Agent skill

Tracing Transitive Vulnerabilities

by jeremylongshore in jeremylongshore/tons-of-skills-marketplace

Build a dependency-tree map of a project (npm or Python) and trace the path from each known-vulnerable transitive package back to one or more direct dependencies.

MITAuto-check: notesSecurity

Install Tracing Transitive Vulnerabilities

skills CLI
$ npx skills add jeremylongshore/tons-of-skills-marketplace --skill tracing-transitive-vulnerabilities -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install jeremylongshore/tons-of-skills-marketplace tracing-transitive-vulnerabilities --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/jeremylongshore/tons-of-skills-marketplace.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/.curated/tracing-transitive-vulnerabilities .claude/skills/tracing-transitive-vulnerabilities && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
tracing-transitive-vulnerabilities
GitHub stars
2.8k
Token cost
~2.2k tokens
SKILL.md length
834 words
Files
4 (incl. scripts, references)
Skills in repo
3,342
Repo updated
First seen
Licence
MIT

At a glance

Build a dependency-tree map of a project (npm or Python) and trace the path from each known-vulnerable transitive package back to one or more direct dependencies.

  • Works in 5 steps: Identify the scan target → Acquire audit data → Walk the graph → …
  • : a multi-finding audit produces noise and you need to prioritize
  • SKILL.md covers Overview, When the skill produces findings, Prerequisites and Instructions, plus 4 more sections
  • Runs Python scripts from its folder; calls python3, pip and npm

What it does

Tracing Transitive Vulnerabilities is an agent skill from jeremylongshore/tons-of-skills-marketplace. Build a dependency-tree map of a project (npm or Python) and trace the path from each known-vulnerable transitive package back to one or more direct dependencies. Identifies which direct-dep bump would clear the most findings at once (highest-leverage upgrade), which vulnerabilities are unreachable through any version bump and require overrides or vendor-patch, and which CVEs sit at deep transitive depth (3+ levels from a direct dep) where blast-radius triage is hardest. Use when: a multi-finding audit produces…

Its SKILL.md is about 2.2k tokens, which your agent loads only when the skill is triggered. The skill folder holds 5 other files, including scripts and reference files (for example `references/PLAYBOOK.md`, `references/THEORY.md` and `scripts/trace_vulns.py`). Compatibility notes: Designed for Claude Code

It sits in Security, covering Vulnerability scanning and Supply chain security. It works with npm and Python. The repository describes itself as: Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com. The licence is MIT.

When your agent uses it

  • : a multi-finding audit produces noise and you need to prioritize
  • Planning a major dependency refresh
  • After an upstream package compromise hits your tree (e.g
  • With: trace transitive vulns

Example prompts

  • “trace transitive vulns”
  • “find dep paths”
  • “SBOM vuln trace”
  • “/tracing-transitive-vulnerabilities”

Requirements

  • Python 3
  • Node.js
  • Compatibility (from SKILL.md): Designed for Claude Code
  • Pre-approved tools (allowed-tools): Read, Bash(npm:*), Bash(pip:*), Bash(pip-audit:*), Bash(python3:*), Bash(pipdeptree:*), Glob

Workflow steps

5 steps, taken from the step headings in SKILL.md.

  1. Identify the scan target
  2. Acquire audit data
  3. Walk the graph
  4. Triage by leverage
  5. Plan the upgrades

What it can do on your machine

Read from SKILL.md and the folder at commit cfae287. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Read
    • Bash(npm:*)
    • Bash(pip:*)
    • Bash(pip-audit:*)
    • Bash(python3:*)
    • Bash(pipdeptree:*)
    • Glob

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (Python), which the agent can run.

    Shell commands in SKILL.md call:

    • python3
    • pip
    • npm
    • jq

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use pip and npm, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

  • Compatibility

    Designed for Claude Code

    From compatibility in the SKILL.md frontmatter.

Context cost

Tracing Transitive Vulnerabilities loads about 2.2k tokens when it runs, and up to ~5.4k if it reads all its reference files. Until then it costs about 257 tokens; SKILL.md has 834 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~257
When it runs · the whole SKILL.md, loaded when a task matches
~2.2k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~5.4k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteMentions a .env fileSKILL.md:33
    - Write(.env)
  • NoteMentions a .env fileSKILL.md:34
    - Edit(.env)

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from jeremylongshore/tons-of-skills-marketplace at commit cfae287, republished under its MIT licence (© jeremylongshore). 834 words, ~2,168 tokens.

