Agent skill

Dependency Audit

by Mathews-Tom in Mathews-Tom/armory

Audits direct and transitive dependencies for license compliance, maintenance health, CVEs, abandoned packages, and bloat.

MITAuto-check passedSecurity

Install Dependency Audit

skills CLI
$ npx skills add Mathews-Tom/armory --skill dependency-audit -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install Mathews-Tom/armory dependency-audit --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/Mathews-Tom/armory.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/dependency-audit .claude/skills/dependency-audit && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
dependency-audit
GitHub stars
327
Token cost
~2.7k tokens
SKILL.md length
899 words
Files
6 (incl. references)
Skills in repo
80
Repo updated
First seen
Licence
MIT

At a glance

Audits direct and transitive dependencies for license compliance, maintenance health, CVEs, abandoned packages, and bloat.

  • Works in 6 steps: Parse Dependency Tree → Audit Licenses → Assess Maintenance Health → …
  • : audit dependencies
  • SKILL.md covers Reference Files, Prerequisites, Workflow and Output Format, plus 6 more sections
  • Calls npm, cargo and uv

What it does

Dependency Audit is an agent skill from Mathews-Tom/armory. Audits direct and transitive dependencies for license compliance, maintenance health, CVEs, abandoned packages, and bloat. Triggers on: "audit dependencies", "license check", "dependency health", "abandoned packages", "unused dependencies", "license compliance", "supply chain", "dependency risk".

Its SKILL.md is about 2.7k tokens, which your agent loads only when the skill is triggered. The skill folder holds 7 other files, including reference files (for example `evals/cases.yaml`, `references/bloat-detection.md` and `references/cve-sources.md`).

It sits in Security, covering Regulatory compliance, Vulnerability scanning and Supply chain security. The repository describes itself as: Curated, production-grade skills for AI coding agents. Battle-tested workflows for developers who use AI seriously. The licence is MIT.

When your agent uses it

  • : audit dependencies
  • Dependency health
  • Abandoned packages
  • Unused dependencies

Example prompts

  • “audit dependencies”
  • “license check”
  • “dependency health”
  • “/dependency-audit”

Requirements

  • Node.js

Workflow steps

6 steps, taken from the step headings in SKILL.md.

  1. Parse Dependency Tree
  2. Audit Licenses
  3. Assess Maintenance Health
  4. Check Security
  5. Detect Bloat
  6. Report

What it can do on your machine

Read from SKILL.md and the folder at commit 4594fb7. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • npm
    • cargo
    • uv

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use npm and uv, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Dependency Audit loads about 2.7k tokens when it runs, and up to ~14k if it reads all its reference files. Until then it costs about 79 tokens; SKILL.md has 899 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~79
When it runs · the whole SKILL.md, loaded when a task matches
~2.7k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~14k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from Mathews-Tom/armory at commit 4594fb7, republished under its MIT licence (© Mathews-Tom). 899 words, ~2,703 tokens.

Download SKILL.mdSave it as .claude/skills/dependency-audit/SKILL.md (or your agent's skills folder). This skill also uses 5 other files; get the full folder from GitHub.
name
dependency-audit
description
Audits direct and transitive dependencies for license compliance, maintenance health, CVEs, abandoned packages, and bloat. Triggers on: "audit dependencies", "license check", "dependency health", "abandoned packages", "unused dependencies", "license compliance", "supply chain", "dependency risk".
metadata.version
1.1.1
metadata.category
review
metadata.tags
dependencies, vulnerabilities, licenses, supply-chain
metadata.difficulty
intermediate
metadata.phase
review

Dependency Audit

Comprehensive dependency risk assessment: license compatibility analysis, maintenance health scoring, CVE detection, bloat identification, and transitive dependency risk mapping. Produces an actionable report with prioritized remediation steps organized by urgency (security → license → maintenance → bloat).

