities, license issues, and upgrade opportunities across Python, Node.js, Go, and Rust.

MITAuto-check passedSecurity

Install Dependency Auditor

skills CLI
$ npx skills add borghei/Claude-Skills --skill dependency-auditor -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install borghei/Claude-Skills dependency-auditor --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/borghei/Claude-Skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/engineering/dependency-auditor .claude/skills/dependency-auditor && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
dependency-auditor
GitHub stars
874
Token cost
~1.8k tokens
SKILL.md length
714 words
Files
19 (incl. scripts, references, assets)
Skills in repo
364
Repo updated
First seen
Licence
MIT

At a glance

Scan project dependencies for vulnerabilities, license issues, and upgrade opportunities across Python, Node.js, Go, and Rust.

  • Auditing dependencies
  • SKILL.md covers Core Capabilities, When to Use, Clarify First and Tools, plus 3 more sections
  • Runs Python scripts from its folder; calls python
  • Checking licenses

What it does

Dependency Auditor is an agent skill from borghei/Claude-Skills. Scan project dependencies for vulnerabilities, license issues, and upgrade opportunities across Python, Node.js, Go, and Rust. Use when auditing dependencies, checking licenses, planning upgrades, or assessing supply chain security.

Its SKILL.md is about 1.8k tokens, which your agent loads only when the skill is triggered. The skill folder holds 22 other files, including scripts, reference files and assets (for example `README.md`, `assets/sample_package.json` and `expected_outputs/sample_vulnerability_report.json`).

It sits in Security, covering Supply chain security. It works with Python, Rust and Node.js. The repository describes itself as: 385 AI skills, 77 expert agents, and 900 stdlib Python tools for every team: engineering, PM, marketing, C-level, compliance, business ops, research, and a LinkedIn toolkit… The licence is MIT.

When your agent uses it

  • Auditing dependencies
  • Checking licenses
  • Planning upgrades
  • Assessing supply chain security

Example prompts

  • “/dependency-auditor”

Requirements

  • Python 3
  • Node.js

What it can do on your machine

Read from SKILL.md and the folder at commit c9a1487. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 3 files in scripts/ (Python, from the files we listed), which the agent can run.

    Shell commands in SKILL.md call:

    • python

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Dependency Auditor loads about 1.8k tokens when it runs, and up to ~17k if it reads all its reference files. Until then it costs about 63 tokens; SKILL.md has 714 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~63
When it runs · the whole SKILL.md, loaded when a task matches
~1.8k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~17k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from borghei/Claude-Skills at commit c9a1487, republished under its MIT licence (© borghei). 714 words, ~1,803 tokens.

Download SKILL.mdSave it as .claude/skills/dependency-auditor/SKILL.md (or your agent's skills folder). This skill also uses 18 other files; get the full folder from GitHub.
name
dependency-auditor
description
Scan project dependencies for vulnerabilities, license issues, and upgrade opportunities across Python, Node.js, Go, and Rust. Use when auditing dependencies, checking licenses, planning upgrades, or assessing supply chain security.
license
MIT + Commons Clause
metadata.version
1.1.0
metadata.author
borghei
metadata.category
engineering
metadata.domain
security
metadata.tier
POWERFUL
metadata.updated
2026-06-17

Dependency Auditor

A multi-language toolkit for analyzing, auditing, and managing dependencies. It scans manifests and lockfiles across 8+ ecosystems to surface vulnerabilities, classify licenses, detect bloat, and produce safe, phased upgrade plans — giving teams visibility into security, legal, and maintenance risk hidden in their dependency trees.

Core Capabilities

  • Vulnerability scanning & CVE matching — match direct/transitive deps against a built-in CVE database with CVSS scoring across Node, Python, Go, Rust, Ruby, Java, PHP, .NET.
  • License compliance — classify into permissive / weak-copyleft / strong-copyleft / proprietary / unknown tiers and detect incompatible combinations (e.g. GPL contamination).
  • Outdated & maintenance detection — categorize updates by patch/minor/major severity; flag abandoned or end-of-life packages.
  • Dependency bloat analysis — find unused, redundant, or oversized packages and consolidation opportunities.
  • Upgrade path planning — semver breaking-change prediction, risk matrix, prioritization, rollback strategies.
  • Supply chain security — provenance checks, typosquatting/malicious-package detection, transitive risk scoring.
  • Lockfile analysis — validate freshness, integrity hashes, and cross-environment consistency for deterministic builds.

