Agent skill

Dependency Audit

by briiirussell in briiirussell/cybersecurity-skills

Audit project dependencies, frameworks, languages, and dev tools for known vulnerabilities, CVEs, and security anti-patterns.

MITAuto-check: warningsSecurity

Install Dependency Audit

The automated check flagged lines worth reading first. See the safety section below.

skills CLI
$ npx skills add briiirussell/cybersecurity-skills --skill dependency-audit -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install briiirussell/cybersecurity-skills dependency-audit --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/briiirussell/cybersecurity-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/dependency-audit .claude/skills/dependency-audit && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
dependency-audit
GitHub stars
413
Token cost
~3.2k tokens
SKILL.md length
1,181 words
Files
1
Skills in repo
25
Repo updated
First seen
Licence
MIT

At a glance

Audit project dependencies, frameworks, languages, and dev tools for known vulnerabilities, CVEs, and security anti-patterns.

  • Works in 5 steps: Inventory the Stack → Run Automated Audit Tools → Research Framework-Specific Known Issues → …
  • The user mentions dependency audit
  • SKILL.md covers Methodology, Output Format, Boundaries and References
  • Calls npm, pip and docker; reaches github.com

What it does

Dependency Audit is an agent skill from briiirussell/cybersecurity-skills. Audit project dependencies, frameworks, languages, and dev tools for known vulnerabilities, CVEs, and security anti-patterns. Use when the user mentions 'dependency audit,' 'npm audit,' 'CVE,' 'vulnerable packages,' 'supply chain security,' 'outdated dependencies,' 'known vulnerabilities,' 'security advisory,' 'package security,' 'framework vulnerability,' 'is this package safe,' or needs to check whether their stack has known security issues.

Its SKILL.md is about 3.2k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Security, covering Vulnerability scanning, Dependency management and Supply chain security. It works with npm. The repository describes itself as: Cybersecurity skills for AI coding agents (Claude Code, Cursor, Codex). The licence is MIT.

When your agent uses it

  • The user mentions dependency audit
  • Vulnerable packages
  • Supply chain security
  • Outdated dependencies

Example prompts

  • “dependency audit,”
  • “npm audit,”
  • “vulnerable packages,”
  • “/dependency-audit”

Requirements

  • Python 3
  • Node.js
  • Docker
  • Pre-approved tools (allowed-tools): Bash, Read, Write, Grep, Glob, WebSearch

Workflow steps

5 steps, taken from the step headings in SKILL.md.

  1. Inventory the Stack
  2. Run Automated Audit Tools
  3. Research Framework-Specific Known Issues
  4. Check for Supply Chain Risks
  5. Check Dev Tool and CI/CD Security

What it can do on your machine

Read from SKILL.md and the folder at commit c9ade03. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Bash
    • Read
    • Write
    • Grep
    • Glob
    • WebSearch

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • npm
    • pip
    • docker
    • trivy
    • yarn
    • bundle
    • cargo
    • composer
    • dotnet
    • git

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • github.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Dependency Audit loads about 3.2k tokens when it runs. Until then it costs about 116 tokens; SKILL.md has 1,181 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~116
When it runs · the whole SKILL.md, loaded when a task matches
~3.2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: warnings

The automated check found patterns that need a careful read before installing.

  • NoteMentions a .env fileSKILL.md:116
    - Exposed `.env` files in public directory or client bundle (`NEXT_PUBLIC_` prefix leaking secrets)
  • WarningMentions a credentials file (SSH keys, cloud or package-manager tokens)SKILL.md:181
    - Missing `.npmrc` or `pip.conf` scoping to private registry
  • NotePre-approves every shell command (allowed-tools: Bash)SKILL.md
    allowed-tools: Bash, Read, Write, Grep, Glob, WebSearch

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from briiirussell/cybersecurity-skills at commit c9ade03, republished under its MIT licence (© briiirussell). 1,181 words, ~3,207 tokens.

