Agent skill

Dep Triage

by epam in epam/ai-dial-chat

Reviews dependency-scan findings against repo source to mark each as confirmed (real risk) or falsepositive (not exploitable in this codebase context).

Apache-2.0Auto-check passedSecurity

Install Dep Triage

skills CLI
$ npx skills add epam/ai-dial-chat --skill dep-triage -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install epam/ai-dial-chat dep-triage --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/epam/ai-dial-chat.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/dep-triage .claude/skills/dep-triage && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
dep-triage
GitHub stars
504
Token cost
~1.6k tokens
SKILL.md length
662 words
Files
1
Skills in repo
18
Repo updated
First seen
Licence
Apache-2.0

At a glance

Reviews dependency-scan findings against repo source to mark each as confirmed (real risk) or falsepositive (not exploitable in this codebase context).

  • Works in 3 steps: The package is imported by repo source… → The vulnerable code path is plausibly… → The package is NOT exclusively a…
  • Tasks that involve Vulnerability scanning
  • SKILL.md covers Overview, When to use, Required tools and Inputs, plus 5 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Dep Triage is an agent skill from epam/ai-dial-chat. Reviews dependency-scan findings against repo source to mark each as confirmed (real risk) or falsepositive (not exploitable in this codebase context). Use after /dep-scan emits CVE findings; reduces reviewer noise before human review.

Its SKILL.md is about 1.6k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Security, covering Vulnerability scanning and Codebase knowledge for agents. The repository describes itself as: A default UI for AI DIAL. The licence is Apache-2.0.

When your agent uses it

  • Tasks that involve Vulnerability scanning
  • Tasks that involve Codebase knowledge for agents

Example prompts

  • “Use the dep-triage skill to review dependency-scan findings against repo source to mark each as confirmed (real risk) or falsepositive (not…”
  • “/dep-triage”

Workflow steps

3 steps, taken from the first numbered list in SKILL.md.

  1. The package is imported by repo source under apps/, libs/, or
  2. The vulnerable code path is plausibly reachable from a request,
  3. The package is NOT exclusively a dev-time dependency.

What it can do on your machine

Read from SKILL.md and the folder at commit 3455656. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Dep Triage loads about 1.6k tokens when it runs. Until then it costs about 62 tokens; SKILL.md has 662 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~62
When it runs · the whole SKILL.md, loaded when a task matches
~1.6k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from epam/ai-dial-chat at commit 3455656, republished under its Apache-2.0 licence (© epam). 662 words, ~1,613 tokens.

Download SKILL.mdSave it as .claude/skills/dep-triage/SKILL.md (or your agent's skills folder).
name
dep-triage
description
Reviews dependency-scan findings against repo source to mark each as confirmed (real risk) or false_positive (not exploitable in this codebase context). Use after /dep-scan emits CVE findings; reduces reviewer noise before human review.

Dependency Triage

Overview

Reads upstream scan findings, evaluates each in the repo's actual usage context, and emits the same findings augmented with triage_outcome (confirmed | false_positive) and a one-sentence triage_reason.

This is the triage step — does not run scanners itself. Always downstream of /dep-scan (or another scan agent emitting the same finding shape: cve, package, installed_version, fixed_version).

When to use

  • After /dep-scan in a chained agent (needs: [scan-deps]).
  • Whenever raw scanner output needs filtering before human review.
  • Periodically (e.g., scheduled re-triage to update prior-run outcomes as the codebase evolves).

Required tools

  • Read, Grep, Glob — to inspect repo source for package usage
  • Bash(git diff:*) — to scope which dependencies the PR touched
  • Skill — invocation only
  • Write — auto-granted; for stage-output.json

Inputs

  • upstream/scan-deps/stage-output.json — scan findings from the upstream scan-deps agent (or compatible scanner)

Triage rubric

For each finding under payload.findings[]:

Confirmed (triage_outcome: confirmed)

Mark confirmed if all three hold:

  1. The package is imported by repo source under apps/, libs/, or packages/.
  2. The vulnerable code path is plausibly reachable from a request, user input, or build output.
  3. The package is NOT exclusively a dev-time dependency.
False positive (triage_outcome: false_positive)

Mark FP if any one of these holds:

  1. Not a runtime dep. Listed only under devDependencies / peerDependencies and not exposed at build/runtime (test fixtures, type generators, bundler internals).
  2. Vulnerable function unused. The specific CVE-affected function/API is not called anywhere in apps/, libs/, or packages/.
  3. Network/host context excludes risk. E.g., DoS vuln on internal service the project doesn't expose; SSRF on URL the project never constructs; XSS in a sanitizer the project doesn't reach.
  4. Already mitigated transitively. Repo's package overrides / resolutions pin a safe version.
  5. Out-of-scope target. Scanner flagged a vendored binary, build artifact, or test fixture not part of the deployed application.
Conservative tie-break

If you can't establish FP via one of the rules above, mark confirmed. Better one extra reviewer click than missing a real CVE. Capture uncertainty in triage_reason so the reviewer can re-evaluate quickly.