Download SKILL.mdSave it as .claude/skills/tracing-transitive-vulnerabilities/SKILL.md (or your agent's skills folder). This skill also uses 3 other files; get the full folder from GitHub.
name
tracing-transitive-vulnerabilities
description
Build a dependency-tree map of a project (npm or Python) and trace the path from each known-vulnerable transitive package back to one or more direct dependencies. Identifies which direct-dep bump would clear the most findings at once (highest-leverage upgrade), which vulnerabilities are unreachable through any version bump and require overrides or vendor-patch, and which CVEs sit at deep transitive depth (3+ levels from a direct dep) where blast-radius triage is hardest. Use when: a multi-finding audit produces noise and you need to prioritize, when planning a major dependency refresh, after an upstream package compromise hits your tree (e.g. event-stream flatmap-stream), or when an audit shows findings that automated fix commands cannot auto-resolve. Threshold: any HIGH or CRITICAL CVE reachable only through transitive paths that no single direct-dep bump can clear. Trigger with: "trace transitive vulns", "find dep paths", "SBOM vuln trace", "which direct dep pulls this CVE".
allowed-tools
Read, Bash(npm:*), Bash(pip:*), Bash(pip-audit:*), Bash(python3:*), Bash(pipdeptree:*), Glob
compatibility
Designed for Claude Code
disallowed-tools
Bash(rm:*), Bash(curl:*), Bash(wget:*), Write(.env), Edit(.env), Bash(npm install:*), Bash(pip install:*)
version
3.30.0
author
Jeremy Longshore <jeremy@intentsolutions.io>
license
MIT
tags
security, sbom, transitive-dependency, dependency-graph, pentest

Tracing Transitive Vulnerabilities

Overview

The auditing-npm-dependencies and auditing-python-dependencies skills each surface CVEs, but they don't answer the question that actually decides remediation order: which of these findings can I clear by bumping ONE direct dep, and which require deeper intervention?

That question is the core of supply-chain triage. A high-CVSS CVE in lodash@4.17.4 is alarming on first read. If it's pulled in by five different direct deps, the right fix may not be to bump any of them — it may be a single root-level overrides entry pinning lodash@^4.17.21. The triage discussion goes very differently when you can quote: "this CVE is reachable via 5 paths, all of which flow through webpack, which has a fixed version available." That shifts a project-wide panic to a one-line PR.

This skill walks the project's dependency graph (via npm ls, pipdeptree, or equivalent), intersects it with the CVE findings already produced by the per-language audit skills, and emits a trace report that includes:

  • For each CVE: the full path(s) from direct dep → ... → vulnerable package
  • For each direct dep: the count of CVEs reachable through it
  • "Highest-leverage upgrade" recommendation — the single direct-dep bump that clears the most findings at once
  • "Unreachable" findings — CVEs whose vulnerable version range is forced by EVERY parent in the path, requiring overrides or vendor-patch
  • "Deep transitive" findings (≥3 levels from a direct dep) — these are highest-risk for hidden surprises because the relationship to your code is most opaque

When the skill produces findings

FindingSeverityThresholdAffected control
Critical CVE at deep transitive depth (≥3)HIGHDepth ≥3 + severity CRITICAL — blast radius unclearCWE-1395
High CVE reachable only via overridesHIGHNo direct-dep version clears the findingCWE-1395
Multi-CVE direct-dep hotspotMEDIUMSingle direct dep is ancestor for ≥3 separate CVEs(informational)
Direct-dep bump clears N findingsINFOReports the recommended bump(operational)
Unreachable CVE (no fix in any reachable version)HIGHFinding has no fix-available across the whole graphCWE-1395
Circular dep with CVEMEDIUMCycle in the dep graph involves a vulnerable package(operational)

Prerequisites

  • Python 3.9+
  • npm or pip available (depending on project type)
  • pipdeptree (optional but recommended for Python; falls back to pip show chains if absent — slower but works)
  • An existing audit JSON file from auditing-npm-dependencies or auditing-python-dependencies, OR the willingness to let this skill run those audits itself

Instructions

Step 1 — Identify the scan target

The skill auto-detects whether the project is npm-flavored (package.json + node_modules) or Python-flavored (pyproject.toml / requirements.txt / installed venv).