Download SKILL.mdSave it as .claude/skills/dependency-audit/SKILL.md (or your agent's skills folder).
name
dependency-audit
description
Audit project dependencies, frameworks, languages, and dev tools for known vulnerabilities, CVEs, and security anti-patterns. Use when the user mentions 'dependency audit,' 'npm audit,' 'CVE,' 'vulnerable packages,' 'supply chain security,' 'outdated dependencies,' 'known vulnerabilities,' 'security advisory,' 'package security,' 'framework vulnerability,' 'is this package safe,' or needs to check whether their stack has known security issues.
allowed-tools
Bash, Read, Write, Grep, Glob, WebSearch

Dependency Audit — Framework, Package, and Toolchain Security

Audit project dependencies, frameworks, language runtimes, and dev tools for known vulnerabilities (CVEs), security anti-patterns, and supply chain risks.

Methodology

Step 1: Inventory the Stack

Identify everything in use — not just direct dependencies but the full chain:

Package manifests — read and catalog:

Node/JS:    package.json, package-lock.json, yarn.lock, pnpm-lock.yaml
Python:     requirements.txt, Pipfile.lock, pyproject.toml, poetry.lock
Ruby:       Gemfile, Gemfile.lock
Go:         go.mod, go.sum
Rust:       Cargo.toml, Cargo.lock
Java:       pom.xml, build.gradle
PHP:        composer.json, composer.lock
.NET:       *.csproj, packages.config

Framework and runtime versions:

  • Check framework version (Next.js, Django, Rails, Spring, Laravel, Express, etc.)
  • Check language/runtime version (Node.js, Python, Ruby, Go, Java, PHP, .NET)
  • Check infrastructure tools (Docker base images, Terraform providers, Kubernetes versions)

Dev tools and CI/CD:

  • Check CI/CD pipeline configs (.github/workflows, .gitlab-ci.yml, Jenkinsfile)
  • Check pre-commit hooks, linters, formatters
  • Check container base images and their update status
  • Check IaC tool versions (Terraform, Pulumi, CDK)

Edge cases in package manifests:

  • optionalDependencies — installed but not audited by default
  • peerDependencies — version range may not match what's installed
  • overrides / yarn resolutions / pnpm overrides — check if used to silence advisories rather than fix them
  • Monorepos: read every packages/*/package.json and apps/*/package.json, not just the root
  • engines field — older-than-LTS Node makes other audits moot
Step 2: Run Automated Audit Tools

Run the appropriate audit command for the project:

bash
# Node.js
npm audit --json                # full structured output
npm audit --omit=dev --json     # production-only: filters dev/build-time vulns
# Compare the two — vulns only in dev/build tooling do not ship to users
# and should be triaged as lower priority. Don't bury this in the report.

# Python
pip audit          # If pip-audit installed
safety check       # If safety installed

# Ruby
bundle audit

# Go
govulncheck ./...

# Rust
cargo audit

# PHP
composer audit

# .NET
dotnet list package --vulnerable

# Docker
docker scout cves <image>
trivy image <image>

# General (if Trivy is available)
trivy fs .

Applying fixes — read before you --force:

bash
npm audit fix                   # safe: upgrades within stated ranges
npm audit fix --dry-run --force # ALWAYS dry-run first
npm audit fix --force           # only after reviewing the dry-run

npm audit fix --force can resolve an advisory by DOWNGRADING a package to an older version that doesn't trigger the audit signature. This is almost always wrong (e.g. downgrading next@16 to next@9 to "fix" a transitive postcss CVE). Inspect dry-run output for "Will install X@Y, which is a breaking change" — that's the tool trying to downgrade.

When npm audit fix cannot resolve an advisory (transitive dep pinned by an upstream package):

  1. Determine reachability — is the vulnerable code path actually invoked in your usage? npm ls <package> + reading the parent's source can rule it out as unreachable.
  2. Consider a package.json overrides pin to a patched version (test thoroughly — overrides can break the parent).
  3. Consider swapping the parent provider entirely.
  4. If none apply: document explicitly, track upstream, and note in the audit report rather than silently dropping the finding.
Step 3: Research Framework-Specific Known Issues

Beyond CVEs in packages, check for known vulnerability patterns specific to the framework in use. Search for recent advisories and common misconfiguration issues.