Process

  1. Read upstream output. upstream/scan-deps/stage-output.json — parse payload.findings[].

  2. For each finding, follow the rubric:

    • Use Grep to find imports of package in apps/, libs/, packages/.
    • If imports exist, Read the importing files to check whether the vulnerable API is actually used.
    • Inspect package.json files to determine dependencies vs devDependencies (path matters — root package.json vs workspace package.jsons differ in semantics).
    • Consider transitive resolutions: check pnpm-lock.yaml / package-lock.json for pinned-safe versions.
  3. Augment each finding with two new fields:

    • triage_outcome: "confirmed" or "false_positive"
    • triage_reason: one short sentence explaining the call. Reference the rule number (1-5) for FPs.
  4. Recompute summary. Update the top-level summary field to reflect post-triage counts: "trivy: <N> raw → <C> confirmed, <F> false_positive".

Show full SKILL.md (220 more words)Show less

Output

Same top-level shape as the upstream scan, with two augmentations:

{
  "stage": "triage-deps",
  "status": "<see below>",
  "summary": "trivy: <N> raw → <C> confirmed, <F> false positive",
  "payload": {
    "findings": [
      {
        "severity": "high",
        "file": "package-lock.json",
        "message": "<CVE>: ... (unchanged from scan)",
        "suggested_fix": "...",
        "cve": "...",
        "package": "lodash",
        "installed_version": "4.17.20",
        "fixed_version": "4.17.21",
        "triage_outcome": "confirmed",
        "triage_reason": "Imported by libs/foo and the vulnerable .pickBy() is called in src/utils/groupBy.ts."
      },
      {
        "severity": "high",
        "file": "package-lock.json",
        "message": "<CVE>: ...",
        ...,
        "triage_outcome": "false_positive",
        "triage_reason": "FP rule 2: vulnerable .template() function is not called anywhere under apps/ or libs/."
      }
    ],
    "triage_summary": {
      "raw": <N>,
      "confirmed": <C>,
      "false_positive": <F>
    }
  }
}
Status
  • passed — all findings false_positive (no confirmed real risks)
  • passed_with_findings — confirmed findings exist but only at info/low/medium severity
  • failed — any confirmed finding at high or critical severity
Severity discipline

Do not downgrade severity. A confirmed-but-low-likelihood finding keeps its original severity (high/critical); the human reviewer decides whether to accept the risk. Triage filters the noise; it does not soften the signal.

Heuristics

  • Grep first, read second. Don't blindly Read every file in libs/. A focused Grep for from '<package>' or require('<package>') scopes the work.
  • Multiple CVEs per package are independent. Same package can have one confirmed CVE (vulnerable function called) and one FP CVE (different function unused). Evaluate each on its own.
  • Capture audit context in triage_reason. A future scheduled re-triage can diff outcomes only if the reasoning is preserved.
  • Don't fabricate file paths. If you can't find an import of the affected package in the repo, that's FP rule 1 (not a runtime dep) or rule 5 (out-of-scope target). Mark it accordingly, don't invent evidence.

Output preservation vs sticky-comment filtering

Emit all findings (confirmed and FP) under payload.findings[] for the artifact — the artifact is the audit trail. The renderer (which posts the sticky PR comment) can filter to confirmed-only for the human view; the artifact retains the full record.

© epam, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .claude/skills/dep-triage of epam/ai-dial-chat.

Open the folder on GitHubat commit 3455656

Compare with similar skills

Dep Triage next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Dep Triage compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Dep Triage this skillepam/ai-dial-chat504—~1.6kAutomated safety check: PassApache-2.0
Deepsec Documentation Guidevercel-labs/deepsec8.1k—~956Automated safety check: PassApache-2.0
Shiro Attack CLISummerSec/ShiroAttack22.6k—~945Automated safety check: PassMIT
Cve Remediationrundeck/rundeck6.3k—~2.9kAutomated safety check: PassApache-2.0
Native Dependency Updatemono/SkiaSharp5.6k—~4.1kAutomated safety check: PassMIT
Forensifyalexgreensh/repo-forensics190—~2.5kAutomated safety check: NotesCustom licence

Similar skills

  • Deepsec Documentation Guide

    vercel-labs/deepsec

    Official

    Points the agent at deepsec's own docs to answer questions about initializing, configuring, resuming, scanning with and extending the vulnerability scanner.

    8.1k GitHub stars~956 tokensUpdated 10 days ago
    SecurityAuto-check passed
  • Shiro Attack CLI

    SummerSec/ShiroAttack2

    当用户要求利用、检测或测试 Apache Shiro rememberMe 反序列化漏洞 (Shiro-550, CVE-2016-4437) 时使用。触发词包括 "Shiro"、"rememberMe"、"shiro attack"、"CVE-2016-4437"、"Shiro-550"、"爆破 Shiro key"、"利用 Shiro"、"Shiro…

    2.6k GitHub stars~945 tokensUpdated 4 mo ago
    SecurityAuto-check passed
  • Cve Remediation

    rundeck/rundeck

    Verify if a CVE affects the project and remediate it. An agent skill from rundeck/rundeck.

