Agent skill

Analyzing Dependencies

by jeremylongshore in jeremylongshore/tons-of-skills-marketplace

Analyze dependencies for known security vulnerabilities and outdated versions.

MITAuto-check passedLegal & Compliance

Install Analyzing Dependencies

skills CLI
$ npx skills add jeremylongshore/tons-of-skills-marketplace --skill analyzing-dependencies -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install jeremylongshore/tons-of-skills-marketplace analyzing-dependencies --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/jeremylongshore/tons-of-skills-marketplace.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/.curated/analyzing-dependencies .claude/skills/analyzing-dependencies && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
analyzing-dependencies
GitHub stars
2.8k
Token cost
~1.7k tokens
SKILL.md length
764 words
Files
8 (incl. scripts, references, assets)
Skills in repo
3,342
Repo updated
First seen
Licence
MIT

At a glance

Analyze dependencies for known security vulnerabilities and outdated versions.

  • Works in 10 steps: Detect the project ecosystem by scanning… → For npm projects, run npm audit --json… → For Python projects, run pip-audit… → …
  • Auditing third-party libraries
  • SKILL.md covers Overview, Prerequisites, Instructions and Output, plus 3 more sections
  • Runs Python and Shell scripts from its folder; calls npm, pip and composer

What it does

Analyzing Dependencies is an agent skill from jeremylongshore/tons-of-skills-marketplace. Analyze dependencies for known security vulnerabilities and outdated versions. Use when auditing third-party libraries. Trigger with 'check dependencies', 'scan for vulnerabilities', or 'audit packages'.

Its SKILL.md is about 1.7k tokens, which your agent loads only when the skill is triggered. The skill folder holds 10 other files, including scripts, reference files and assets (for example `assets/README.md`, `assets/report_template.md` and `references/README.md`). Compatibility notes: Designed for Claude Code

It sits in Legal & Compliance. It works with npm, Python and Ruby. The repository describes itself as: Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com. The licence is MIT.

When your agent uses it

  • Auditing third-party libraries
  • With check dependencies
  • Scan for vulnerabilities

Example prompts

  • “check dependencies”
  • “scan for vulnerabilities”
  • “audit packages”
  • “/analyzing-dependencies”

Requirements

  • Python 3
  • Node.js
  • A Bash shell
  • Compatibility (from SKILL.md): Designed for Claude Code
  • Pre-approved tools (allowed-tools): Read, Write, Edit, Grep, Glob, Bash(security:*), Bash(scan:*), Bash(audit:*)

Workflow steps

10 steps, taken from the first numbered list in SKILL.md.

  1. Detect the project ecosystem by scanning ${CLAUDE_SKILL_DIR}/ for manifest files: package.json and package-lock.json (npm/Node.js)…
  2. For npm projects, run npm audit --json and parse the structured output. Map each advisory to its CVE identifier, CVSS score, severity…
  3. For Python projects, run pip-audit --format=json or parse safety check --json output. Cross-reference each vulnerability against the OSV…
  4. For other ecosystems, run the equivalent audit command (composer audit, bundle audit, cargo audit, govulncheck) and normalize the output…
  5. Analyze the dependency tree for transitive vulnerabilities -- identify which direct dependency pulls in the vulnerable transitive…
  6. Check for outdated packages by comparing installed versions against the latest available versions. Categorize updates as patch (safe)…
  7. Audit license compliance by extracting license declarations from each dependency. Flag packages using copyleft licenses (GPL, AGPL) in…
  8. Identify abandoned or unmaintained packages: flag dependencies with no releases in over 2 years, archived repositories, or known…
  9. Classify each finding by severity (critical, high, medium, low) using CVSS scores: critical >= 9.0, high >= 7.0, medium >= 4.0, low < 4.0.
  10. Generate a remediation plan with specific upgrade commands, alternative packages for abandoned dependencies, and a priority order based on…

What it can do on your machine

Read from SKILL.md and the folder at commit d57fcd5. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Read
    • Write
    • Edit
    • Grep
    • Glob
    • Bash(security:*)
    • Bash(scan:*)
    • Bash(audit:*)

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 4 files in scripts/ (Python and Shell), which the agent can run.

    Shell commands in SKILL.md call:

    • npm
    • pip
    • composer
    • bundle
    • cargo

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • owasp.org
    • nvd.nist.gov
    • github.com
    • osv.dev
    • spdx.org

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

  • Compatibility

    Designed for Claude Code

    From compatibility in the SKILL.md frontmatter.

