Check Deps Sync
Hyk260/PureChat
Check if package.json files are in sync with pnpm-lock.yaml.
Audit JS/TS projects against NPM Security Guidelines covering project setup, dependency hygiene, CI/CD pipeline, Dependabot, and incident response.
The automated check flagged lines worth reading first. See the safety section below.
$ npx skills add c0x12c/ai-toolkit --skill js-security-audit -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install c0x12c/ai-toolkit js-security-audit --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/c0x12c/ai-toolkit.git skills-src && mkdir -p .claude/skills && cp -r skills-src/toolkit/skills/js-security-audit .claude/skills/js-security-audit && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "js-security-audit" agent skill from https://github.com/c0x12c/ai-toolkit/tree/master/toolkit/skills/js-security-audit into .claude/skills/js-security-audit/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "js-security-audit", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/c0x12c/ai-toolkit/tree/master/toolkit/skills/js-security-auditType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add c0x12c/ai-toolkit --skill js-security-audit -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install c0x12c/ai-toolkit js-security-audit --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/c0x12c/ai-toolkit.git skills-src && mkdir -p .agents/skills && cp -r skills-src/toolkit/skills/js-security-audit .agents/skills/js-security-audit && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "js-security-audit" agent skill from https://github.com/c0x12c/ai-toolkit/tree/master/toolkit/skills/js-security-audit into .agents/skills/js-security-audit/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "js-security-audit", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add c0x12c/ai-toolkit --skill js-security-audit -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install c0x12c/ai-toolkit js-security-audit --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/c0x12c/ai-toolkit.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/toolkit/skills/js-security-audit .cursor/skills/js-security-audit && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "js-security-audit" agent skill from https://github.com/c0x12c/ai-toolkit/tree/master/toolkit/skills/js-security-audit into .cursor/skills/js-security-audit/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "js-security-audit", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/c0x12c/ai-toolkit.git --path toolkit/skills/js-security-audit--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add c0x12c/ai-toolkit --skill js-security-audit -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install c0x12c/ai-toolkit js-security-audit --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/c0x12c/ai-toolkit.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/toolkit/skills/js-security-audit .gemini/skills/js-security-audit && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "js-security-audit" agent skill from https://github.com/c0x12c/ai-toolkit/tree/master/toolkit/skills/js-security-audit into .gemini/skills/js-security-audit/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "js-security-audit", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install c0x12c/ai-toolkit js-security-auditInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add c0x12c/ai-toolkit --skill js-security-audit -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/c0x12c/ai-toolkit.git skills-src && mkdir -p .github/skills && cp -r skills-src/toolkit/skills/js-security-audit .github/skills/js-security-audit && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "js-security-audit" agent skill from https://github.com/c0x12c/ai-toolkit/tree/master/toolkit/skills/js-security-audit into .github/skills/js-security-audit/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "js-security-audit", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add c0x12c/ai-toolkit --skill js-security-audit -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install c0x12c/ai-toolkit js-security-audit --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/c0x12c/ai-toolkit.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/toolkit/skills/js-security-audit .opencode/skills/js-security-audit && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "js-security-audit" agent skill from https://github.com/c0x12c/ai-toolkit/tree/master/toolkit/skills/js-security-audit into .opencode/skills/js-security-audit/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "js-security-audit", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
js-security-auditAudit JS/TS projects against NPM Security Guidelines covering project setup, dependency hygiene, CI/CD pipeline, Dependabot, and incident response.
JS Security Audit is an agent skill from c0x12c/ai-toolkit. Audit JS/TS projects against NPM Security Guidelines covering project setup, dependency hygiene, CI/CD pipeline, Dependabot, and incident response. Use when reviewing package.json or lockfiles, adding or upgrading npm dependencies, setting up CI security gates, hardening a new repo, or responding to a compromised package.
Its SKILL.md is about 1.6k tokens, which your agent loads only when the skill is triggered. The skill folder holds 4 other files (for example `audit-checklist.md`, `eslint-security.md` and `incident-playbook.md`).
It sits in Security, covering Dependency management, Security review and Incident response. It works with npm, pnpm and ESLint.
5 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 96b2c9d. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
npmFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use npm, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
JS Security Audit loads about 1.6k tokens when it runs. Until then it costs about 85 tokens; SKILL.md has 599 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found patterns that need a careful read before installing.
- New repo hardening — verify `.npmrc`, lockfiles, 2FA, exact pinningCheck `.npmrc`, lockfile presence, version pinning, `.gitignore`, scoped packages.- **Warning** — missing `.npmrc` hardening, no Dependabot config, no SBOM generation, ESLint security config missing- **[Project Setup]** `.npmrc` missing `ignore-scripts=true`- File: `.npmrc:1`Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
Without a licence we can't republish the file, so here is its outline and opening line. It has 599 words (~1,590 tokens).
“Run a 5-area security audit on a JS/TS project (npm, yarn, or pnpm). Produces a pass/fail report per area with file:line references.”