When to Use

  • Auditing a project's dependencies for vulnerabilities or supply-chain risk.
  • Checking license compliance before distribution or M&A due diligence.
  • Planning safe, phased dependency upgrades.
  • Adding a dependency security gate to CI/CD.
  • Cleaning up unused or redundant dependencies.

Clarify First

Before running the audit, confirm these inputs. If any is unknown or vague, ASK — do not assume:

  • Project & ecosystem — the project path and which manifests/lockfiles (the input the scanner parses)
  • Audit focus — vulnerabilities, license compliance, or upgrade planning (selects dep_scanner.py vs license_checker.py vs upgrade_planner.py)
  • Policy & gate — license policy strictness and fail-on-severity threshold (sets --policy, --fail-on-high, and the CI verdict)

Stop rule: ask only the 2-3 that most change the output. If the user says "just draft it," proceed and list your assumptions at the top of the artifact.

Tools

ToolPurposeCommand
dep_scanner.pyScan manifests/lockfiles across 8+ ecosystems, match CVEs, produce a security reportpython scripts/dep_scanner.py /path/to/project --format json --fail-on-high
license_checker.pyClassify dependency licenses by risk tier and detect conflicts vs the project licensepython scripts/license_checker.py /path/to/project --policy strict --warn-conflicts
upgrade_planner.pyEvaluate semver gaps, assess breaking-change risk, output a phased upgrade planpython scripts/upgrade_planner.py deps.json --risk-threshold medium --timeline 30

References

Load the reference that matches the task — keep this file lean and pull detail on demand:

  • references/capabilities-and-best-practices.md — full breakdown of every analysis capability, the scanner/analyzer/planner internals, use cases by team, advanced/enterprise features, recommended scan cadences, and metrics/KPIs. Read when you need the deep capability or architecture detail.
  • references/tools-integration-and-troubleshooting.md — quick-start and CI/CD/scheduled-audit integration commands, complete per-tool flag/output reference, the troubleshooting table, and success-criteria targets. Read when running the tools, wiring them into pipelines, or diagnosing failures.
  • references/vulnerability_assessment_guide.md — how to assess, prioritize, and remediate dependency vulnerabilities (CVSS, exploitability, disclosure timelines). Read when triaging or responding to security findings.
  • references/license_compatibility_matrix.md — comprehensive license-type reference and compatibility matrix for combining open-source dependencies. Read when resolving license conflicts or making distribution decisions.
  • references/dependency_management_best_practices.md — strategic, governance, security, and operational best practices across the dependency lifecycle. Read when establishing dependency policy or team workflows.
Show full SKILL.md (240 more words)Show less

Scope & Limitations

This skill covers:

  • Parsing dependency manifests and lockfiles for JavaScript/Node.js, Python, Go, Rust, Ruby, Java, PHP, and C#/.NET ecosystems.
  • Matching dependencies against a built-in vulnerability database of common CVE patterns with severity scoring.
  • Classifying licenses into risk tiers (permissive, weak copyleft, strong copyleft, proprietary, unknown) and detecting conflicts.
  • Generating prioritized, phased upgrade plans with breaking-change analysis, rollback procedures, and time estimates.

This skill does NOT cover:

  • Real-time querying of live vulnerability databases (NVD, OSV, GitHub Advisory); the built-in DB is a representative subset. For continuous monitoring, see skill-security-auditor.
  • Container image or OS-level package scanning. For infrastructure auditing, see ci-cd-pipeline-builder or observability-designer.
  • Automated PR creation for dependency updates (Dependabot/Renovate-style); the skill produces plans and reports, not code changes.
  • Runtime dependency analysis or dynamic import tracing; detection is static manifest/lockfile parsing only.