Context cost

Analyzing Dependencies loads about 1.7k tokens when it runs, and up to ~1.7k if it reads all its reference files. Until then it costs about 57 tokens; SKILL.md has 764 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~57
When it runs · the whole SKILL.md, loaded when a task matches
~1.7k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~1.7k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from jeremylongshore/tons-of-skills-marketplace at commit d57fcd5, republished under its MIT licence (© jeremylongshore). 764 words, ~1,720 tokens.

Download SKILL.mdSave it as .claude/skills/analyzing-dependencies/SKILL.md (or your agent's skills folder). This skill also uses 7 other files; get the full folder from GitHub.
name
analyzing-dependencies
description
Analyze dependencies for known security vulnerabilities and outdated versions. Use when auditing third-party libraries. Trigger with 'check dependencies', 'scan for vulnerabilities', or 'audit packages'.
allowed-tools
Read, Write, Edit, Grep, Glob, Bash(security:*), Bash(scan:*), Bash(audit:*)
compatibility
Designed for Claude Code
version
1.27.0
license
MIT
author
Jeremy Longshore <jeremy@intentsolutions.io>
tags
security, audit, analyzing-dependencies

Analyzing Dependencies

Overview

Analyze project dependencies for known security vulnerabilities, outdated versions, and license compliance issues across multiple package ecosystems. This skill inspects npm, pip, Composer, Gem, Go module, and Cargo manifests and lock files, cross-references findings against CVE databases, and produces actionable remediation guidance with upgrade paths.

Prerequisites

  • Access to the target project directory and manifest files in ${CLAUDE_SKILL_DIR}/
  • At least one package manager CLI available: npm, pip/pip-audit, composer, gem, go, or cargo
  • Network access for querying vulnerability databases (NVD, GitHub Advisory Database, OSV)
  • Reference: ${CLAUDE_SKILL_DIR}/references/README.md for npm/pip audit report formats, license compatibility matrix, and dependency management best practices

Instructions

  1. Detect the project ecosystem by scanning ${CLAUDE_SKILL_DIR}/ for manifest files: package.json and package-lock.json (npm/Node.js), requirements.txt/pyproject.toml/Pipfile.lock (Python), composer.json/composer.lock (PHP), Gemfile/Gemfile.lock (Ruby), go.mod/go.sum (Go), Cargo.toml/Cargo.lock (Rust).
  2. For npm projects, run npm audit --json and parse the structured output. Map each advisory to its CVE identifier, CVSS score, severity level, vulnerable version range, and patched version.
  3. For Python projects, run pip-audit --format=json or parse safety check --json output. Cross-reference each vulnerability against the OSV database for additional context.
  4. For other ecosystems, run the equivalent audit command (composer audit, bundle audit, cargo audit, govulncheck) and normalize the output to a common finding format.
  5. Analyze the dependency tree for transitive vulnerabilities -- identify which direct dependency pulls in the vulnerable transitive dependency, and whether upgrading the direct dependency resolves the issue.
  6. Check for outdated packages by comparing installed versions against the latest available versions. Categorize updates as patch (safe), minor (likely safe), or major (breaking changes possible).
  7. Audit license compliance by extracting license declarations from each dependency. Flag packages using copyleft licenses (GPL, AGPL) in proprietary projects, packages with no declared license, and packages with license conflicts per the compatibility matrix in ${CLAUDE_SKILL_DIR}/references/README.md.
  8. Identify abandoned or unmaintained packages: flag dependencies with no releases in over 2 years, archived repositories, or known deprecation notices.
  9. Classify each finding by severity (critical, high, medium, low) using CVSS scores: critical >= 9.0, high >= 7.0, medium >= 4.0, low < 4.0.
  10. Generate a remediation plan with specific upgrade commands, alternative packages for abandoned dependencies, and a priority order based on severity and exploitability.

Output

  • Vulnerability report: Table with columns: Package, Installed Version, Vulnerability (CVE ID), CVSS Score, Severity, Patched Version, Direct/Transitive
  • Outdated packages: Table with columns: Package, Current Version, Latest Version, Update Type (patch/minor/major), Breaking Changes Risk
  • License audit: Table with columns: Package, License, Compatibility Status (OK, Warning, Conflict), Notes
  • Dependency tree visualization: For critical vulnerabilities, the chain from direct dependency to vulnerable transitive dependency
  • Remediation commands: Ready-to-run commands (e.g., npm install package@version, pip install --upgrade package==version) prioritized by severity
  • Executive summary: Total dependencies scanned, total vulnerabilities by severity, outdated count, license conflicts count
Show full SKILL.md (313 more words)Show less

