Agent skill

Dependency Scan

by jwynia in jwynia/agent-skills

Detect CVEs and security issues in project dependencies. An agent skill from jwynia/agent-skills.

MITAuto-check passedSecurity

Install Dependency Scan

skills CLI
$ npx skills add jwynia/agent-skills --skill dependency-scan -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install jwynia/agent-skills dependency-scan --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/jwynia/agent-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/tech/security/dependency-scan .claude/skills/dependency-scan && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
dependency-scan
GitHub stars
166
Token cost
~1.7k tokens
SKILL.md length
275 words
Files
1
Skills in repo
112
Repo updated
First seen
Licence
MIT

At a glance

Detect CVEs and security issues in project dependencies. An agent skill from jwynia/agent-skills.

  • Works in 5 steps: Identifies package managers in your… → Parses dependency manifests… → Checks vulnerability databases for known… → …
  • You need to analyze packages for known vulnerabilities across npm
  • SKILL.md covers Quick Start, What This Skill Does, Supported Package Managers and Scan Modes, plus 6 more sections
  • Calls npm and cargo; reaches nvd.nist.gov and github.com

What it does

Dependency Scan is an agent skill from jwynia/agent-skills. Detect CVEs and security issues in project dependencies. Use when you need to analyze packages for known vulnerabilities across npm, pip, cargo, and other ecosystems.

Its SKILL.md is about 1.7k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Security, covering Vulnerability scanning. It works with npm, Ruby, Rust and Python. The licence is MIT.

When your agent uses it

  • You need to analyze packages for known vulnerabilities across npm
  • Other ecosystems

Example prompts

  • “/dependency-scan”

Requirements

  • Python 3
  • Node.js

Workflow steps

5 steps, taken from the first numbered list in SKILL.md.

  1. Identifies package managers in your project
  2. Parses dependency manifests (package.json, requirements.txt, etc.)
  3. Checks vulnerability databases for known CVEs
  4. Reports severity and remediation options
  5. Optionally auto-fixes by updating to patched versions

What it can do on your machine

Read from SKILL.md and the folder at commit e02ec7e. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • npm
    • cargo

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • nvd.nist.gov
    • github.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Dependency Scan loads about 1.7k tokens when it runs. Until then it costs about 46 tokens; SKILL.md has 275 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~46
When it runs · the whole SKILL.md, loaded when a task matches
~1.7k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from jwynia/agent-skills at commit e02ec7e, republished under its MIT licence (© jwynia). 275 words, ~1,730 tokens.

Download SKILL.mdSave it as .claude/skills/dependency-scan/SKILL.md (or your agent's skills folder).
name
dependency-scan
description
Detect CVEs and security issues in project dependencies. Use when you need to analyze packages for known vulnerabilities across npm, pip, cargo, and other ecosystems.
license
MIT
metadata.author
jwynia
metadata.version
1.0
metadata.type
utility
metadata.mode
evaluative
metadata.domain
development

Dependency Scan

Analyze package dependencies for known vulnerabilities.

Quick Start

/dependency-scan                  # Scan all detected package managers
/dependency-scan --npm            # Node.js packages only
/dependency-scan --pip            # Python packages only
/dependency-scan --fix            # Auto-fix where possible

What This Skill Does

  1. Identifies package managers in your project
  2. Parses dependency manifests (package.json, requirements.txt, etc.)
  3. Checks vulnerability databases for known CVEs
  4. Reports severity and remediation options
  5. Optionally auto-fixes by updating to patched versions

Supported Package Managers

EcosystemFilesTool Used
Node.jspackage.json, package-lock.jsonnpm audit
Pythonrequirements.txt, Pipfile, pyproject.tomlpip-audit, safety
RubyGemfile, Gemfile.lockbundler-audit
Javapom.xml, build.gradledependency-check
Gogo.mod, go.sumgovulncheck
RustCargo.toml, Cargo.lockcargo-audit
PHPcomposer.json, composer.lockcomposer audit
.NET*.csproj, packages.configdotnet list --vulnerable

Scan Modes

Full Scan
/dependency-scan

Scans all detected package managers, reports all severity levels.