SKILL.md and 4 other files in toolkit/skills/js-security-audit of c0x12c/ai-toolkit.
Open the folder on GitHubat commit 96b2c9d
JS Security Audit next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| JS Security Audit this skillc0x12c/ai-toolkit | 106 | — | ~1.6k | Automated safety check: Warn | None | |
| Check Deps SyncHyk260/PureChat | 546 | — | ~594 | Automated safety check: Pass | MIT | |
| Uv WorkflowAedelon/claude-code-blueprint | 120 | — | ~1.2k | Automated safety check: Notes | Custom licence | |
| Linea Dependency MaintenanceConsensys-Incorporated/linea-attestation-registry | 177 | 1 repos | ~3.7k | Automated safety check: Warn | MIT | |
| Audit And Reduce Dependenciesgrafana/skills | 281 | — | ~3.6k | Automated safety check: Warn | Apache-2.0 | |
| npm Supply Chain Securitybodadotsh/npm-security-best-practices | 858 | — | ~1k | Automated safety check: Warn | MIT |
Hyk260/PureChat
Check if package.json files are in sync with pnpm-lock.yaml.
Aedelon/claude-code-blueprint
Master uv package manager for Python: project setup, dependency management, virtual environments, lockfiles, CI/CD integration, Docker builds, and migration from pip/poetry.
Consensys-Incorporated/linea-attestation-registry
Safely plan and execute dependency maintenance for JavaScript/TypeScript (npm, pnpm) and GitHub Actions, including npm lockfiles, pnpm workspaces, catalogs, overrides, SHA-pinned action versions…
grafana/skills
Reduces JavaScript dependency footprint with pnpm while preserving lockfile, workspace layout, and dependency range style.
bodadotsh/npm-security-best-practices
Applies safer package manager defaults and dependency vetting to JavaScript and TypeScript projects to reduce supply-chain attack risk.
linuxfoundation/insights
Automated triage and fixing of Dependabot security vulnerabilities (IN-1189).
c0x12c/ai-toolkit
UI/UX design intelligence with searchable style, palette, typography, and chart databases.
c0x12c/ai-toolkit
Creates RPC-style endpoint following layered architecture (Controller → Manager → Repository).
c0x12c/ai-toolkit
Design RPC-style APIs with layered architecture (Controller → Manager → Repository).
c0x12c/ai-toolkit
CI/CD pipeline patterns for GitHub Actions, PR automation, and deployment workflows.
c0x12c/ai-toolkit
Turn one idea into platform-native content for X, LinkedIn, TikTok, YouTube, newsletters.
c0x12c/ai-toolkit
Creates database table with full Kotlin synchronization (SQL migration → Table → Entity → Repository → Tests).
Categories
Audit JS/TS projects against NPM Security Guidelines covering project setup, dependency hygiene, CI/CD pipeline, Dependabot, and incident response. JS Security Audit is an agent skill from c0x12c/ai-toolkit. Audit JS/TS projects against NPM Security Guidelines covering project setup, dependency hygiene, CI/CD pipeline, Dependabot, and incident response.
JS Security Audit fits situations like: reviewing package.json; upgrading npm dependencies; setting up CI security gates; hardening a new repo.
Run `npx skills add c0x12c/ai-toolkit --skill js-security-audit -a claude-code`. Or copy the skill folder (toolkit/skills/js-security-audit in c0x12c/ai-toolkit) into .claude/skills/js-security-audit in your project. Claude Code loads it when a task matches its description.
Run `npx skills add c0x12c/ai-toolkit --skill js-security-audit -a codex`. Or copy the skill folder (toolkit/skills/js-security-audit in c0x12c/ai-toolkit) into .agents/skills/js-security-audit in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add c0x12c/ai-toolkit --skill js-security-audit -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/js-security-audit, .gemini/skills/js-security-audit, .github/skills/js-security-audit and .opencode/skills/js-security-audit in your project.
Going by SKILL.md and its folder, JS Security Audit needs the command-line tools its instructions call (npm). Our summary lists: Node.js.
SKILL.md contains no URLs. Its commands use npm, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md flagged 5 warning(s): mentions a credentials file (ssh keys, cloud or package-manager tokens). Read the flagged lines before installing; the check is not a guarantee either way.
No licence was found for JS Security Audit or its repository. Without one, default copyright applies: ask the author before reusing or redistributing it.
About 1.6k tokens (SKILL.md is roughly 6.4k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with JS Security Audit: Check Deps Sync (Hyk260/PureChat, 546 stars), Uv Workflow (Aedelon/claude-code-blueprint, 120 stars), Linea Dependency Maintenance (Consensys-Incorporated/linea-attestation-registry, 177 stars) and Audit And Reduce Dependencies (grafana/skills, 281 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
c0x12c (a GitHub organization) maintains it in c0x12c/ai-toolkit, which has 106 GitHub stars. The repository holds 33 skills in this directory. The repository was last updated on June 18, 2026.
Source: c0x12c/ai-toolkit on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.