Error Handling

ErrorCauseSolution
npm audit returns exit code 1Vulnerabilities found (expected behavior)Parse the JSON output normally; exit code 1 indicates findings, not a tool failure
pip-audit not installedTool not available in the environmentInstall with pip install pip-audit or fall back to manual pip list --outdated combined with OSV API queries
Lock file missing or outdatedDependencies not properly lockedRun npm install, pip freeze, or equivalent to generate/update the lock file before scanning
Network timeout querying vulnerability DBFirewall or connectivity issueRetry with increased timeout; fall back to offline analysis of lock file versions against cached CVE data
Mixed ecosystem projectMultiple manifest files in one repoScan each ecosystem independently and combine results into a unified report
Private registry packages not foundAudit tools cannot resolve private packagesSkip private packages in the vulnerability scan; note them as "unverifiable" in the report

Examples

npm Pre-Deployment Audit

Run npm audit --json in ${CLAUDE_SKILL_DIR}/. Parse the output to identify critical and high severity advisories. For each, trace the dependency chain from direct dependency to vulnerable package. Produce upgrade commands: npm install express@4.19.2 to resolve CVE-2024-XXXXX in path-to-regexp. Flag any advisory without a fix available as requiring a workaround or alternative package.

Python Dependency Security Check

Run pip-audit --format=json -r ${CLAUDE_SKILL_DIR}/requirements.txt. Map each vulnerability to its CVE, CVSS score, and fixed version. For transitive dependencies, identify the direct dependency pulling in the vulnerable package. Recommend pinning to safe versions in requirements.txt and adding pip-audit to the CI pipeline.

License Compliance Scan

Extract licenses from ${CLAUDE_SKILL_DIR}/node_modules/ using license-checker --json or equivalent. Flag any GPL-3.0 or AGPL-3.0 licensed package used in a proprietary application as a license conflict. Flag packages with UNLICENSED or missing license fields as requiring legal review before production use.

Resources

© jeremylongshore, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 7 other files (scripts, references, assets) in skills/.curated/analyzing-dependencies of jeremylongshore/tons-of-skills-marketplace.

  • SKILL.md
  • assets/README.md
  • assets/report_template.md
  • references/README.md
  • scripts/README.md
  • scripts/dependency_check.sh
  • scripts/license_compliance_checker.py
  • scripts/vulnerability_report_parser.py

Open the folder on GitHubat commit d57fcd5

Compare with similar skills

Analyzing Dependencies next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Analyzing Dependencies compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Analyzing Dependencies this skilljeremylongshore/tons-of-skills-marketplace2.8k—~1.7kAutomated safety check: PassMIT
Dep Auditorlaolaoshiren/claude-code-skills-zh880—~895Automated safety check: PassMIT
Claude Settings Auditgetsentry/skills1k4 repos~3kAutomated safety check: PassApache-2.0
Upgrade PackagesMelbourneDeveloper/dart_node113—~2.2kAutomated safety check: PassNone
Dependency Scanjwynia/agent-skills170—~1.7kAutomated safety check: PassMIT
Dependency Auditoralirezarezvani/claude-skills28k—~1.1kAutomated safety check: PassMIT

Similar skills

  • Dep Auditor

    laolaoshiren/claude-code-skills-zh

    审计 Node.js、Python、Go、Rust、JVM、Ruby 项目的依赖漏洞、版本健康度与许可证事实;当用户要求检查 package.json、lockfile、requirements、go.mod、Cargo.toml、pom.xml、Gemfile.lock,或生成不改依赖的中文审计报告时使用

    880 GitHub stars~895 tokensUpdated 6 days ago
    DevelopmentAuto-check passed
  • Claude Settings Audit

    getsentry/skills

    Official

    Analyze a repository to generate recommended Claude Code settings.json permissions.

    1k GitHub starsUsed in 4 repos~3k tokens
    DevelopmentAuto-check passed
  • Upgrade Packages

    MelbourneDeveloper/dart_node

    Upgrade all dependencies/packages to their latest versions for the detected language(s).

    113 GitHub stars~2.2k tokensUpdated 27 days ago
    MobileAuto-check passed
  • Dependency Scan

    jwynia/agent-skills

    Detect CVEs and security issues in project dependencies. An agent skill from jwynia/agent-skills.

    170 GitHub stars~1.7k tokensUpdated 7 mo ago
    SecurityAuto-check passed
  • Dependency Auditor

    alirezarezvani/claude-skills

    Audit and manage dependencies across multi-language projects.

    28k GitHub stars~1.1k tokensUpdated 1 mo ago
    Legal & ComplianceAuto-check passed
  • Dependency Audit Assistant

    aiskillstore/marketplace

    Reviews package dependencies for security vulnerabilities, outdated versions, and license compliance.