    6.3k GitHub stars~2.9k tokensUpdated today
    SecurityAuto-check passed
  • Update native dependencies (libpng, libexpat, zlib, libwebp, harfbuzz, freetype, libjpeg-turbo, etc.) in SkiaSharp's Skia fork.

    5.6k GitHub stars~4.1k tokensUpdated today
    SecurityAuto-check passed
  • Forensify

    alexgreensh/repo-forensics

    Cross-agent self-inspection of your AI-agent stack. An agent skill from alexgreensh/repo-forensics.

    190 GitHub stars~2.5k tokensUpdated 12 days ago
    SecurityAuto-check: notes
  • Write Cve Rule

    evdenis/cvehound

    Write, debug, or validate a CVEhound detection rule (.cocci or .grep) for a Linux kernel CVE.

    138 GitHub stars~2.5k tokensUpdated yesterday
    SecurityAuto-check passed

More from epam/ai-dial-chat

All 18 skills in this repo
  • Refactoring Audit

    epam/ai-dial-chat

    Deep codebase refactoring audit for AI DIAL Chat. An agent skill from epam/ai-dial-chat.

    504 GitHub stars~4.3k tokensUpdated today
    Auto-check passed
  • Read unresolved GitHub code review threads for the pull request associated with the current branch, classify each comment, and implement and verify required code fixes.

    504 GitHub stars~1.7k tokensUpdated today
    Auto-check passed
  • Create Ticket

    epam/ai-dial-chat

    Interactively create OR update GitHub issues (Bug, Feature, Task) for the current repository.

    504 GitHub stars~4.6k tokensUpdated today
    Auto-check passed
  • Dep Scan

    epam/ai-dial-chat

    Runs Trivy filesystem scan against the repo root and emits structured vulnerability findings (CVE, package, versions) in the SDLC reviewer schema.

    504 GitHub stars~1.2k tokensUpdated today
    Auto-check passed
  • Figma

    epam/ai-dial-chat

    Design-to-code workflow for Figma designs. An agent skill from epam/ai-dial-chat.

    504 GitHub stars~997 tokensUpdated today
    Auto-check passed
  • Git Ship

    epam/ai-dial-chat

    A skill your agent uses whenever the user wants to commit, push, or ship changes in a git repository.

    504 GitHub stars~1.2k tokensUpdated today
    Auto-check passed

Categories

Questions about Dep Triage

What does Dep Triage do?

Reviews dependency-scan findings against repo source to mark each as confirmed (real risk) or falsepositive (not exploitable in this codebase context). Dep Triage is an agent skill from epam/ai-dial-chat. Reviews dependency-scan findings against repo source to mark each as confirmed (real risk) or falsepositive (not exploitable in this codebase context).

When should I use Dep Triage?

Dep Triage fits situations like: tasks that involve Vulnerability scanning; tasks that involve Codebase knowledge for agents.

How do I install Dep Triage in Claude Code?

Run `npx skills add epam/ai-dial-chat --skill dep-triage -a claude-code`. Or copy the skill folder (.claude/skills/dep-triage in epam/ai-dial-chat) into .claude/skills/dep-triage in your project. Claude Code loads it when a task matches its description.

How do I install Dep Triage in Codex?

Run `npx skills add epam/ai-dial-chat --skill dep-triage -a codex`. Or copy the skill folder (.claude/skills/dep-triage in epam/ai-dial-chat) into .agents/skills/dep-triage in your project. Codex loads it when a task matches its description.

Can I use Dep Triage in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add epam/ai-dial-chat --skill dep-triage -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/dep-triage, .gemini/skills/dep-triage, .github/skills/dep-triage and .opencode/skills/dep-triage in your project.

What does Dep Triage need to run?

SKILL.md names no scripts, command-line tools or credentials: Dep Triage is instructions for the agent only.

Does Dep Triage access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Dep Triage safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Dep Triage use?

Dep Triage is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Dep Triage use?

About 1.6k tokens (SKILL.md is roughly 6.5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Dep Triage?

Skills that share tags, products or a category with Dep Triage: Deepsec Documentation Guide (vercel-labs/deepsec, 8.1k stars), Shiro Attack CLI (SummerSec/ShiroAttack2, 2.6k stars), Cve Remediation (rundeck/rundeck, 6.3k stars) and Native Dependency Update (mono/SkiaSharp, 5.6k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Dep Triage?

epam (a GitHub organization) maintains it in epam/ai-dial-chat, which has 504 GitHub stars. The repository holds 18 skills in this directory. The repository was last updated on October 9, 2026.

Source: epam/ai-dial-chat on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.