Agent skill

Maven Dependency Audit

by decebals in decebals/claude-code-java

Audit Maven dependencies for outdated versions, security vulnerabilities, and conflicts.

MITAuto-check passedDevelopment

Install Maven Dependency Audit

skills CLI
$ npx skills add decebals/claude-code-java --skill maven-dependency-audit -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install decebals/claude-code-java maven-dependency-audit --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/decebals/claude-code-java.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/maven-dependency-audit .claude/skills/maven-dependency-audit && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
maven-dependency-audit
GitHub stars
751
Token cost
~1.7k tokens
SKILL.md length
339 words
Files
2
Skills in repo
18
Repo updated
First seen
Licence
MIT

At a glance

Audit Maven dependencies for outdated versions, security vulnerabilities, and conflicts.

  • Works in 4 steps: Check for Outdated Dependencies → Analyze Dependency Tree → Security Vulnerability Scan → …
  • User says check dependencies
  • SKILL.md covers When to Use, Audit Workflow, 1. Check for Outdated… and 2. Analyze Dependency Tree, plus 6 more sections
  • Calls mvn

What it does

Maven Dependency Audit is an agent skill from decebals/claude-code-java. Audit Maven dependencies for outdated versions, security vulnerabilities, and conflicts. Use when user says "check dependencies", "audit dependencies", "outdated deps", or before releases.

Its SKILL.md is about 1.7k tokens, which your agent loads only when the skill is triggered. The skill folder holds 1 other file (for example `README.md`).

It sits in Development, covering Dependency management. The repository describes itself as: Reusable AI development infrastructure for Java projects, optimized for Claude Code. The licence is MIT.

When your agent uses it

  • User says check dependencies
  • Audit dependencies
  • Before releases

Example prompts

  • “check dependencies”
  • “audit dependencies”
  • “outdated deps”
  • “/maven-dependency-audit”

Workflow steps

4 steps, taken from the step headings in SKILL.md.

  1. Check for Outdated Dependencies
  2. Analyze Dependency Tree
  3. Security Vulnerability Scan
  4. Generate Audit Report

What it can do on your machine

Read from SKILL.md and the folder at commit 0d98fe9. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • mvn

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Maven Dependency Audit loads about 1.7k tokens when it runs. Until then it costs about 53 tokens; SKILL.md has 339 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~53
When it runs · the whole SKILL.md, loaded when a task matches
~1.7k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from decebals/claude-code-java at commit 0d98fe9, republished under its MIT licence (© decebals). 339 words, ~1,663 tokens.

Download SKILL.mdSave it as .claude/skills/maven-dependency-audit/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
maven-dependency-audit
description
Audit Maven dependencies for outdated versions, security vulnerabilities, and conflicts. Use when user says "check dependencies", "audit dependencies", "outdated deps", or before releases.
license
MIT

Maven Dependency Audit Skill

Audit Maven dependencies for updates, vulnerabilities, and conflicts.

When to Use

  • User says "check dependencies" / "audit dependencies" / "outdated dependencies"
  • Before a release
  • Regular maintenance (monthly recommended)
  • After security advisory

Audit Workflow

  1. Check for updates - Find outdated dependencies
  2. Analyze tree - Find conflicts and duplicates
  3. Security scan - Check for vulnerabilities
  4. Report - Summary with prioritized actions

1. Check for Outdated Dependencies

Command
bash
mvn versions:display-dependency-updates
Output Analysis
[INFO] The following dependencies in Dependencies have newer versions:
[INFO]   org.slf4j:slf4j-api ......................... 1.7.36 -> 2.0.9
[INFO]   com.fasterxml.jackson.core:jackson-databind . 2.14.0 -> 2.16.1
[INFO]   org.junit.jupiter:junit-jupiter ............. 5.9.0 -> 5.10.1
Categorize Updates
CategoryCriteriaAction
SecurityCVE fix in newer versionUpdate ASAP
Majorx.0.0 changeReview changelog, test thoroughly
Minorx.y.0 changeUsually safe, test
Patchx.y.z changeSafe, minimal testing
Check Plugin Updates Too
bash
mvn versions:display-plugin-updates