Specific Ecosystem
/dependency-scan --npm
/dependency-scan --pip
/dependency-scan --go
Severity Filter
/dependency-scan --severity critical,high
/dependency-scan --severity medium
Auto-Fix Mode
/dependency-scan --fix
/dependency-scan --fix --dry-run    # Preview changes

Attempts to update vulnerable packages to patched versions.

Output Format

Summary View
DEPENDENCY SCAN RESULTS
=======================

Scanned: package.json, requirements.txt
Packages analyzed: 127 (78 npm, 49 pip)

VULNERABILITIES BY SEVERITY
  Critical: 2
  High: 4
  Medium: 8
  Low: 12

TOP ISSUES

[!] CRITICAL: lodash < 4.17.21
    CVE-2021-23337: Command Injection
    Affected: lodash@4.17.19
    Fix: npm update lodash

[!] CRITICAL: urllib3 < 2.0.6
    CVE-2023-43804: Cookie Leak
    Affected: urllib3@1.26.0
    Fix: pip install urllib3>=2.0.6

[H] HIGH: express < 4.19.2
    CVE-2024-29041: Open Redirect
    Affected: express@4.18.0
    Fix: npm update express
Detailed View
/dependency-scan --details
DETAILED VULNERABILITY REPORT
=============================

CVE-2021-23337
--------------
Package: lodash
Installed: 4.17.19
Patched: 4.17.21
Severity: CRITICAL (CVSS 9.8)

Description:
  Command Injection in lodash template function allows
  arbitrary command execution via crafted template strings.

Attack Vector: Remote, no auth required
Exploitability: Public exploit available

References:
  - https://nvd.nist.gov/vuln/detail/CVE-2021-23337
  - https://github.com/lodash/lodash/issues/5085

Remediation:
  npm update lodash
  # or
  npm install lodash@4.17.21

Vulnerability Sources

Databases Consulted
DatabaseCoverage
NVD (National Vulnerability Database)All CVEs
GitHub Advisory DatabaseGitHub-reported
OSV (Open Source Vulnerabilities)Multi-ecosystem
npm Security AdvisoriesNode.js specific
PyPI Advisory DatabasePython specific
RustSec Advisory DatabaseRust specific
CVSS Scoring
ScoreSeverity
9.0-10.0Critical
7.0-8.9High
4.0-6.9Medium
0.1-3.9Low

Commands Used

Node.js (npm)
bash
npm audit --json
npm audit fix           # Auto-fix
npm audit fix --force   # Breaking changes OK
Python (pip-audit)
bash
pip-audit
pip-audit --fix
pip-audit -r requirements.txt
Python (safety)
bash
safety check
safety check -r requirements.txt
Ruby (bundler-audit)
bash
bundle-audit check
bundle-audit update     # Update advisory DB
Go (govulncheck)
bash
govulncheck ./...
Rust (cargo-audit)
bash
cargo audit
cargo audit fix         # Auto-fix

Auto-Fix Behavior

Safe Fixes

Updates within semver-compatible range:

  • Patch versions (1.2.3 → 1.2.4)
  • Minor versions if locked to major (^1.2.3 → ^1.3.0)
Breaking Fixes

May introduce breaking changes:

  • Major version updates
  • Requires --force flag
Fix Report
AUTO-FIX REPORT
===============

Fixed: 8 vulnerabilities
  lodash: 4.17.19 → 4.17.21
  axios: 0.21.0 → 0.21.1
  minimist: 1.2.5 → 1.2.6

Unable to fix: 2 vulnerabilities
  react-scripts: No patch available (major version required)
  webpack-dev-server: Conflicts with other dependencies

Review package.json changes before committing.