For every direct dependency, cross-reference the installed version against:

  • https://github.com/advisories?ecosystem=npm&query=<package>
  • https://github.com/<org>/<repo>/security/advisories

The framework-specific patterns below cover evergreen anti-patterns (mass assignment, debug-in-prod, etc.). Recent CVEs need a fresh check because hardcoded advisory lists rot fast and LLM training data is often 6+ months behind the latest.

Next.js / React:

  • Server Actions exposing internal endpoints (pre-14.1.1 middleware bypass CVE-2025-29927)
  • dangerouslySetInnerHTML without sanitization
  • SSRF through image optimization (next/image with unrestricted domains)
  • Exposed .env files in public directory or client bundle (NEXT_PUBLIC_ prefix leaking secrets)
  • Middleware auth bypass patterns — check middleware.ts matches all protected routes
  • Server Component / Client Component boundary leaking server-only data:
    • Any module reading process.env.SECRET or instantiating a DB client should start with import "server-only"; — fails the build if imported from a Client Component
    • Grep for: files in lib/ that touch process.env.[A-Z_]+ but do NOT import server-only
    • Inverse check: any file with "use client" importing from such a module is a leak
  • Outdated next.config.js security headers

Django:

  • DEBUG=True in production
  • ALLOWED_HOSTS misconfigured (wildcard *)
  • Missing CSRF middleware or @csrf_exempt on state-changing views
  • Raw SQL via extra(), raw(), or RawSQL without parameterization
  • Pickle deserialization in sessions (use JSON serializer)
  • Secret key committed to source control

Rails:

  • Mass assignment without strong parameters
  • SQL injection via where("column = '#{input}'")
  • Unpatched Action Pack, Action View, or Active Record CVEs
  • Insecure deserialization in cookies (verify secret_key_base rotation)
  • CSRF token bypass in API-only mode

Express / Node.js:

  • Prototype pollution through Object.assign, lodash.merge, deep-extend
  • ReDoS (Regular Expression Denial of Service) in validation patterns
  • Path traversal through req.params in file serving routes
  • Missing rate limiting on auth endpoints
  • eval() or Function() with user input
  • Event loop blocking with synchronous operations

Serverless / edge runtimes (Vercel, Lambda, Cloud Run, Workers):

  • In-memory state ≠ rate limit. A module-scoped Map or Set for rate limiting, sessions, or caches is per-instance. Cold starts reset state; load spreads across instances; attackers bypass trivially.
    • Grep for: const rateLimitMap = new Map, const cache = new Map in server-action / API-route files
    • Fix: shared store — Vercel KV, Upstash Ratelimit, Redis, DynamoDB
  • Unbounded in-memory collections leak memory under traffic. Cap size and evict (LRU or FIFO).
  • x-forwarded-for trust: only trustworthy when the edge overwrites it. Behind misconfigured proxy chains it's attacker-spoofable. A fallback to a single "unknown" bucket throttles all anonymous traffic together; random-fallback silently disables the limit.

Spring / Java:

  • Spring4Shell and related RCE vulnerabilities
  • Deserialization attacks (Java native serialization, Jackson polymorphic types)
  • SpEL injection in Spring Expression Language
  • Missing CSRF protection on state-changing endpoints
  • Actuator endpoints exposed without authentication

Laravel / PHP:

  • APP_DEBUG=true in production (leaks env vars in error pages)
  • SQL injection via raw DB queries without bindings
  • Mass assignment without $fillable / $guarded
  • File upload without type validation (PHP execution via uploaded .php)
  • Insecure deserialization in queued jobs

WordPress:

  • Outdated core, theme, or plugin versions (most common attack vector)
  • File editor enabled in wp-admin (allows code injection if admin is compromised)
  • XML-RPC enabled (brute force amplification, SSRF)
  • Default admin username, weak passwords
  • Unpatched plugin vulnerabilities (check WPScan database)
Show full SKILL.md (342 more words)Show less
Step 4: Check for Supply Chain Risks

Beyond known CVEs, look for supply chain attack indicators:

Dependency confusion / substitution:

  • Private package names that could be claimed on public registries
  • Missing .npmrc or pip.conf scoping to private registry
  • No lockfile integrity verification

Typosquatting:

  • Package names that are close misspellings of popular packages
  • Recently published packages with very few downloads
  • Packages that changed ownership recently

Malicious packages:

  • Postinstall scripts that make network requests or execute code (scripts.postinstall in package.json)
  • Packages with obfuscated code
  • Excessive permission requests relative to functionality

Maintenance risk:

  • Unmaintained packages (no commits in 2+ years, archived repos)
  • Single-maintainer packages for critical functionality
  • Packages with known but unpatched vulnerabilities (maintainer unresponsive)

Lockfile integrity:

  • Lockfile committed? git ls-files | grep -E 'package-lock\.json|yarn\.lock|pnpm-lock\.yaml|Gemfile\.lock|poetry\.lock|composer\.lock|Cargo\.lock|go\.sum'
  • CI installs from lockfile?
    • Check .github/workflows/*.yml, .gitlab-ci.yml, Jenkinsfile, vercel.json, netlify.toml, Dockerfile
    • npm install (bad) vs npm ci (good); yarn install (bad) vs yarn install --immutable (good); pip install -r (bad) vs pip install --require-hashes -r (good)
  • integrity hashes present in the lockfile? (modern npm/pnpm yes by default)
Step 5: Check Dev Tool and CI/CD Security

GitHub Actions:

  • pull_request_target trigger with checkout of PR code (code injection risk)
  • Secrets accessible in forked PR workflows
  • Unpinned action versions (uses: actions/checkout@main vs @v4.1.0 or SHA pin)
  • Script injection via ${{ github.event.issue.title }} in run: blocks

Docker:

  • Running as root in container (missing USER directive)
  • Base image with known CVEs (check with trivy or docker scout)
  • Secrets baked into image layers (visible via docker history)
  • latest tag instead of pinned version

Terraform / IaC:

  • Hardcoded secrets in .tf files
  • Unpinned provider versions
  • Missing state file encryption
  • Over-permissive IAM in provider configuration

Output Format

markdown
# Dependency & Stack Security Audit
## Project: [name]
## Stack: [language, framework, key tools]
## Date: [date]

### Stack Inventory
| Component | Version | Latest | Status |
|-----------|---------|--------|--------|

### Known Vulnerabilities (CVEs)
| Package | Installed | Vuln | Severity | Where reachable | CVE | Fix Version |
|---------|-----------|------|----------|-----------------|-----|-------------|

Where reachable values: `runtime` / `build-only` / `dev-only`. Confirm with `npm ls --omit=dev <package>` or inspect the deployment artifact (Vercel function bundle, Docker layer). Build- and dev-only vulnerabilities should not block a release on their own; runtime-reachable ones should.

### Framework-Specific Issues
#### [SEVERITY] [Title]
**Component:** [framework/tool name and version]
**Issue:** [description]
**Evidence:** [code or config snippet]
**Remediation:** [specific fix]

### Supply Chain Risks
| Risk | Package/Component | Details | Remediation |
|------|-------------------|---------|-------------|

### Dev Tool / CI Security
| Tool | Issue | Severity | Remediation |
|------|-------|----------|-------------|

### Prioritized Action Plan
1. [Critical — actively exploited CVEs, RCE vulnerabilities]
2. [High — known CVEs with public exploits, supply chain risks]
3. [Medium — framework misconfigurations, outdated dependencies]
4. [Low — maintenance risks, best practice improvements]