    433 GitHub stars~2.2k tokensUpdated yesterday
    SecurityAuto-check: notes

More from jeremylongshore/tons-of-skills-marketplace

All 3,342 skills in this repo
  • Performing Security Code Review

    jeremylongshore/tons-of-skills-marketplace

    Execute this skill enables AI assistant to conduct a security-focused code review using the security-agent plugin.

    2.8k GitHub starsUsed in 2 repos~1.3k tokens
    Auto-check: notes
  • Adapting Transfer Learning Models

    jeremylongshore/tons-of-skills-marketplace

    Build this skill automates the adaptation of pre-trained machine learning models using transfer learning techniques.

    2.8k GitHub stars~1.1k tokensUpdated today
    Auto-check passed
  • Agent Context Loader

    jeremylongshore/tons-of-skills-marketplace

    Execute proactive auto-loading: automatically detects and loads agents.md files.

    2.8k GitHub stars~1.1k tokensUpdated today
    Auto-check passed
  • Aggregating Performance Metrics

    jeremylongshore/tons-of-skills-marketplace

    Aggregate and centralize performance metrics from applications, systems, databases, caches, and services.

    2.8k GitHub stars~1.2k tokensUpdated today
    Auto-check passed
  • Analyzing Capacity Planning

    jeremylongshore/tons-of-skills-marketplace

    Execute this skill enables AI assistant to analyze capacity requirements and plan for future growth.

    2.8k GitHub stars~947 tokensUpdated today
    Auto-check passed
  • Analyzing Database Indexes

    jeremylongshore/tons-of-skills-marketplace

    Process use when you need to work with database indexing. An agent skill from jeremylongshore/tons-of-skills-marketplace.

    2.8k GitHub stars~2k tokensUpdated today
    Auto-check passed

Works with

Questions about Analyzing Dependencies

What does Analyzing Dependencies do?

Analyze dependencies for known security vulnerabilities and outdated versions. Analyzing Dependencies is an agent skill from jeremylongshore/tons-of-skills-marketplace. Analyze dependencies for known security vulnerabilities and outdated versions.

When should I use Analyzing Dependencies?

Analyzing Dependencies fits situations like: auditing third-party libraries; with check dependencies; scan for vulnerabilities.

How do I install Analyzing Dependencies in Claude Code?

Run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill analyzing-dependencies -a claude-code`. Or copy the skill folder (skills/.curated/analyzing-dependencies in jeremylongshore/tons-of-skills-marketplace) into .claude/skills/analyzing-dependencies in your project. Claude Code loads it when a task matches its description.

How do I install Analyzing Dependencies in Codex?

Run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill analyzing-dependencies -a codex`. Or copy the skill folder (skills/.curated/analyzing-dependencies in jeremylongshore/tons-of-skills-marketplace) into .agents/skills/analyzing-dependencies in your project. Codex loads it when a task matches its description.

Can I use Analyzing Dependencies in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill analyzing-dependencies -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/analyzing-dependencies, .gemini/skills/analyzing-dependencies, .github/skills/analyzing-dependencies and .opencode/skills/analyzing-dependencies in your project.

What does Analyzing Dependencies need to run?

Going by SKILL.md and its folder, Analyzing Dependencies needs Python and a shell for the scripts in its folder and the command-line tools its instructions call (npm, pip, composer, bundle and cargo). Our summary lists: Python 3; Node.js; A Bash shell. Its frontmatter pre-approves these tools: Read, Write, Edit, Grep, Glob, Bash(security:*), Bash(scan:*), Bash(audit:*). Compatibility (from SKILL.md): Designed for Claude Code.

Does Analyzing Dependencies access the network?

SKILL.md names 5 domains. As links in the text: owasp.org, nvd.nist.gov, github.com, osv.dev and spdx.org. This is read from the text; nothing was executed.

Is Analyzing Dependencies safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Analyzing Dependencies use?

Analyzing Dependencies is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Analyzing Dependencies use?

About 1.7k tokens (SKILL.md is roughly 6.9k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 16 tokens, read only when the agent opens those files.

What are the alternatives to Analyzing Dependencies?

Skills that share tags, products or a category with Analyzing Dependencies: Dep Auditor (laolaoshiren/claude-code-skills-zh, 880 stars), Claude Settings Audit (getsentry/skills, 1k stars), Upgrade Packages (MelbourneDeveloper/dart_node, 113 stars) and Dependency Scan (jwynia/agent-skills, 170 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Analyzing Dependencies?

jeremylongshore (a GitHub user) maintains it in jeremylongshore/tons-of-skills-marketplace, which has 2,831 GitHub stars. The repository holds 3,342 skills in this directory. The repository was last updated on October 11, 2026.

Source: jeremylongshore/tons-of-skills-marketplace on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.