Step 2 — Acquire audit data

The skill can run the per-language audit itself, or consume a pre-produced audit JSON:

bash
# Self-running mode
python3 ./scripts/trace_vulns.py /path/to/project

# Pre-produced mode (faster on re-runs)
python3 plugins/security/penetration-tester/skills/auditing-npm-dependencies/scripts/audit_npm.py \
    /path/to/project --format json --output /tmp/audit.json
python3 ./scripts/trace_vulns.py /path/to/project --audit-input /tmp/audit.json
Step 3 — Walk the graph

For npm, the skill calls npm ls --json --all to enumerate the full installed tree. For Python, it calls pipdeptree --json-tree or falls back to recursive pip show.

The resulting graph is intersected with the per-package CVE findings, producing a path list for each vulnerability.

Show full SKILL.md (358 more words)Show less
Step 4 — Triage by leverage

The report ranks findings by:

  1. Severity (CRITICAL → HIGH → MEDIUM → LOW)
  2. Depth in the graph (deeper = more uncertain blast radius)
  3. Number of reachable paths (more paths = harder to clear with a single bump)

For each direct dep, the report aggregates:

  • Total reachable CVE count
  • Severity breakdown
  • Suggested bump version (if available)
Step 5 — Plan the upgrades

Use the "highest-leverage upgrade" recommendation as the first PR. Then re-run this skill against the post-upgrade state to confirm how many findings dropped. Iterate until the residual is overrides / vendor work only.

Examples

Example 1 — Triage a noisy audit
bash
# Run base audit
python3 plugins/security/penetration-tester/skills/auditing-npm-dependencies/scripts/audit_npm.py \
    . --format json --output /tmp/npm-audit.json

# Trace
python3 ./scripts/trace_vulns.py . --audit-input /tmp/npm-audit.json \
    --format markdown --output /tmp/trace.md

/tmp/trace.md is human-readable: per-CVE path lists + recommended bumps + leverage analysis.

Example 2 — Highest-leverage upgrade discovery
bash
python3 ./scripts/trace_vulns.py . --format json --leverage-only \
    | jq '.[] | select(.cve_count >= 3)'

Surfaces direct deps that, if bumped, would clear ≥3 CVEs at once.

Example 3 — Deep-transitive risk report
bash
python3 ./scripts/trace_vulns.py . --min-depth 3 --format markdown \
    --output deep-trace.md

Limits output to findings at depth ≥3 from a direct dep — the hardest-to-triage class.

Output

JSON / JSONL / Markdown per lib/report.py. Exit codes: 0 clean, 1 high/critical, 2 error.

Each Finding includes:

  • id — trace::<cve-id>::<vulnerable-package>
  • severity — re-derived based on depth + reachability
  • category — transitive-trace
  • summary — short description of the path situation
  • evidence — original CVE, dep path(s), depth, parent direct-deps, recommended bump
  • references — link back to the source audit finding

A "leverage report" section in markdown output lists the top-N direct-dep bumps ranked by aggregate CVE-clearance count.

Error Handling

  • npm ls fails to produce a complete tree (lockfile out of sync) → emits an INFO Finding flagging the desync and proceeds with partial data.
  • pipdeptree not installed → falls back to pip show recursion; emits INFO finding recommending pipdeptree install for accuracy.
  • No audit findings input AND no audit tool available → exits 2 with operational error advising the operator to provide an audit JSON via --audit-input.
  • Graph contains cycles → cycles are detected and broken; each package in the cycle is reported once at its shallowest depth.

Resources

  • references/THEORY.md — Why deep transitive deps are disproportionately risky, dependency-graph traversal theory, SBOM (Software Bill of Materials) standards (CycloneDX, SPDX 3.0), reachability theory for vulnerability analysis, exploit-prediction-scoring-system (EPSS) integration plans
  • references/PLAYBOOK.md — Per-runtime trace patterns, SBOM generation patterns (cyclonedx-cli, syft, anchore), graph-based upgrade planning, when to override vs vendor-patch, integration with the per-language audit skills

© jeremylongshore, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 3 other files (scripts, references) in skills/.curated/tracing-transitive-vulnerabilities of jeremylongshore/tons-of-skills-marketplace.

