Dep Auditor
laolaoshiren/claude-code-skills-zh
审计 Node.js、Python、Go、Rust、JVM、Ruby 项目的依赖漏洞、版本健康度与许可证事实;当用户要求检查 package.json、lockfile、requirements、go.mod、Cargo.toml、pom.xml、Gemfile.lock,或生成不改依赖的中文审计报告时使用
Analyze dependencies for known security vulnerabilities and outdated versions.
$ npx skills add jeremylongshore/tons-of-skills-marketplace --skill analyzing-dependencies -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install jeremylongshore/tons-of-skills-marketplace analyzing-dependencies --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/jeremylongshore/tons-of-skills-marketplace.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/.curated/analyzing-dependencies .claude/skills/analyzing-dependencies && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "analyzing-dependencies" agent skill from https://github.com/jeremylongshore/tons-of-skills-marketplace/tree/main/skills/.curated/analyzing-dependencies into .claude/skills/analyzing-dependencies/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "analyzing-dependencies", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/jeremylongshore/tons-of-skills-marketplace/tree/main/skills/.curated/analyzing-dependenciesType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add jeremylongshore/tons-of-skills-marketplace --skill analyzing-dependencies -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install jeremylongshore/tons-of-skills-marketplace analyzing-dependencies --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/jeremylongshore/tons-of-skills-marketplace.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/.curated/analyzing-dependencies .agents/skills/analyzing-dependencies && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "analyzing-dependencies" agent skill from https://github.com/jeremylongshore/tons-of-skills-marketplace/tree/main/skills/.curated/analyzing-dependencies into .agents/skills/analyzing-dependencies/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "analyzing-dependencies", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add jeremylongshore/tons-of-skills-marketplace --skill analyzing-dependencies -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install jeremylongshore/tons-of-skills-marketplace analyzing-dependencies --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/jeremylongshore/tons-of-skills-marketplace.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/.curated/analyzing-dependencies .cursor/skills/analyzing-dependencies && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "analyzing-dependencies" agent skill from https://github.com/jeremylongshore/tons-of-skills-marketplace/tree/main/skills/.curated/analyzing-dependencies into .cursor/skills/analyzing-dependencies/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "analyzing-dependencies", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/jeremylongshore/tons-of-skills-marketplace.git --path skills/.curated/analyzing-dependencies--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add jeremylongshore/tons-of-skills-marketplace --skill analyzing-dependencies -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install jeremylongshore/tons-of-skills-marketplace analyzing-dependencies --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/jeremylongshore/tons-of-skills-marketplace.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/.curated/analyzing-dependencies .gemini/skills/analyzing-dependencies && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "analyzing-dependencies" agent skill from https://github.com/jeremylongshore/tons-of-skills-marketplace/tree/main/skills/.curated/analyzing-dependencies into .gemini/skills/analyzing-dependencies/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "analyzing-dependencies", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install jeremylongshore/tons-of-skills-marketplace analyzing-dependenciesInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add jeremylongshore/tons-of-skills-marketplace --skill analyzing-dependencies -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/jeremylongshore/tons-of-skills-marketplace.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/.curated/analyzing-dependencies .github/skills/analyzing-dependencies && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "analyzing-dependencies" agent skill from https://github.com/jeremylongshore/tons-of-skills-marketplace/tree/main/skills/.curated/analyzing-dependencies into .github/skills/analyzing-dependencies/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "analyzing-dependencies", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add jeremylongshore/tons-of-skills-marketplace --skill analyzing-dependencies -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install jeremylongshore/tons-of-skills-marketplace analyzing-dependencies --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/jeremylongshore/tons-of-skills-marketplace.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/.curated/analyzing-dependencies .opencode/skills/analyzing-dependencies && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "analyzing-dependencies" agent skill from https://github.com/jeremylongshore/tons-of-skills-marketplace/tree/main/skills/.curated/analyzing-dependencies into .opencode/skills/analyzing-dependencies/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "analyzing-dependencies", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
analyzing-dependenciesAnalyze dependencies for known security vulnerabilities and outdated versions.
Analyzing Dependencies is an agent skill from jeremylongshore/tons-of-skills-marketplace. Analyze dependencies for known security vulnerabilities and outdated versions. Use when auditing third-party libraries. Trigger with 'check dependencies', 'scan for vulnerabilities', or 'audit packages'.
Its SKILL.md is about 1.7k tokens, which your agent loads only when the skill is triggered. The skill folder holds 10 other files, including scripts, reference files and assets (for example `assets/README.md`, `assets/report_template.md` and `references/README.md`). Compatibility notes: Designed for Claude Code
It sits in Legal & Compliance. It works with npm, Python and Ruby. The repository describes itself as: Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com. The licence is MIT.
