Agent skill

Dependency Awareness

by Goldziher in Goldziher/ai-rulez

Per-language dependency vulnerability audit tool reference (cargo audit/deny, pip-audit, npm/pnpm audit, govulncheck, bundler-audit, composer audit, OWASP dependency-check, dotnet vulnerable…

MITAuto-check passedSecurity

Install Dependency Awareness

skills CLI
$ npx skills add Goldziher/ai-rulez --skill dependency-awareness -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install Goldziher/ai-rulez dependency-awareness --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/Goldziher/ai-rulez.git skills-src && mkdir -p .claude/skills && cp -r skills-src/internal/builtins/universal/security/skills/dependency-awareness .claude/skills/dependency-awareness && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
dependency-awareness
GitHub stars
159
Token cost
~250 tokens
SKILL.md length
71 words
Files
1
Skills in repo
11
Repo updated
First seen
Licence
MIT

At a glance

Per-language dependency vulnerability audit tool reference (cargo audit/deny, pip-audit, npm/pnpm audit, govulncheck, bundler-audit, composer audit, OWASP dependency-check, dotnet vulnerable…

  • Tasks that involve Vulnerability scanning
  • Calls cargo, npm and pnpm
  • Tasks that involve Web application vulnerabilities
  • Tasks that involve Supply chain security

What it does

Dependency Awareness is an agent skill from Goldziher/ai-rulez. Per-language dependency vulnerability audit tool reference (cargo audit/deny, pip-audit, npm/pnpm audit, govulncheck, bundler-audit, composer audit, OWASP dependency-check, dotnet vulnerable, mixaudit). Load when adding, updating, or auditing project dependencies, wiring up CI supply-chain checks, or triaging CVEs in a lock file.

Its SKILL.md is about 250 tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Security, covering Vulnerability scanning, Web application vulnerabilities and Supply chain security. It works with pnpm, .NET and npm. The repository describes itself as: One source of truth for AI assistant configs: 14 built-in presets (Claude, Cursor, Copilot, Codex, Gemini, Xum, …), full-parity custom presets, and distributable plugin bundles… The licence is MIT.

When your agent uses it

  • Tasks that involve Vulnerability scanning
  • Tasks that involve Web application vulnerabilities
  • Tasks that involve Supply chain security

Example prompts

  • “/dependency-awareness”

What it can do on your machine

Read from SKILL.md and the folder at commit 2dbd6a4. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • cargo
    • npm
    • pnpm
    • composer
    • dotnet

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use npm and pnpm, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Dependency Awareness loads about 250 tokens when it runs. Until then it costs about 88 tokens; SKILL.md has 71 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~88
When it runs · the whole SKILL.md, loaded when a task matches
~250

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from Goldziher/ai-rulez at commit 2dbd6a4, republished under its MIT licence (© Goldziher). 71 words, ~250 tokens.

Download SKILL.mdSave it as .claude/skills/dependency-awareness/SKILL.md (or your agent's skills folder).
name
dependency-awareness
description
Per-language dependency vulnerability audit tool reference (cargo audit/deny, pip-audit, npm/pnpm audit, govulncheck, bundler-audit, composer audit, OWASP dependency-check, dotnet vulnerable, mix_audit). Load when adding, updating, or auditing project dependencies, wiring up CI supply-chain checks, or triaging CVEs in a lock file.

Audit dependencies before adding them. Prefer well-maintained, widely-used packages with active maintenance. Pin versions and commit lock files. Use language-specific audit tools in CI:

  • Rust: cargo audit, cargo deny (license + advisory policies)
  • Python: pip-audit, bandit (SAST)
  • JavaScript/TypeScript: npm audit, pnpm audit
  • Go: govulncheck
  • Ruby: bundler-audit
  • PHP: composer audit
  • Java: OWASP dependency-check Maven/Gradle plugin
  • C#: dotnet list package --vulnerable
  • Elixir: mix_audit Zero tolerance for critical/high CVEs. Automate dependency update PRs where possible.

© Goldziher, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in internal/builtins/universal/security/skills/dependency-awareness of Goldziher/ai-rulez.

Open the folder on GitHubat commit 2dbd6a4

Compare with similar skills

Dependency Awareness next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Dependency Awareness compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Dependency Awareness this skillGoldziher/ai-rulez159—~250Automated safety check: PassMIT
Interlinked Supply ChainQuentinCody/interlinked-cli178—~2.8kAutomated safety check: PassMIT
npm Supply Chain Securitybodadotsh/npm-security-best-practices858—~1kAutomated safety check: WarnMIT
Cyber NeoHainrixz/cyber-neo283—~5.9kAutomated safety check: WarnMIT
Code Vuln Auditzebbern/claude-code-guide4.7k—~1.3kAutomated safety check: PassMIT
Security Vuln Remediationstacklok/toolhive-studio170—~2.3kAutomated safety check: NotesApache-2.0

Similar skills

  • Interlinked Supply Chain

    QuentinCody/interlinked-cli

    Respond to blocked package installs and manage the Interlinked supply-chain allowlist.

    178 GitHub stars~2.8k tokensUpdated 7 days ago
    SecurityAuto-check passed
  • npm Supply Chain Security

    bodadotsh/npm-security-best-practices

    Applies safer package manager defaults and dependency vetting to JavaScript and TypeScript projects to reduce supply-chain attack risk.

    858 GitHub stars~1k tokensUpdated 9 days ago
    SecurityAuto-check: warnings
  • Cyber Neo

    Hainrixz/cyber-neo

    Comprehensive cybersecurity analysis for any local project. An agent skill from Hainrixz/cyber-neo.