2. Analyze Dependency Tree

Full Tree
bash
mvn dependency:tree
Filter for Specific Dependency
bash
mvn dependency:tree -Dincludes=org.slf4j
Find Conflicts

Look for:

[INFO] +- com.example:module-a:jar:1.0:compile
[INFO] |  \- org.slf4j:slf4j-api:jar:1.7.36:compile
[INFO] +- com.example:module-b:jar:1.0:compile
[INFO] |  \- org.slf4j:slf4j-api:jar:2.0.9:compile (omitted for conflict)

Flags:

  • (omitted for conflict) - Version conflict resolved by Maven
  • (omitted for duplicate) - Same version, no issue
  • Multiple versions of same library - Potential runtime issues
Analyze Unused Dependencies
bash
mvn dependency:analyze

Output:

[WARNING] Used undeclared dependencies found:
[WARNING]    org.slf4j:slf4j-api:jar:2.0.9:compile
[WARNING] Unused declared dependencies found:
[WARNING]    commons-io:commons-io:jar:2.11.0:compile

3. Security Vulnerability Scan

Add to pom.xml:

xml
<plugin>
    <groupId>org.owasp</groupId>
    <artifactId>dependency-check-maven</artifactId>
    <version>9.0.7</version>
</plugin>

Run:

bash
mvn dependency-check:check

Output: HTML report in target/dependency-check-report.html

Option B: Maven Dependency Plugin
bash
mvn dependency:analyze-report
Option C: GitHub Dependabot

If using GitHub, enable Dependabot alerts in repository settings.

Severity Levels
CVSS ScoreSeverityAction
9.0 - 10.0CriticalUpdate immediately
7.0 - 8.9HighUpdate within days
4.0 - 6.9MediumUpdate within weeks
0.1 - 3.9LowUpdate at convenience

4. Generate Audit Report

Output Format
markdown
## Dependency Audit Report

**Project:** {project-name}
**Date:** {date}
**Total Dependencies:** {count}

### Security Issues

| Dependency | Current | CVE | Severity | Fixed In |
|------------|---------|-----|----------|----------|
| log4j-core | 2.14.0 | CVE-2021-44228 | Critical | 2.17.1 |

### Outdated Dependencies

#### Major Updates (Review Required)
| Dependency | Current | Latest | Notes |
|------------|---------|--------|-------|
| slf4j-api | 1.7.36 | 2.0.9 | API changes, see migration guide |

#### Minor/Patch Updates (Safe)
| Dependency | Current | Latest |
|------------|---------|--------|
| junit-jupiter | 5.9.0 | 5.10.1 |
| jackson-databind | 2.14.0 | 2.16.1 |

### Conflicts Detected
- slf4j-api: 1.7.36 vs 2.0.9 (resolved to 2.0.9)

### Unused Dependencies
- commons-io:commons-io:2.11.0 (consider removing)

### Recommendations
1. **Immediate:** Update log4j-core to fix CVE-2021-44228
2. **This sprint:** Update minor/patch versions
3. **Plan:** Evaluate slf4j 2.x migration

Common Scenarios

Scenario: Check Before Release
bash
# Quick check
mvn versions:display-dependency-updates -q

# Full audit
mvn versions:display-dependency-updates && \
mvn dependency:analyze && \
mvn dependency-check:check
Scenario: Find Why Dependency is Included
bash
mvn dependency:tree -Dincludes=commons-logging
Scenario: Force Specific Version (Resolve Conflict)
xml
<dependencyManagement>
    <dependencies>
        <dependency>
            <groupId>org.slf4j</groupId>
            <artifactId>slf4j-api</artifactId>
            <version>2.0.9</version>
        </dependency>
    </dependencies>
</dependencyManagement>
Scenario: Exclude Transitive Dependency
xml
<dependency>
    <groupId>com.example</groupId>
    <artifactId>some-library</artifactId>
    <version>1.0</version>
    <exclusions>
        <exclusion>
            <groupId>commons-logging</groupId>
            <artifactId>commons-logging</artifactId>
        </exclusion>
    </exclusions>
</dependency>

