Dep Auditor
laolaoshiren/claude-code-skills-zh
审计 Node.js、Python、Go、Rust、JVM、Ruby 项目的依赖漏洞、版本健康度与许可证事实;当用户要求检查 package.json、lockfile、requirements、go.mod、Cargo.toml、pom.xml、Gemfile.lock,或生成不改依赖的中文审计报告时使用
Detect CVEs and security issues in project dependencies. An agent skill from jwynia/agent-skills.
$ npx skills add jwynia/agent-skills --skill dependency-scan -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install jwynia/agent-skills dependency-scan --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/jwynia/agent-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/tech/security/dependency-scan .claude/skills/dependency-scan && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "dependency-scan" agent skill from https://github.com/jwynia/agent-skills/tree/main/skills/tech/security/dependency-scan into .claude/skills/dependency-scan/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "dependency-scan", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/jwynia/agent-skills/tree/main/skills/tech/security/dependency-scanType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add jwynia/agent-skills --skill dependency-scan -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install jwynia/agent-skills dependency-scan --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/jwynia/agent-skills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/tech/security/dependency-scan .agents/skills/dependency-scan && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "dependency-scan" agent skill from https://github.com/jwynia/agent-skills/tree/main/skills/tech/security/dependency-scan into .agents/skills/dependency-scan/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "dependency-scan", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add jwynia/agent-skills --skill dependency-scan -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install jwynia/agent-skills dependency-scan --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/jwynia/agent-skills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/tech/security/dependency-scan .cursor/skills/dependency-scan && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "dependency-scan" agent skill from https://github.com/jwynia/agent-skills/tree/main/skills/tech/security/dependency-scan into .cursor/skills/dependency-scan/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "dependency-scan", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/jwynia/agent-skills.git --path skills/tech/security/dependency-scan--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add jwynia/agent-skills --skill dependency-scan -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install jwynia/agent-skills dependency-scan --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/jwynia/agent-skills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/tech/security/dependency-scan .gemini/skills/dependency-scan && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "dependency-scan" agent skill from https://github.com/jwynia/agent-skills/tree/main/skills/tech/security/dependency-scan into .gemini/skills/dependency-scan/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "dependency-scan", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install jwynia/agent-skills dependency-scanInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add jwynia/agent-skills --skill dependency-scan -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/jwynia/agent-skills.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/tech/security/dependency-scan .github/skills/dependency-scan && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "dependency-scan" agent skill from https://github.com/jwynia/agent-skills/tree/main/skills/tech/security/dependency-scan into .github/skills/dependency-scan/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "dependency-scan", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add jwynia/agent-skills --skill dependency-scan -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install jwynia/agent-skills dependency-scan --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/jwynia/agent-skills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/tech/security/dependency-scan .opencode/skills/dependency-scan && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "dependency-scan" agent skill from https://github.com/jwynia/agent-skills/tree/main/skills/tech/security/dependency-scan into .opencode/skills/dependency-scan/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "dependency-scan", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
dependency-scanDetect CVEs and security issues in project dependencies. An agent skill from jwynia/agent-skills.
Dependency Scan is an agent skill from jwynia/agent-skills. Detect CVEs and security issues in project dependencies. Use when you need to analyze packages for known vulnerabilities across npm, pip, cargo, and other ecosystems.
Its SKILL.md is about 1.7k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Security, covering Vulnerability scanning. It works with npm, Ruby, Rust and Python. The licence is MIT.
5 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit e02ec7e. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
npmcargoFrom the folder's file list and the shell code blocks in SKILL.md.
Hosts in commands or code, which the agent is likely to contact:
nvd.nist.govgithub.comFrom URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Dependency Scan loads about 1.7k tokens when it runs. Until then it costs about 46 tokens; SKILL.md has 275 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from jwynia/agent-skills at commit e02ec7e, republished under its MIT licence (© jwynia). 275 words, ~1,730 tokens.
.claude/skills/dependency-scan/SKILL.md (or your agent's skills folder).Analyze package dependencies for known vulnerabilities.
/dependency-scan # Scan all detected package managers
/dependency-scan --npm # Node.js packages only
/dependency-scan --pip # Python packages only
/dependency-scan --fix # Auto-fix where possible| Ecosystem | Files | Tool Used |
|---|---|---|
| Node.js | package.json, package-lock.json | npm audit |
| Python | requirements.txt, Pipfile, pyproject.toml | pip-audit, safety |
| Ruby | Gemfile, Gemfile.lock | bundler-audit |
| Java | pom.xml, build.gradle | dependency-check |
| Go | go.mod, go.sum | govulncheck |
| Rust | Cargo.toml, Cargo.lock | cargo-audit |
| PHP | composer.json, composer.lock | composer audit |
| .NET | *.csproj, packages.config | dotnet list --vulnerable |
/dependency-scanScans all detected package managers, reports all severity levels.