Reference Files

FileContentsLoad When
references/license-compatibility.mdLicense compatibility matrix, copyleft detection, commercial-safe licensesAlways
references/health-metrics.mdMaintenance health indicators, scoring criteria, abandonment detectionAlways
references/bloat-detection.mdIdentifying unused deps, duplicate functionality, heavy transitive treesBloat analysis requested
references/cve-sources.mdCVE databases, advisory sources, vulnerability severity interpretationSecurity audit requested

Prerequisites

  • Access to the project's dependency files (pyproject.toml, requirements.txt, package.json, Cargo.toml, go.mod)
  • Lock file (for exact versions and transitive dependencies)
  • Project license (to determine compatibility requirements)

Workflow

Phase 1: Parse Dependency Tree
  1. Direct dependencies — Packages explicitly declared in the project.
  2. Transitive dependencies — Dependencies of dependencies. Often 10-50x the direct count.
  3. Version constraints — Pinned (==1.2.3), ranged (>=1.0,<2.0), or floating (*).
  4. Development vs production — Separate dev/test dependencies from production.

Tools:

  • Python: uv pip list, pip-audit, pipdeptree
  • Node.js: npm list --all, npm audit
  • Rust: cargo tree, cargo audit
Phase 2: Audit Licenses

For each dependency:

  1. Identify the license — Check package metadata, LICENSE file, pyproject.toml.

  2. Classify compatibility — Against the project's own license:

    LicenseCommercial OKCopyleftRisk Level
    MIT, BSD, ISC, Apache 2.0YesNoLow
    LGPLWith careWeakMedium
    GPL-2.0, GPL-3.0No (unless GPL project)StrongHigh
    AGPLNo (unless AGPL project)Strong + networkCritical
    UnknownCannot determineUnknownCritical
  3. Flag issues — Copyleft licenses in proprietary projects, unknown licenses, license changes between versions.

Phase 3: Assess Maintenance Health

For each dependency, evaluate maintenance signals:

IndicatorHealthyWarningAbandoned
Last release< 6 months6-18 months> 18 months
Commits (90 days)10+1-90
Open issues response< 2 weeks2-8 weeks> 8 weeks or no response
Bus factor3+ maintainers21
CI statusPassingFlakyFailing or absent
Phase 4: Check Security
  1. Known CVEs — Check against advisory databases:

    • Python: pip-audit, PyPI advisory database
    • Node.js: npm audit, GitHub Advisory Database
    • General: NVD (National Vulnerability Database)
  2. Severity classification — CVSS score interpretation:

    CVSS ScoreSeverityAction
    9.0-10.0CriticalUpgrade immediately
    7.0-8.9HighUpgrade within days
    4.0-6.9MediumUpgrade within weeks
    0.1-3.9LowUpgrade at convenience
  3. Fix availability — Is there a patched version? If not, what's the workaround?

Phase 5: Detect Bloat
  1. Unused dependencies — Dependencies imported nowhere in the codebase.
  2. Duplicate functionality — Multiple packages doing the same thing (2 HTTP clients, 2 JSON parsers).
  3. Heavy transitive trees — Packages that pull in dozens of sub-dependencies for a simple feature.
  4. Size analysis — Large packages used for small functionality.
Phase 6: Report

Produce a prioritized report with action items.

Output Format

text
## Dependency Audit: {Project Name}

### Summary
| Metric | Count |
|--------|-------|
| Direct dependencies | {N} |
| Transitive dependencies | {N} |
| License issues | {N} |
| Maintenance concerns | {N} |
| Security vulnerabilities | {N} |
| Bloat candidates | {N} |

### License Compliance

| Package | Version | License | Compatible | Issue |
|---------|---------|---------|------------|-------|
| {pkg} | {ver} | MIT | Yes | None |
| {pkg} | {ver} | GPL-3.0 | No | Copyleft in proprietary project |
| {pkg} | {ver} | Unknown | Unknown | License not identifiable |

### Maintenance Health

| Package | Last Release | Commits (90d) | Maintainers | Status |
|---------|-------------|---------------|-------------|--------|
| {pkg} | {date} | {N} | {N} | {Healthy/Warning/Abandoned} |

### Security Vulnerabilities

| Package | Version | CVE | Severity | Fix Available | Fixed In |
|---------|---------|-----|----------|---------------|----------|
| {pkg} | {ver} | {CVE-ID} | {severity} | {Yes/No} | {version} |

### Bloat Analysis

| Package | Install Size | Used By | Recommendation |
|---------|-------------|---------|----------------|
| {pkg} | {size} | {usage description} | {Remove/Replace/Keep} |