Token Optimization

  • Use -q (quiet) flag for less verbose output
  • Filter with -Dincludes=groupId:artifactId when looking for specific deps
  • Run commands separately and summarize findings
  • Don't paste entire dependency tree - summarize conflicts

Quick Commands Reference

TaskCommand
Outdated depsmvn versions:display-dependency-updates
Outdated pluginsmvn versions:display-plugin-updates
Dependency treemvn dependency:tree
Find specific depmvn dependency:tree -Dincludes=groupId
Unused depsmvn dependency:analyze
Security scanmvn dependency-check:check
Update versionsmvn versions:use-latest-releases
Update snapshotsmvn versions:use-latest-snapshots

Update Strategies

  1. Update patch versions freely
  2. Update minor versions with basic testing
  3. Major versions require migration plan
Aggressive (For Active Development)
bash
# Update all to latest (use with caution!)
mvn versions:use-latest-releases
mvn versions:commit  # or versions:revert
Selective
bash
# Update specific dependency
mvn versions:use-latest-versions -Dincludes=org.junit.jupiter

© decebals, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file in skills/maven-dependency-audit of decebals/claude-code-java.

  • SKILL.md
  • README.md

Open the folder on GitHubat commit 0d98fe9

Compare with similar skills

Maven Dependency Audit next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Maven Dependency Audit compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Maven Dependency Audit this skilldecebals/claude-code-java751—~1.7kAutomated safety check: PassMIT
Triage Dependabot Alertsactivepieces/activepieces25k—~2.9kAutomated safety check: PassCustom licence
Golang Continuous Integrationsamber/cc-skills-golang3.4k—~3.7kAutomated safety check: PassMIT
Golang Continuous Integrationcontext-labs/whip1.1k—~3.5kAutomated safety check: PassMIT
Gem Dependency Managementruby-git/ruby-git1.8k—~806Automated safety check: PassMIT
Stash Supply Chain Securitycipherstash/stack157—~5.2kAutomated safety check: WarnMIT

Similar skills

  • Triage Dependabot Alerts

    activepieces/activepieces

    Triage Dependabot dependency vulnerability alerts for the Activepieces repo — pull open alerts, dedupe to distinct (package, advisory), confirm the vulnerable package + API is actually used, and…

    25k GitHub stars~2.9k tokensUpdated today
    DevelopmentAuto-check passed
  • Golang Continuous Integration

    samber/cc-skills-golang

    GitHub Actions CI/CD pipeline configuration for Golang projects — workflow files for test, lint, SAST, coverage and vulnerability-scan jobs, Dependabot and Renovate config files, GoReleaser release…

    3.4k GitHub stars~3.7k tokensUpdated 9 days ago
    DevelopmentAuto-check passed
  • CI/CD with GitHub Actions for Golang — testing, linting, SAST, security scanning, coverage, Dependabot, Renovate, GoReleaser, release pipelines.

    1.1k GitHub stars~3.5k tokensUpdated 5 days ago
    DevelopmentAuto-check passed
  • Gem Dependency Management

    ruby-git/ruby-git

    Workflow for updating gem dependencies and fixing CVEs in the ruby-git project: assess with bundle outdated and audit, edit the gemspec, test, then commit with conventional messages.

    1.8k GitHub stars~806 tokensUpdated 8 days ago
    DevelopmentAuto-check passed
  • Supply-chain security controls for the @cipherstash/stack monorepo.

    157 GitHub stars~5.2k tokensUpdated today
    DevelopmentAuto-check: warnings
  • Dependency Upgrade Protocol

    dralgorhythm/claude-agentic-framework

    Sequences safe dependency upgrades: read the changelog, verify the version exists upstream, pin it, and keep major bumps in separate commits behind a full gate run.