/dependency-scan --npm
/dependency-scan --pip
/dependency-scan --go/dependency-scan --severity critical,high
/dependency-scan --severity medium/dependency-scan --fix
/dependency-scan --fix --dry-run # Preview changesAttempts to update vulnerable packages to patched versions.
DEPENDENCY SCAN RESULTS
=======================
Scanned: package.json, requirements.txt
Packages analyzed: 127 (78 npm, 49 pip)
VULNERABILITIES BY SEVERITY
Critical: 2
High: 4
Medium: 8
Low: 12
TOP ISSUES
[!] CRITICAL: lodash < 4.17.21
CVE-2021-23337: Command Injection
Affected: lodash@4.17.19
Fix: npm update lodash
[!] CRITICAL: urllib3 < 2.0.6
CVE-2023-43804: Cookie Leak
Affected: urllib3@1.26.0
Fix: pip install urllib3>=2.0.6
[H] HIGH: express < 4.19.2
CVE-2024-29041: Open Redirect
Affected: express@4.18.0
Fix: npm update express/dependency-scan --detailsDETAILED VULNERABILITY REPORT
=============================
CVE-2021-23337
--------------
Package: lodash
Installed: 4.17.19
Patched: 4.17.21
Severity: CRITICAL (CVSS 9.8)
Description:
Command Injection in lodash template function allows
arbitrary command execution via crafted template strings.
Attack Vector: Remote, no auth required
Exploitability: Public exploit available
References:
- https://nvd.nist.gov/vuln/detail/CVE-2021-23337
- https://github.com/lodash/lodash/issues/5085
Remediation:
npm update lodash
# or
npm install lodash@4.17.21| Database | Coverage |
|---|---|
| NVD (National Vulnerability Database) | All CVEs |
| GitHub Advisory Database | GitHub-reported |
| OSV (Open Source Vulnerabilities) | Multi-ecosystem |
| npm Security Advisories | Node.js specific |
| PyPI Advisory Database | Python specific |
| RustSec Advisory Database | Rust specific |
| Score | Severity |
|---|---|
| 9.0-10.0 | Critical |
| 7.0-8.9 | High |
| 4.0-6.9 | Medium |
| 0.1-3.9 | Low |
npm audit --json
npm audit fix # Auto-fix
npm audit fix --force # Breaking changes OKpip-audit
pip-audit --fix
pip-audit -r requirements.txtsafety check
safety check -r requirements.txtbundle-audit check
bundle-audit update # Update advisory DBgovulncheck ./...cargo audit
cargo audit fix # Auto-fixUpdates within semver-compatible range:
May introduce breaking changes:
--force flagAUTO-FIX REPORT
===============
Fixed: 8 vulnerabilities
lodash: 4.17.19 → 4.17.21
axios: 0.21.0 → 0.21.1
minimist: 1.2.5 → 1.2.6
Unable to fix: 2 vulnerabilities
react-scripts: No patch available (major version required)
webpack-dev-server: Conflicts with other dependencies
Review package.json changes before committing.Create .dependency-scan-ignore:
# Ignore specific CVEs (document reason!)
ignore:
- id: CVE-2021-23337
reason: "Not exploitable in our usage, lodash template not used"
expires: 2024-12-31
- id: GHSA-xxx-xxx
reason: "Development dependency only"
# Ignore packages
packages:
- name: lodash
versions: ["< 4.17.0"] # Only old versions# .dependency-scan.yaml
thresholds:
fail_on: critical # Fail CI on critical
warn_on: high # Warn on high
ignore_below: low # Don't report low
fix:
auto_fix: true
allow_major: false # No major version bumps- name: Dependency Scan
run: |
/dependency-scan --severity critical,high --fail-on-findings
- name: Auto-fix and PR
if: failure()
run: |
/dependency-scan --fix
git add .
gh pr create --title "Security: Update vulnerable dependencies"#!/bin/sh
# Run on package.json changes
if git diff --cached --name-only | grep -q "package.json\|requirements.txt"; then
/dependency-scan --severity critical,high
fi/dependency-scan --healthAdditional checks:
DEPENDENCY HEALTH
=================
Outdated (major behind): 5
react: 17.0.2 → 18.2.0
typescript: 4.9.5 → 5.3.3
Deprecated: 1
request: Use got, axios, or node-fetch
Unmaintained (>2 years): 2
moment: Consider dayjs or date-fns
License Issues: 0/security-scan - Full security analysis/secrets-scan - Credential detection/config-scan - Configuration security© jwynia, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in skills/tech/security/dependency-scan of jwynia/agent-skills.