  • SKILL.md
  • references/PLAYBOOK.md
  • references/THEORY.md
  • scripts/trace_vulns.py

Open the folder on GitHubat commit cfae287

Compare with similar skills

Tracing Transitive Vulnerabilities next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Tracing Transitive Vulnerabilities compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Tracing Transitive Vulnerabilities this skilljeremylongshore/tons-of-skills-marketplace2.8k—~2.2kAutomated safety check: NotesMIT
npm Supply Chain Checkmajiayu000/spellbook287—~1.5kAutomated safety check: PassMIT
Vulners API Python SDKvulnersCom/api376—~2.3kAutomated safety check: PassMIT
Security AuditTheDecipherist/claude-code-mastery551—~1.3kAutomated safety check: NotesMIT
Cyber NeoHainrixz/cyber-neo283—~5.9kAutomated safety check: WarnMIT
Corpus Sweepnubjs/nub4.4k—~2.4kAutomated safety check: PassMIT

Similar skills

  • npm Supply Chain Check

    majiayu000/spellbook

    Scans a repository, its lockfiles and node_modules for known malicious npm package versions and install-time indicators, using a read-only Python scanner.

    287 GitHub stars~1.5k tokensUpdated 2 days ago
    SecurityAuto-check passed
  • A skill your agent uses when modifying, testing, documenting, or reviewing the Vulners Python SDK.

    376 GitHub stars~2.3k tokensUpdated 12 days ago
    SecurityAuto-check passed
  • Security Audit

    TheDecipherist/claude-code-mastery

    Checks a codebase for hardcoded secrets, vulnerable dependencies, weak input handling, weak authentication and unsafe transport settings before deployment or merge.

    551 GitHub stars~1.3k tokensUpdated 5 mo ago
    SecurityAuto-check: notes
  • Cyber Neo

    Hainrixz/cyber-neo

    Comprehensive cybersecurity analysis for any local project. An agent skill from Hainrixz/cyber-neo.

    283 GitHub stars~5.9k tokensUpdated 2 mo ago
    SecurityAuto-check: warnings
  • Corpus Sweep

    nubjs/nub

    Run a large sharded measurement sweep over npm packages (the build-jail catalog probe, or any harness that installs thousands of package-versions and records a verdict per run).

    4.4k GitHub stars~2.4k tokensUpdated yesterday
    SecurityAuto-check passed
  • Sca Trivy

    AgentSecOps/SecOpsAgentKit

    Software Composition Analysis (SCA) and container vulnerability scanning using Aqua Trivy for identifying CVE vulnerabilities in dependencies, container images, IaC misconfigurations, and license…

    220 GitHub starsUsed in 2 repos~3.7k tokens
    SecurityAuto-check passed

More from jeremylongshore/tons-of-skills-marketplace

All 3,342 skills in this repo
  • Performing Security Code Review

    jeremylongshore/tons-of-skills-marketplace

    Execute this skill enables AI assistant to conduct a security-focused code review using the security-agent plugin.

    2.8k GitHub starsUsed in 2 repos~1.3k tokens
    Auto-check: notes
  • Adapting Transfer Learning Models

    jeremylongshore/tons-of-skills-marketplace

    Build this skill automates the adaptation of pre-trained machine learning models using transfer learning techniques.

    2.8k GitHub stars~1.1k tokensUpdated today
    Auto-check passed
  • Agent Context Loader

    jeremylongshore/tons-of-skills-marketplace

    Execute proactive auto-loading: automatically detects and loads agents.md files.

    2.8k GitHub stars~1.1k tokensUpdated today
    Auto-check passed
  • Aggregating Performance Metrics

    jeremylongshore/tons-of-skills-marketplace

    Aggregate and centralize performance metrics from applications, systems, databases, caches, and services.