    125 GitHub stars~1.5k tokensUpdated 2 mo ago
    DevelopmentAuto-check passed

More from decebals/claude-code-java

All 18 skills in this repo
  • Java Design Patterns Reference

    decebals/claude-code-java

    A practical Java reference for Builder, Factory, Singleton, Strategy, Observer and other patterns, with a table matching problems to patterns.

    751 GitHub starsUsed in 1 repo~4.4k tokens
    Auto-check passed
  • Jpa Patterns

    decebals/claude-code-java

    JPA/Hibernate patterns and common pitfalls (N+1, lazy loading, transactions, queries).

    751 GitHub starsUsed in 1 repo~4k tokens
    Auto-check passed
  • Logging Patterns

    decebals/claude-code-java

    Java logging best practices with SLF4J, structured logging (JSON), and MDC for request tracing.

    751 GitHub starsUsed in 1 repo~3.3k tokens
    Auto-check passed
  • REST API Contract Review

    decebals/claude-code-java

    Reviews REST API design for correct HTTP verbs, versioning, DTO use, consistent responses and backward compatibility before an API change ships.

    751 GitHub stars~2.8k tokensUpdated 1 mo ago
    Auto-check passed
  • Java Architecture Review

    decebals/claude-code-java

    Reviews a Java project's architecture at the macro level: package structure, module boundaries, dependency direction and layering.

    751 GitHub stars~2.2k tokensUpdated 1 mo ago
    Auto-check passed
  • Changelog Generator for Java

    decebals/claude-code-java

    Builds changelog entries from conventional commits in a Java project, after working out whether it uses SemVer, two-part versions or calendar versions.

    751 GitHub stars~2.1k tokensUpdated 1 mo ago
    Auto-check passed

Questions about Maven Dependency Audit

What does Maven Dependency Audit do?

Audit Maven dependencies for outdated versions, security vulnerabilities, and conflicts. Maven Dependency Audit is an agent skill from decebals/claude-code-java. Audit Maven dependencies for outdated versions, security vulnerabilities, and conflicts.

When should I use Maven Dependency Audit?

Maven Dependency Audit fits situations like: user says check dependencies; audit dependencies; before releases.

How do I install Maven Dependency Audit in Claude Code?

Run `npx skills add decebals/claude-code-java --skill maven-dependency-audit -a claude-code`. Or copy the skill folder (skills/maven-dependency-audit in decebals/claude-code-java) into .claude/skills/maven-dependency-audit in your project. Claude Code loads it when a task matches its description.

How do I install Maven Dependency Audit in Codex?

Run `npx skills add decebals/claude-code-java --skill maven-dependency-audit -a codex`. Or copy the skill folder (skills/maven-dependency-audit in decebals/claude-code-java) into .agents/skills/maven-dependency-audit in your project. Codex loads it when a task matches its description.

Can I use Maven Dependency Audit in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add decebals/claude-code-java --skill maven-dependency-audit -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/maven-dependency-audit, .gemini/skills/maven-dependency-audit, .github/skills/maven-dependency-audit and .opencode/skills/maven-dependency-audit in your project.

What does Maven Dependency Audit need to run?

Going by SKILL.md and its folder, Maven Dependency Audit needs the command-line tools its instructions call (mvn).

Does Maven Dependency Audit access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Maven Dependency Audit safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Maven Dependency Audit use?

Maven Dependency Audit is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Maven Dependency Audit use?

About 1.7k tokens (SKILL.md is roughly 6.7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Maven Dependency Audit?

Skills that share tags, products or a category with Maven Dependency Audit: Triage Dependabot Alerts (activepieces/activepieces, 25k stars), Golang Continuous Integration (samber/cc-skills-golang, 3.4k stars), Golang Continuous Integration (context-labs/whip, 1.1k stars) and Gem Dependency Management (ruby-git/ruby-git, 1.8k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Maven Dependency Audit?

decebals (a GitHub user) maintains it in decebals/claude-code-java, which has 751 GitHub stars. The repository holds 18 skills in this directory. The repository was last updated on September 6, 2026.

Source: decebals/claude-code-java on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.