Open the folder on GitHubat commit e02ec7e
Dependency Scan next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Dependency Scan this skilljwynia/agent-skills | 166 | — | ~1.7k | Automated safety check: Pass | MIT | |
| Dep Auditorlaolaoshiren/claude-code-skills-zh | 878 | — | ~895 | Automated safety check: Pass | MIT | |
| Security AuditTheDecipherist/claude-code-mastery | 550 | — | ~1.3k | Automated safety check: Notes | MIT | |
| Security Reviewgithub/awesome-copilot | 40k | 1 repos | ~2.3k | Automated safety check: Notes | MIT | |
| Sca AuditOWASP/secure-agent-playbook | 187 | — | ~494 | Automated safety check: Pass | CC-BY-4.0 | |
| Phy Regex AuditLeoYeAI/openclaw-master-skills | 2.2k | — | ~5.1k | Automated safety check: Pass | Apache-2.0 |
laolaoshiren/claude-code-skills-zh
审计 Node.js、Python、Go、Rust、JVM、Ruby 项目的依赖漏洞、版本健康度与许可证事实;当用户要求检查 package.json、lockfile、requirements、go.mod、Cargo.toml、pom.xml、Gemfile.lock,或生成不改依赖的中文审计报告时使用
TheDecipherist/claude-code-mastery
Checks a codebase for hardcoded secrets, vulnerable dependencies, weak input handling, weak authentication and unsafe transport settings before deployment or merge.
github/awesome-copilot
AI-powered codebase security scanner that reasons about code like a security researcher — tracing data flows, understanding component interactions, and catching vulnerabilities that pattern-matching…
OWASP/secure-agent-playbook
Scan project dependencies for known vulnerabilities (CVEs). An agent skill from OWASP/secure-agent-playbook.
LeoYeAI/openclaw-master-skills
Static ReDoS (Regular Expression Denial of Service) vulnerability scanner and regex quality auditor for codebases.
infometa/workbuddyskills
容器安全CVE漏洞修复验证引擎。从容器漏扫报告(Excel)自动提取漏洞,生成修复计划, SSH到测试环境验证OS包(apt/yum/apk)、Python(pip)、Node.js(npm)、Java(JAR)四种包类型的 修复方案,产出修复验证报告。不涉及主机层漏洞修复、不处理容器编排层安全配置。
jwynia/agent-skills
Diagnose devcontainer configuration problems and guide development environment setup.
jwynia/agent-skills
Create distinctive, production-grade frontend interfaces with high design quality.
jwynia/agent-skills
Orchestrate agile development workflows for Gitea repositories using the tea CLI.
jwynia/agent-skills
Generate game assets using AI image generation APIs (DALL-E, Replicate, fal.ai) and prepare them for Godot.
jwynia/agent-skills
Develop AI agents, tools, and workflows with Mastra v1 Beta and Hono servers.
jwynia/agent-skills
Create and manipulate PowerPoint PPTX files programmatically.
Categories
Detect CVEs and security issues in project dependencies. An agent skill from jwynia/agent-skills. Dependency Scan is an agent skill from jwynia/agent-skills. Detect CVEs and security issues in project dependencies.
Dependency Scan fits situations like: you need to analyze packages for known vulnerabilities across npm; other ecosystems.
Run `npx skills add jwynia/agent-skills --skill dependency-scan -a claude-code`. Or copy the skill folder (skills/tech/security/dependency-scan in jwynia/agent-skills) into .claude/skills/dependency-scan in your project. Claude Code loads it when a task matches its description.
Run `npx skills add jwynia/agent-skills --skill dependency-scan -a codex`. Or copy the skill folder (skills/tech/security/dependency-scan in jwynia/agent-skills) into .agents/skills/dependency-scan in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add jwynia/agent-skills --skill dependency-scan -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/dependency-scan, .gemini/skills/dependency-scan, .github/skills/dependency-scan and .opencode/skills/dependency-scan in your project.
Going by SKILL.md and its folder, Dependency Scan needs the command-line tools its instructions call (npm and cargo). Our summary lists: Python 3; Node.js.
SKILL.md names 2 domains. In commands or code: nvd.nist.gov and github.com; the agent is likely to contact these when it follows the instructions. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Dependency Scan is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.
About 1.7k tokens (SKILL.md is roughly 6.9k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Dependency Scan: Dep Auditor (laolaoshiren/claude-code-skills-zh, 878 stars), Security Audit (TheDecipherist/claude-code-mastery, 550 stars), Security Review (github/awesome-copilot, 40k stars) and Sca Audit (OWASP/secure-agent-playbook, 187 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
jwynia (a GitHub user) maintains it in jwynia/agent-skills, which has 166 GitHub stars. The repository holds 112 skills in this directory. The repository was last updated on February 24, 2026.
Source: jwynia/agent-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.