Integration Points

SkillIntegrationData Flow
skill-security-auditorFeed vulnerability scan results into broader security audit workflowsdep_scanner.py --format json output consumed as evidence artifacts
ci-cd-pipeline-builderEmbed dependency gates in CI/CD pipelinesdep_scanner.py --fail-on-high and license_checker.py --policy strict as pipeline steps
release-managerAttach dependency audit reports to release checklistsJSON reports from all three tools included in release documentation
pr-review-expertFlag dependency changes during pull request reviewScanner diff between base and head branch dependency files
env-secrets-managerEnsure dependency tooling credentials (registry tokens) are securely managedRegistry authentication tokens stored and rotated via secrets manager
observability-designerMonitor dependency health metrics over timeScan summary statistics exported to monitoring dashboards

© borghei, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 18 other files (scripts, references, assets) in engineering/dependency-auditor of borghei/Claude-Skills.

  • SKILL.md
  • README.md
  • assets/sample_go.mod
  • assets/sample_package.json
  • assets/sample_requirements.txt
  • expected_outputs/sample_license_report.txt
  • expected_outputs/sample_upgrade_plan.txt
  • expected_outputs/sample_vulnerability_report.json
  • references/capabilities-and-best-practices.md
  • references/dependency_management_best_practices.md
  • references/license_compatibility_matrix.md
  • references/tools-integration-and-troubleshooting.md
  • references/vulnerability_assessment_guide.md
  • scripts/dep_scanner.py
  • scripts/license_checker.py
  • scripts/upgrade_planner.py
  • test-inventory.json
  • … and 2 more

Open the folder on GitHubat commit c9a1487

Compare with similar skills

Dependency Auditor next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Dependency Auditor compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Dependency Auditor this skillborghei/Claude-Skills874—~1.8kAutomated safety check: PassMIT
Dependency Scanjwynia/agent-skills165—~1.7kAutomated safety check: PassMIT
Release Skillsnexmoe/eve4213 repos~3.3kAutomated safety check: PassNone
CI Pipeline Synthesizerkajisho5/ffmpeg-skill1.9k1 repos~1.1kAutomated safety check: PassMIT
Dbgtheodo-group/debug-that158—~1.9kAutomated safety check: PassMIT
Dep Auditorlaolaoshiren/claude-code-skills-zh877—~895Automated safety check: PassMIT

Similar skills

  • Dependency Scan

    jwynia/agent-skills

    Detect CVEs and security issues in project dependencies. An agent skill from jwynia/agent-skills.

    165 GitHub stars~1.7k tokensUpdated 7 mo ago
    SecurityAuto-check passed
  • Release Skills

    nexmoe/eve

    Universal release workflow. An agent skill from nexmoe/eve.

    421 GitHub starsUsed in 3 repos~3.3k tokens
    DevelopmentAuto-check passed
  • CI Pipeline Synthesizer

    kajisho5/ffmpeg-skill

    Generate GitHub Actions CI/CD pipeline configurations for automated building and testing of library and package projects.

    1.9k GitHub starsUsed in 1 repo~1.1k tokens
    DevOps & CloudAuto-check passed
  • Dbg

    theodo-group/debug-that

    Debug applications using the dbg CLI debugger. An agent skill from theodo-group/debug-that.

    158 GitHub stars~1.9k tokensUpdated 4 mo ago
    DevelopmentAuto-check passed
  • Dep Auditor

    laolaoshiren/claude-code-skills-zh

    审计 Node.js、Python、Go、Rust、JVM、Ruby 项目的依赖漏洞、版本健康度与许可证事实;当用户要求检查 package.json、lockfile、requirements、go.mod、Cargo.toml、pom.xml、Gemfile.lock,或生成不改依赖的中文审计报告时使用

    877 GitHub stars~895 tokensUpdated 2 days ago
    DevelopmentAuto-check passed
  • Nxv

    utensils/nxv

    Find any version of any Nix package across nixpkgs git history using the nxv CLI or HTTP API.