    2.8k GitHub stars~1.2k tokensUpdated today
    Auto-check passed
  • Analyzing Capacity Planning

    jeremylongshore/tons-of-skills-marketplace

    Execute this skill enables AI assistant to analyze capacity requirements and plan for future growth.

    2.8k GitHub stars~947 tokensUpdated today
    Auto-check passed
  • Analyzing Database Indexes

    jeremylongshore/tons-of-skills-marketplace

    Process use when you need to work with database indexing. An agent skill from jeremylongshore/tons-of-skills-marketplace.

    2.8k GitHub stars~2k tokensUpdated today
    Auto-check passed

Works with

Categories

Questions about Tracing Transitive Vulnerabilities

What does Tracing Transitive Vulnerabilities do?

Build a dependency-tree map of a project (npm or Python) and trace the path from each known-vulnerable transitive package back to one or more direct dependencies. Tracing Transitive Vulnerabilities is an agent skill from jeremylongshore/tons-of-skills-marketplace. Build a dependency-tree map of a project (npm or Python) and trace the path from each known-vulnerable transitive package back to one or more direct dependencies.

When should I use Tracing Transitive Vulnerabilities?

Tracing Transitive Vulnerabilities fits situations like: : a multi-finding audit produces noise and you need to prioritize; planning a major dependency refresh; after an upstream package compromise hits your tree (e.g; with: trace transitive vulns.

How do I install Tracing Transitive Vulnerabilities in Claude Code?

Run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill tracing-transitive-vulnerabilities -a claude-code`. Or copy the skill folder (skills/.curated/tracing-transitive-vulnerabilities in jeremylongshore/tons-of-skills-marketplace) into .claude/skills/tracing-transitive-vulnerabilities in your project. Claude Code loads it when a task matches its description.

How do I install Tracing Transitive Vulnerabilities in Codex?

Run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill tracing-transitive-vulnerabilities -a codex`. Or copy the skill folder (skills/.curated/tracing-transitive-vulnerabilities in jeremylongshore/tons-of-skills-marketplace) into .agents/skills/tracing-transitive-vulnerabilities in your project. Codex loads it when a task matches its description.

Can I use Tracing Transitive Vulnerabilities in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill tracing-transitive-vulnerabilities -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/tracing-transitive-vulnerabilities, .gemini/skills/tracing-transitive-vulnerabilities, .github/skills/tracing-transitive-vulnerabilities and .opencode/skills/tracing-transitive-vulnerabilities in your project.

What does Tracing Transitive Vulnerabilities need to run?

Going by SKILL.md and its folder, Tracing Transitive Vulnerabilities needs Python for the scripts in its folder and the command-line tools its instructions call (python3, pip, npm and jq). Our summary lists: Python 3; Node.js. Its frontmatter pre-approves these tools: Read, Bash(npm:*), Bash(pip:*), Bash(pip-audit:*), Bash(python3:*), Bash(pipdeptree:*), Glob. Compatibility (from SKILL.md): Designed for Claude Code.

Does Tracing Transitive Vulnerabilities access the network?

SKILL.md contains no URLs. Its commands use pip and npm, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Tracing Transitive Vulnerabilities safe to install?

Our automated static check of SKILL.md found notes only (mentions a .env file), nothing it rates as a warning. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Tracing Transitive Vulnerabilities use?

Tracing Transitive Vulnerabilities is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Tracing Transitive Vulnerabilities use?

About 2.2k tokens (SKILL.md is roughly 8.7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 3.3k tokens, read only when the agent opens those files.

What are the alternatives to Tracing Transitive Vulnerabilities?

Skills that share tags, products or a category with Tracing Transitive Vulnerabilities: npm Supply Chain Check (majiayu000/spellbook, 287 stars), Vulners API Python SDK (vulnersCom/api, 376 stars), Security Audit (TheDecipherist/claude-code-mastery, 551 stars) and Cyber Neo (Hainrixz/cyber-neo, 283 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Tracing Transitive Vulnerabilities?

jeremylongshore (a GitHub user) maintains it in jeremylongshore/tons-of-skills-marketplace, which has 2,827 GitHub stars. The repository holds 3,342 skills in this directory. The repository was last updated on October 10, 2026.

Source: jeremylongshore/tons-of-skills-marketplace on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.