Configuration

Ignore Known Issues

Create .dependency-scan-ignore:

yaml
# Ignore specific CVEs (document reason!)
ignore:
  - id: CVE-2021-23337
    reason: "Not exploitable in our usage, lodash template not used"
    expires: 2024-12-31

  - id: GHSA-xxx-xxx
    reason: "Development dependency only"

# Ignore packages
packages:
  - name: lodash
    versions: ["< 4.17.0"]  # Only old versions
Severity Thresholds
yaml
# .dependency-scan.yaml
thresholds:
  fail_on: critical         # Fail CI on critical
  warn_on: high            # Warn on high
  ignore_below: low        # Don't report low

fix:
  auto_fix: true
  allow_major: false       # No major version bumps

CI/CD Integration

GitHub Actions
yaml
- name: Dependency Scan
  run: |
    /dependency-scan --severity critical,high --fail-on-findings

- name: Auto-fix and PR
  if: failure()
  run: |
    /dependency-scan --fix
    git add .
    gh pr create --title "Security: Update vulnerable dependencies"
Pre-Commit
bash
#!/bin/sh
# Run on package.json changes
if git diff --cached --name-only | grep -q "package.json\|requirements.txt"; then
  /dependency-scan --severity critical,high
fi

Dependency Health

Beyond CVEs
/dependency-scan --health

Additional checks:

  • Outdated packages: Major versions behind
  • Deprecated packages: No longer maintained
  • License issues: Incompatible licenses
  • Maintenance: Last update, open issues
Health Report
DEPENDENCY HEALTH
=================

Outdated (major behind): 5
  react: 17.0.2 → 18.2.0
  typescript: 4.9.5 → 5.3.3

Deprecated: 1
  request: Use got, axios, or node-fetch

Unmaintained (>2 years): 2
  moment: Consider dayjs or date-fns

License Issues: 0
  • /security-scan - Full security analysis
  • /secrets-scan - Credential detection
  • /config-scan - Configuration security

© jwynia, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/tech/security/dependency-scan of jwynia/agent-skills.

Open the folder on GitHubat commit e02ec7e

Compare with similar skills

Dependency Scan next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Dependency Scan compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Dependency Scan this skilljwynia/agent-skills166—~1.7kAutomated safety check: PassMIT
Dep Auditorlaolaoshiren/claude-code-skills-zh878—~895Automated safety check: PassMIT
Security AuditTheDecipherist/claude-code-mastery550—~1.3kAutomated safety check: NotesMIT
Security Reviewgithub/awesome-copilot40k1 repos~2.3kAutomated safety check: NotesMIT
Sca AuditOWASP/secure-agent-playbook187—~494Automated safety check: PassCC-BY-4.0
Phy Regex AuditLeoYeAI/openclaw-master-skills2.2k—~5.1kAutomated safety check: PassApache-2.0

Similar skills

  • Dep Auditor

    laolaoshiren/claude-code-skills-zh

    审计 Node.js、Python、Go、Rust、JVM、Ruby 项目的依赖漏洞、版本健康度与许可证事实;当用户要求检查 package.json、lockfile、requirements、go.mod、Cargo.toml、pom.xml、Gemfile.lock,或生成不改依赖的中文审计报告时使用

    878 GitHub stars~895 tokensUpdated 3 days ago
    DevelopmentAuto-check passed
  • Security Audit

    TheDecipherist/claude-code-mastery

    Checks a codebase for hardcoded secrets, vulnerable dependencies, weak input handling, weak authentication and unsafe transport settings before deployment or merge.

    550 GitHub stars~1.3k tokensUpdated 5 mo ago
    SecurityAuto-check: notes
  • Security Review

    github/awesome-copilot

    Official

    AI-powered codebase security scanner that reasons about code like a security researcher — tracing data flows, understanding component interactions, and catching vulnerabilities that pattern-matching…

    40k GitHub starsUsed in 1 repo~2.3k tokens
    SecurityAuto-check: notes
  • Sca Audit

    OWASP/secure-agent-playbook

    Scan project dependencies for known vulnerabilities (CVEs). An agent skill from OWASP/secure-agent-playbook.

    187 GitHub stars~494 tokensUpdated 13 days ago
    SecurityAuto-check passed
  • Phy Regex Audit

    LeoYeAI/openclaw-master-skills

    Static ReDoS (Regular Expression Denial of Service) vulnerability scanner and regex quality auditor for codebases.