    136 GitHub stars~7.9k tokensUpdated 1 mo ago
    Backend & APIsAuto-check: notes

More from borghei/Claude-Skills

All 364 skills in this repo
  • Agents In The Team

    borghei/Claude-Skills

    Run delivery when AI coding and ops agents take tickets. An agent skill from borghei/Claude-Skills.

    874 GitHub stars~4.2k tokensUpdated yesterday
    Auto-check passed
  • AI Content Disclosure

    borghei/Claude-Skills

    Check AI-generated marketing content and reviews for required disclosures under the EU AI Act, FTC rules and platform AI-label policies.

    874 GitHub stars~3.4k tokensUpdated yesterday
    Auto-check passed
  • AI Prototyping

    borghei/Claude-Skills

    Idea to AI-generated prototype to customer validation to engineering handoff.

    874 GitHub stars~3.6k tokensUpdated yesterday
    Auto-check passed
  • Analytics Engineer

    borghei/Claude-Skills

    Analytics engineering across data modeling, dbt, transformation, and semantic layers.

    874 GitHub stars~3.4k tokensUpdated yesterday
    Auto-check passed
  • Ansoff Matrix

    borghei/Claude-Skills

    Ansoff Matrix — 4-quadrant framework for growth options: market penetration, market/product development, and diversification.

    874 GitHub stars~2.2k tokensUpdated yesterday
    Auto-check passed
  • Brainstorm Okrs

    borghei/Claude-Skills

    OKR brainstorming and validation using the Radical Focus framework — outcome objectives, measurable key results, counter-metrics.

    874 GitHub stars~1.4k tokensUpdated yesterday
    Auto-check passed

Categories

Questions about Dependency Auditor

What does Dependency Auditor do?

Scan project dependencies for vulnerabilities, license issues, and upgrade opportunities across Python, Node.js, Go, and Rust. Dependency Auditor is an agent skill from borghei/Claude-Skills.js, Go, and Rust.

When should I use Dependency Auditor?

Dependency Auditor fits situations like: auditing dependencies; checking licenses; planning upgrades; assessing supply chain security.

How do I install Dependency Auditor in Claude Code?

Run `npx skills add borghei/Claude-Skills --skill dependency-auditor -a claude-code`. Or copy the skill folder (engineering/dependency-auditor in borghei/Claude-Skills) into .claude/skills/dependency-auditor in your project. Claude Code loads it when a task matches its description.

How do I install Dependency Auditor in Codex?

Run `npx skills add borghei/Claude-Skills --skill dependency-auditor -a codex`. Or copy the skill folder (engineering/dependency-auditor in borghei/Claude-Skills) into .agents/skills/dependency-auditor in your project. Codex loads it when a task matches its description.

Can I use Dependency Auditor in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add borghei/Claude-Skills --skill dependency-auditor -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/dependency-auditor, .gemini/skills/dependency-auditor, .github/skills/dependency-auditor and .opencode/skills/dependency-auditor in your project.

What does Dependency Auditor need to run?

Going by SKILL.md and its folder, Dependency Auditor needs Python for the scripts in its folder and the command-line tools its instructions call (python). Our summary lists: Python 3; Node.js.

Does Dependency Auditor access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Dependency Auditor safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Dependency Auditor use?

Dependency Auditor is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Dependency Auditor use?

About 1.8k tokens (SKILL.md is roughly 7.2k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 15k tokens, read only when the agent opens those files.

What are the alternatives to Dependency Auditor?

Skills that share tags, products or a category with Dependency Auditor: Dependency Scan (jwynia/agent-skills, 165 stars), Release Skills (nexmoe/eve, 421 stars), CI Pipeline Synthesizer (kajisho5/ffmpeg-skill, 1.9k stars) and Dbg (theodo-group/debug-that, 158 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Dependency Auditor?

borghei (a GitHub user) maintains it in borghei/Claude-Skills, which has 874 GitHub stars. The repository holds 364 skills in this directory. The repository was last updated on October 7, 2026.

Source: borghei/Claude-Skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.