Boundaries

  • Only audit code and configurations the user provides
  • When identifying CVEs, verify they apply to the actual installed version
  • Provide specific fix versions or remediation steps for every finding
  • Note when a vulnerability requires specific conditions to exploit (reducing effective severity)
  • Refuse to help exploit found vulnerabilities against unauthorized targets

References

  • OWASP Dependency-Check
  • National Vulnerability Database (NVD)
  • GitHub Advisory Database
  • Snyk Vulnerability Database
  • npm audit / pip-audit / bundler-audit documentation
  • SLSA (Supply-chain Levels for Software Artifacts) framework

© briiirussell, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/dependency-audit of briiirussell/cybersecurity-skills.

Open the folder on GitHubat commit c9ade03

Compare with similar skills

Dependency Audit next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Dependency Audit compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Dependency Audit this skillbriiirussell/cybersecurity-skills413—~3.2kAutomated safety check: WarnMIT
npm Supply Chain Checkmajiayu000/spellbook287—~1.5kAutomated safety check: PassMIT
Dependency Update Auditbacknotprop/plannotator9.3k—~1.8kAutomated safety check: PassApache-2.0
Warp Vulnerability Triagewarpdotdev/warp65k1 repos~2.1kAutomated safety check: PassAGPL-3.0
Supply Chain Risk Auditortrailofbits/skills7.5k—~1.7kAutomated safety check: NotesCC-BY-SA-4.0
Dependency Triagecobusgreyling/loop-engineering11k—~300Automated safety check: PassMIT

Similar skills

  • npm Supply Chain Check

    majiayu000/spellbook

    Scans a repository, its lockfiles and node_modules for known malicious npm package versions and install-time indicators, using a read-only Python scanner.

    287 GitHub stars~1.5k tokensUpdated 2 days ago
    SecurityAuto-check passed
  • Dependency Update Audit

    backnotprop/plannotator

    Audits outdated npm and Bun packages for supply chain integrity before bumping them, deferring risky ones and logging every decision.

    9.3k GitHub stars~1.8k tokensUpdated today
    SecurityAuto-check passed
  • Gathers security findings from Dependabot, GCP container scanning, Docker Scout and Linear security issues, then triages and remediates them across Warp's repos and images.

    65k GitHub starsUsed in 1 repo~2.1k tokens
    SecurityAuto-check passed
  • Supply Chain Risk Auditor

    trailofbits/skills

    Official

    Audits a project's dependencies for supply-chain risk: version-matched advisories for direct dependencies and the full lockfile tree, abandoned or archived upstreams, npm publisher concentration…

    7.5k GitHub stars~1.7k tokensUpdated today
    SecurityAuto-check: notes
  • Dependency Triage

    cobusgreyling/loop-engineering

    Scans package manifests and lockfiles for outdated packages and known CVEs, then classifies each possible update as patch, minor, major or escalate-human for a dependency sweeper loop.

    11k GitHub stars~300 tokensUpdated today
    SecurityAuto-check passed
  • Dependency Check

    ruvnet/ruflo

    Scan project dependencies for known vulnerabilities and CVEs.

    74k GitHub stars~258 tokensUpdated today
    SecurityAuto-check passed

More from briiirussell/cybersecurity-skills

All 25 skills in this repo
  • AI Risk Management

    briiirussell/cybersecurity-skills

    Apply the NIST AI Risk Management Framework (AI RMF 1.0) and adjacent guidance to AI / ML systems — model lifecycle governance, fairness and bias evaluation, robustness, transparency…

    413 GitHub stars~3.7k tokensUpdated 4 mo ago
    Auto-check: notes
  • API Audit

    briiirussell/cybersecurity-skills

    Audit REST, GraphQL, and RPC APIs against the OWASP API Security Top 10 (2023).

    413 GitHub stars~2.8k tokensUpdated 4 mo ago
    Auto-check: notes
  • Breach Patterns

    briiirussell/cybersecurity-skills

    Learn from public breach disclosures — extract the audit question each one implies and check your own stack.