    2.2k GitHub stars~5.1k tokensUpdated 2 mo ago
    SecurityAuto-check passed
  • Container Cve Fix Validator

    infometa/workbuddyskills

    容器安全CVE漏洞修复验证引擎。从容器漏扫报告(Excel)自动提取漏洞,生成修复计划, SSH到测试环境验证OS包(apt/yum/apk)、Python(pip)、Node.js(npm)、Java(JAR)四种包类型的 修复方案,产出修复验证报告。不涉及主机层漏洞修复、不处理容器编排层安全配置。

    344 GitHub stars~779 tokensUpdated yesterday
    SecurityAuto-check: notes

More from jwynia/agent-skills

All 112 skills in this repo
  • Devcontainer

    jwynia/agent-skills

    Diagnose devcontainer configuration problems and guide development environment setup.

    166 GitHub stars~1.2k tokensUpdated 7 mo ago
    Auto-check: notes
  • Frontend Design

    jwynia/agent-skills

    Create distinctive, production-grade frontend interfaces with high design quality.

    166 GitHub stars~3.2k tokensUpdated 7 mo ago
    Auto-check passed
  • Gitea Workflow

    jwynia/agent-skills

    Orchestrate agile development workflows for Gitea repositories using the tea CLI.

    166 GitHub stars~3.8k tokensUpdated 7 mo ago
    Auto-check passed
  • Godot Asset Generator

    jwynia/agent-skills

    Generate game assets using AI image generation APIs (DALL-E, Replicate, fal.ai) and prepare them for Godot.

    166 GitHub stars~3.8k tokensUpdated 7 mo ago
    Auto-check passed
  • Mastra Hono

    jwynia/agent-skills

    Develop AI agents, tools, and workflows with Mastra v1 Beta and Hono servers.

    166 GitHub stars~2.9k tokensUpdated 7 mo ago
    Auto-check passed
  • PPTX Generator

    jwynia/agent-skills

    Create and manipulate PowerPoint PPTX files programmatically.

    166 GitHub stars~3.1k tokensUpdated 7 mo ago
    Auto-check passed

Categories

Questions about Dependency Scan

What does Dependency Scan do?

Detect CVEs and security issues in project dependencies. An agent skill from jwynia/agent-skills. Dependency Scan is an agent skill from jwynia/agent-skills. Detect CVEs and security issues in project dependencies.

When should I use Dependency Scan?

Dependency Scan fits situations like: you need to analyze packages for known vulnerabilities across npm; other ecosystems.

How do I install Dependency Scan in Claude Code?

Run `npx skills add jwynia/agent-skills --skill dependency-scan -a claude-code`. Or copy the skill folder (skills/tech/security/dependency-scan in jwynia/agent-skills) into .claude/skills/dependency-scan in your project. Claude Code loads it when a task matches its description.

How do I install Dependency Scan in Codex?

Run `npx skills add jwynia/agent-skills --skill dependency-scan -a codex`. Or copy the skill folder (skills/tech/security/dependency-scan in jwynia/agent-skills) into .agents/skills/dependency-scan in your project. Codex loads it when a task matches its description.

Can I use Dependency Scan in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add jwynia/agent-skills --skill dependency-scan -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/dependency-scan, .gemini/skills/dependency-scan, .github/skills/dependency-scan and .opencode/skills/dependency-scan in your project.

What does Dependency Scan need to run?

Going by SKILL.md and its folder, Dependency Scan needs the command-line tools its instructions call (npm and cargo). Our summary lists: Python 3; Node.js.

Does Dependency Scan access the network?

SKILL.md names 2 domains. In commands or code: nvd.nist.gov and github.com; the agent is likely to contact these when it follows the instructions. This is read from the text; nothing was executed.

Is Dependency Scan safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Dependency Scan use?

Dependency Scan is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Dependency Scan use?

About 1.7k tokens (SKILL.md is roughly 6.9k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Dependency Scan?

Skills that share tags, products or a category with Dependency Scan: Dep Auditor (laolaoshiren/claude-code-skills-zh, 878 stars), Security Audit (TheDecipherist/claude-code-mastery, 550 stars), Security Review (github/awesome-copilot, 40k stars) and Sca Audit (OWASP/secure-agent-playbook, 187 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Dependency Scan?

jwynia (a GitHub user) maintains it in jwynia/agent-skills, which has 166 GitHub stars. The repository holds 112 skills in this directory. The repository was last updated on February 24, 2026.

Source: jwynia/agent-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.