10 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit d57fcd5. It shows what the files ask for, not the result of running them.
Pre-approves these tools, so the agent can use them without asking each time:
ReadWriteEditGrepGlobBash(security:*)Bash(scan:*)Bash(audit:*)From allowed-tools in the SKILL.md frontmatter.
Ships 4 files in scripts/ (Python and Shell), which the agent can run.
Shell commands in SKILL.md call:
npmpipcomposerbundlecargoFrom the folder's file list and the shell code blocks in SKILL.md.
Links to these hosts (documentation or services it may open):
owasp.orgnvd.nist.govgithub.comosv.devspdx.orgFrom URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Designed for Claude Code
From compatibility in the SKILL.md frontmatter.
Analyzing Dependencies loads about 1.7k tokens when it runs, and up to ~1.7k if it reads all its reference files. Until then it costs about 57 tokens; SKILL.md has 764 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.
The full file from jeremylongshore/tons-of-skills-marketplace at commit d57fcd5, republished under its MIT licence (© jeremylongshore). 764 words, ~1,720 tokens.
.claude/skills/analyzing-dependencies/SKILL.md (or your agent's skills folder). This skill also uses 7 other files; get the full folder from GitHub.Analyze project dependencies for known security vulnerabilities, outdated versions, and license compliance issues across multiple package ecosystems. This skill inspects npm, pip, Composer, Gem, Go module, and Cargo manifests and lock files, cross-references findings against CVE databases, and produces actionable remediation guidance with upgrade paths.
${CLAUDE_SKILL_DIR}/npm, pip/pip-audit, composer, gem, go, or cargo${CLAUDE_SKILL_DIR}/references/README.md for npm/pip audit report formats, license compatibility matrix, and dependency management best practices${CLAUDE_SKILL_DIR}/ for manifest files: package.json and package-lock.json (npm/Node.js), requirements.txt/pyproject.toml/Pipfile.lock (Python), composer.json/composer.lock (PHP), Gemfile/Gemfile.lock (Ruby), go.mod/go.sum (Go), Cargo.toml/Cargo.lock (Rust).npm audit --json and parse the structured output. Map each advisory to its CVE identifier, CVSS score, severity level, vulnerable version range, and patched version.pip-audit --format=json or parse safety check --json output. Cross-reference each vulnerability against the OSV database for additional context.composer audit, bundle audit, cargo audit, govulncheck) and normalize the output to a common finding format.${CLAUDE_SKILL_DIR}/references/README.md.npm install package@version, pip install --upgrade package==version) prioritized by severity| Error | Cause | Solution |
|---|---|---|
npm audit returns exit code 1 | Vulnerabilities found (expected behavior) | Parse the JSON output normally; exit code 1 indicates findings, not a tool failure |
pip-audit not installed | Tool not available in the environment | Install with pip install pip-audit or fall back to manual pip list --outdated combined with OSV API queries |
| Lock file missing or outdated | Dependencies not properly locked | Run npm install, pip freeze, or equivalent to generate/update the lock file before scanning |
| Network timeout querying vulnerability DB | Firewall or connectivity issue | Retry with increased timeout; fall back to offline analysis of lock file versions against cached CVE data |
| Mixed ecosystem project | Multiple manifest files in one repo | Scan each ecosystem independently and combine results into a unified report |
| Private registry packages not found | Audit tools cannot resolve private packages | Skip private packages in the vulnerability scan; note them as "unverifiable" in the report |
Run npm audit --json in ${CLAUDE_SKILL_DIR}/. Parse the output to identify critical
and high severity advisories. For each, trace the dependency chain from direct
dependency to vulnerable package. Produce upgrade commands:
npm install express@4.19.2 to resolve CVE-2024-XXXXX in path-to-regexp.
Flag any advisory without a fix available as requiring a workaround or alternative package.
Run pip-audit --format=json -r ${CLAUDE_SKILL_DIR}/requirements.txt. Map each
vulnerability to its CVE, CVSS score, and fixed version. For transitive
dependencies, identify the direct dependency pulling in the vulnerable package.
Recommend pinning to safe versions in requirements.txt and adding
pip-audit to the CI pipeline.
Extract licenses from ${CLAUDE_SKILL_DIR}/node_modules/ using license-checker --json
or equivalent. Flag any GPL-3.0 or AGPL-3.0 licensed package used in a
proprietary application as a license conflict. Flag packages with UNLICENSED
or missing license fields as requiring legal review before production use.
© jeremylongshore, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 7 other files (scripts, references, assets) in skills/.curated/analyzing-dependencies of jeremylongshore/tons-of-skills-marketplace.