    413 GitHub stars~3.5k tokensUpdated 4 mo ago
    Auto-check: notes
  • Cloud Audit

    briiirussell/cybersecurity-skills

    Audit cloud infrastructure (AWS, GCP, Azure) for misconfigurations, excessive permissions, and security gaps.

    413 GitHub stars~1.3k tokensUpdated 4 mo ago
    Auto-check: notes
  • Container Audit

    briiirussell/cybersecurity-skills

    Audit container images, Dockerfiles, and Kubernetes manifests for misconfigurations, excessive privileges, exposed secrets, and runtime risks.

    413 GitHub stars~2.5k tokensUpdated 4 mo ago
    Auto-check: notes
  • Crypto Audit

    briiirussell/cybersecurity-skills

    Audit cryptography implementation — algorithm choice, key sizes, KDF parameters, IV/nonce handling, signature verification, randomness, TLS configuration, and key rotation.

    413 GitHub stars~2.8k tokensUpdated 4 mo ago
    Auto-check: notes

Works with

Categories

Questions about Dependency Audit

What does Dependency Audit do?

Audit project dependencies, frameworks, languages, and dev tools for known vulnerabilities, CVEs, and security anti-patterns. Dependency Audit is an agent skill from briiirussell/cybersecurity-skills. Audit project dependencies, frameworks, languages, and dev tools for known vulnerabilities, CVEs, and security anti-patterns.

When should I use Dependency Audit?

Dependency Audit fits situations like: the user mentions dependency audit; vulnerable packages; supply chain security; outdated dependencies.

How do I install Dependency Audit in Claude Code?

Run `npx skills add briiirussell/cybersecurity-skills --skill dependency-audit -a claude-code`. Or copy the skill folder (skills/dependency-audit in briiirussell/cybersecurity-skills) into .claude/skills/dependency-audit in your project. Claude Code loads it when a task matches its description.

How do I install Dependency Audit in Codex?

Run `npx skills add briiirussell/cybersecurity-skills --skill dependency-audit -a codex`. Or copy the skill folder (skills/dependency-audit in briiirussell/cybersecurity-skills) into .agents/skills/dependency-audit in your project. Codex loads it when a task matches its description.

Can I use Dependency Audit in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add briiirussell/cybersecurity-skills --skill dependency-audit -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/dependency-audit, .gemini/skills/dependency-audit, .github/skills/dependency-audit and .opencode/skills/dependency-audit in your project.

What does Dependency Audit need to run?

Going by SKILL.md and its folder, Dependency Audit needs the command-line tools its instructions call (npm, pip, docker, trivy, yarn and bundle). Our summary lists: Python 3; Node.js; Docker. Its frontmatter pre-approves these tools: Bash, Read, Write, Grep, Glob, WebSearch.

Does Dependency Audit access the network?

SKILL.md names 1 domain. In commands or code: github.com; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.

Is Dependency Audit safe to install?

Our automated static check of SKILL.md flagged 1 warning(s): mentions a credentials file (ssh keys, cloud or package-manager tokens). Read the flagged lines before installing; the check is not a guarantee either way.

What licence does Dependency Audit use?

Dependency Audit is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Dependency Audit use?

About 3.2k tokens (SKILL.md is roughly 13k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Dependency Audit?

Skills that share tags, products or a category with Dependency Audit: npm Supply Chain Check (majiayu000/spellbook, 287 stars), Dependency Update Audit (backnotprop/plannotator, 9.3k stars), Warp Vulnerability Triage (warpdotdev/warp, 65k stars) and Supply Chain Risk Auditor (trailofbits/skills, 7.5k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Dependency Audit?

briiirussell (a GitHub user) maintains it in briiirussell/cybersecurity-skills, which has 413 GitHub stars. The repository holds 25 skills in this directory. The repository was last updated on May 27, 2026.

Source: briiirussell/cybersecurity-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.