    283 GitHub stars~5.9k tokensUpdated 2 mo ago
    SecurityAuto-check: warnings
  • Code Vuln Audit

    zebbern/claude-code-guide

    Scan code for security issues: dependency vulnerabilities (npm/pip audit), secret leaks (regex and entropy analysis), and OWASP anti-patterns like SQL injection, XSS, or command injection.

    4.7k GitHub stars~1.3k tokensUpdated yesterday
    SecurityAuto-check passed
  • Security Vuln Remediation

    stacklok/toolhive-studio

    Remediate security vulnerabilities found by Grype or pnpm audit.

    170 GitHub stars~2.3k tokensUpdated today
    SecurityAuto-check: notes
  • npm Supply Chain Check

    majiayu000/spellbook

    Scans a repository, its lockfiles and node_modules for known malicious npm package versions and install-time indicators, using a read-only Python scanner.

    287 GitHub stars~1.5k tokensUpdated yesterday
    SecurityAuto-check passed

More from Goldziher/ai-rulez

All 11 skills in this repo
  • AI Rulez

    Goldziher/ai-rulez

    Manage AI assistant governance rules across 52 harnesses (Claude Code, Cursor, Codex, Copilot, Gemini CLI, OpenCode, Devin, and more) using ai-rulez.

    159 GitHub stars~3.1k tokensUpdated today
    Auto-check passed
  • Code Quality Standards

    Goldziher/ai-rulez

    Concrete code-quality thresholds and anti-patterns: 120-char lines, max 20 cyclomatic complexity, max 4 nesting levels, max 50 lines per function, no magic numbers, no global state, composition over…

    159 GitHub stars~486 tokensUpdated today
    Auto-check passed
  • Rust Conventions

    Goldziher/ai-rulez

    Rust code conventions covering edition 2024, cargo fmt/clippy, Result-based error handling, unsafe discipline, async with tokio, API-guideline naming, trait implementations, benchmarking, and…

    159 GitHub stars~746 tokensUpdated today
    Auto-check passed
  • Testing Conventions

    Goldziher/ai-rulez

    How to write a good test: behaviour-describing names (shouldreturnerrorwheninputisempty, givenwhenthen), exact-value assertions over truthiness, snapshot and property-based testing…

    159 GitHub stars~473 tokensUpdated today
    Auto-check passed
  • Vite Plus Conventions

    Goldziher/ai-rulez

    vite+ unified TypeScript toolchain conventions: the vp CLI for package/node management, oxlint/oxfmt, type-aware linting, vitest, rolldown/tsdown bundling, task caching, and migration.

    159 GitHub stars~567 tokensUpdated today
    Auto-check passed
  • Bindings

    Goldziher/ai-rulez

    Cross-language binding architecture rules: bindings as minimal glue, canonical API surface ordering (core, ABI, language), per-language test suites in CI, generated-code discipline, and error/async…

    159 GitHub stars~265 tokensUpdated today
    Auto-check passed

Works with

Categories

Questions about Dependency Awareness

What does Dependency Awareness do?

Per-language dependency vulnerability audit tool reference (cargo audit/deny, pip-audit, npm/pnpm audit, govulncheck, bundler-audit, composer audit, OWASP dependency-check, dotnet vulnerable…. Dependency Awareness is an agent skill from Goldziher/ai-rulez. Per-language dependency vulnerability audit tool reference (cargo audit/deny, pip-audit, npm/pnpm audit, govulncheck, bundler-audit, composer audit, OWASP dependency-check, dotnet vulnerable, mixaudit).

When should I use Dependency Awareness?

Dependency Awareness fits situations like: tasks that involve Vulnerability scanning; tasks that involve Web application vulnerabilities; tasks that involve Supply chain security.

How do I install Dependency Awareness in Claude Code?

Run `npx skills add Goldziher/ai-rulez --skill dependency-awareness -a claude-code`. Or copy the skill folder (internal/builtins/universal/security/skills/dependency-awareness in Goldziher/ai-rulez) into .claude/skills/dependency-awareness in your project. Claude Code loads it when a task matches its description.

How do I install Dependency Awareness in Codex?

Run `npx skills add Goldziher/ai-rulez --skill dependency-awareness -a codex`. Or copy the skill folder (internal/builtins/universal/security/skills/dependency-awareness in Goldziher/ai-rulez) into .agents/skills/dependency-awareness in your project. Codex loads it when a task matches its description.

Can I use Dependency Awareness in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add Goldziher/ai-rulez --skill dependency-awareness -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/dependency-awareness, .gemini/skills/dependency-awareness, .github/skills/dependency-awareness and .opencode/skills/dependency-awareness in your project.

What does Dependency Awareness need to run?

Going by SKILL.md and its folder, Dependency Awareness needs the command-line tools its instructions call (cargo, npm, pnpm, composer and dotnet).

Does Dependency Awareness access the network?

SKILL.md contains no URLs. Its commands use npm, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Dependency Awareness safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Dependency Awareness use?

Dependency Awareness is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Dependency Awareness use?

About 250 tokens (SKILL.md is roughly 1k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Dependency Awareness?

Skills that share tags, products or a category with Dependency Awareness: Interlinked Supply Chain (QuentinCody/interlinked-cli, 178 stars), npm Supply Chain Security (bodadotsh/npm-security-best-practices, 858 stars), Cyber Neo (Hainrixz/cyber-neo, 283 stars) and Code Vuln Audit (zebbern/claude-code-guide, 4.7k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Dependency Awareness?

Goldziher (a GitHub user) maintains it in Goldziher/ai-rulez, which has 159 GitHub stars. The repository holds 11 skills in this directory. The repository was last updated on October 9, 2026.

Source: Goldziher/ai-rulez on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.