Open the folder on GitHubat commit d57fcd5
Analyzing Dependencies next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Analyzing Dependencies this skilljeremylongshore/tons-of-skills-marketplace | 2.8k | — | ~1.7k | Automated safety check: Pass | MIT | |
| Dep Auditorlaolaoshiren/claude-code-skills-zh | 880 | — | ~895 | Automated safety check: Pass | MIT | |
| Claude Settings Auditgetsentry/skills | 1k | 4 repos | ~3k | Automated safety check: Pass | Apache-2.0 | |
| Upgrade PackagesMelbourneDeveloper/dart_node | 113 | — | ~2.2k | Automated safety check: Pass | None | |
| Dependency Scanjwynia/agent-skills | 170 | — | ~1.7k | Automated safety check: Pass | MIT | |
| Dependency Auditoralirezarezvani/claude-skills | 28k | — | ~1.1k | Automated safety check: Pass | MIT |
laolaoshiren/claude-code-skills-zh
审计 Node.js、Python、Go、Rust、JVM、Ruby 项目的依赖漏洞、版本健康度与许可证事实;当用户要求检查 package.json、lockfile、requirements、go.mod、Cargo.toml、pom.xml、Gemfile.lock,或生成不改依赖的中文审计报告时使用
getsentry/skills
Analyze a repository to generate recommended Claude Code settings.json permissions.
MelbourneDeveloper/dart_node
Upgrade all dependencies/packages to their latest versions for the detected language(s).
jwynia/agent-skills
Detect CVEs and security issues in project dependencies. An agent skill from jwynia/agent-skills.
alirezarezvani/claude-skills
Audit and manage dependencies across multi-language projects.
aiskillstore/marketplace
Reviews package dependencies for security vulnerabilities, outdated versions, and license compliance.
jeremylongshore/tons-of-skills-marketplace
Execute this skill enables AI assistant to conduct a security-focused code review using the security-agent plugin.
jeremylongshore/tons-of-skills-marketplace
Build this skill automates the adaptation of pre-trained machine learning models using transfer learning techniques.
jeremylongshore/tons-of-skills-marketplace
Execute proactive auto-loading: automatically detects and loads agents.md files.
jeremylongshore/tons-of-skills-marketplace
Aggregate and centralize performance metrics from applications, systems, databases, caches, and services.
jeremylongshore/tons-of-skills-marketplace
Execute this skill enables AI assistant to analyze capacity requirements and plan for future growth.
jeremylongshore/tons-of-skills-marketplace
Process use when you need to work with database indexing. An agent skill from jeremylongshore/tons-of-skills-marketplace.
Categories
Analyze dependencies for known security vulnerabilities and outdated versions. Analyzing Dependencies is an agent skill from jeremylongshore/tons-of-skills-marketplace. Analyze dependencies for known security vulnerabilities and outdated versions.
Analyzing Dependencies fits situations like: auditing third-party libraries; with check dependencies; scan for vulnerabilities.
Run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill analyzing-dependencies -a claude-code`. Or copy the skill folder (skills/.curated/analyzing-dependencies in jeremylongshore/tons-of-skills-marketplace) into .claude/skills/analyzing-dependencies in your project. Claude Code loads it when a task matches its description.
Run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill analyzing-dependencies -a codex`. Or copy the skill folder (skills/.curated/analyzing-dependencies in jeremylongshore/tons-of-skills-marketplace) into .agents/skills/analyzing-dependencies in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill analyzing-dependencies -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/analyzing-dependencies, .gemini/skills/analyzing-dependencies, .github/skills/analyzing-dependencies and .opencode/skills/analyzing-dependencies in your project.
Going by SKILL.md and its folder, Analyzing Dependencies needs Python and a shell for the scripts in its folder and the command-line tools its instructions call (npm, pip, composer, bundle and cargo). Our summary lists: Python 3; Node.js; A Bash shell. Its frontmatter pre-approves these tools: Read, Write, Edit, Grep, Glob, Bash(security:*), Bash(scan:*), Bash(audit:*). Compatibility (from SKILL.md): Designed for Claude Code.
SKILL.md names 5 domains. As links in the text: owasp.org, nvd.nist.gov, github.com, osv.dev and spdx.org. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.
Analyzing Dependencies is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.
About 1.7k tokens (SKILL.md is roughly 6.9k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 16 tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Analyzing Dependencies: Dep Auditor (laolaoshiren/claude-code-skills-zh, 880 stars), Claude Settings Audit (getsentry/skills, 1k stars), Upgrade Packages (MelbourneDeveloper/dart_node, 113 stars) and Dependency Scan (jwynia/agent-skills, 170 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
jeremylongshore (a GitHub user) maintains it in jeremylongshore/tons-of-skills-marketplace, which has 2,831 GitHub stars. The repository holds 3,342 skills in this directory. The repository was last updated on October 11, 2026.
Source: jeremylongshore/tons-of-skills-marketplace on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.