### Action Items

#### Immediate (Security)
1. Upgrade {pkg} to {version} — fixes {CVE-ID} ({severity})

#### Short-term (License)
1. Review {pkg} GPL usage — may require license change or removal

#### Medium-term (Maintenance)
1. Find alternative to {pkg} — abandoned since {date}

#### Long-term (Bloat)
1. Remove {pkg} — unused in codebase
2. Replace {pkg} with lighter alternative

### Transitive Risk
- {direct-dep} depends on {transitive-dep} which has {issue}

Calibration Rules

  1. Production dependencies first. Dev/test dependencies have lower risk since they don't ship to users. Audit production dependencies with higher scrutiny.
  2. Transitive risk is real. A direct dependency with MIT license may pull in a GPL transitive dependency. Always check the full tree.
  3. Abandoned is not broken. A mature, stable library that hasn't been updated in a year may be perfectly fine. Evaluate based on whether the library is "done" vs "neglected."
  4. Security is non-negotiable. Critical and High CVEs must be addressed immediately. Medium CVEs should be tracked. Low CVEs can wait for the next dependency update cycle.
Show full SKILL.md (359 more words)Show less

Error Handling

ProblemResolution
No lock file availableAudit based on declared dependencies. Note that transitive analysis is incomplete without a lock file.
License metadata missingCheck the package's repository for LICENSE file. Note packages where license cannot be determined.
Package registry unavailableWork from cached metadata and local lockfile data.
Too many dependencies to audit manuallyPrioritize: production deps first, then direct deps, then transitive deps with known issues.

When NOT to Audit

Push back if:

  • The project is a prototype that won't ship — defer audit until production decision
  • The user wants dependency updates, not audit — different task (dependabot, renovate)
  • The project has no dependencies (pure standard library) — nothing to audit

Rationalizations

RationalizationReality
"It's a trusted package"Trust is not a security model — trusted packages get compromised (event-stream, ua-parser-js, colors.js)
"Only a minor version bump"Minor versions can introduce vulnerabilities, change behavior, or add transitive dependencies — semver is a promise, not a guarantee
"We don't use the vulnerable function"Transitive dependencies might — and attack surface includes any code loaded into the process
"The CVE is low severity"Low severity in isolation can be critical in your context — a "low" SSRF in an internal service with cloud metadata access is critical
"We'll update when there's a known exploit"Known exploits mean you're already behind — patch within SLA, not after breach
"Too many dependencies to audit"That's the problem, not an excuse — high dependency count IS a risk finding

Red Flags

  • Auditing only direct dependencies while ignoring transitive dependency tree
  • Dismissing CVEs without checking if the vulnerable code path is reachable
  • No license compatibility check — GPL in a proprietary codebase is a legal finding
  • Accepting "no known vulnerabilities" from a single scanner without cross-referencing
  • Ignoring dependency age — unmaintained packages with no updates in 2+ years are a risk
  • Skipping lockfile analysis (pinned vs. floating versions)

Verification

  • Both direct and transitive dependencies scanned
  • Vulnerability scanner output captured: npm audit / pip-audit / cargo audit
  • Each CVE finding includes: severity, affected version range, upgrade path, reachability assessment
  • License compatibility verified against project license
  • Dependency age and maintenance status checked for top-level deps
  • Lockfile present and version pinning verified — no floating ranges in production

© Mathews-Tom, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 5 other files (references) in skills/dependency-audit of Mathews-Tom/armory.

  • SKILL.md
  • evals/cases.yaml
  • references/bloat-detection.md
  • references/cve-sources.md
  • references/health-metrics.md
  • references/license-compatibility.md

Open the folder on GitHubat commit 4594fb7

Compare with similar skills

Dependency Audit next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Dependency Audit compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Dependency Audit this skillMathews-Tom/armory327—~2.7kAutomated safety check: PassMIT
Codebase Cleanup Deps Auditaiskillstore/marketplace4306 repos~490Automated safety check: PassNone
Open Source PolicyHack23/cia239—~4.6kAutomated safety check: PassApache-2.0
Sca TrivyAgentSecOps/SecOpsAgentKit2192 repos~3.7kAutomated safety check: PassCustom licence
Sbom SyftAgentSecOps/SecOpsAgentKit2191 repos~3.5kAutomated safety check: PassCustom licence
Sca Securityhardw00t/ai-security-arsenal104—~3kAutomated safety check: PassNone

Similar skills

  • Codebase Cleanup Deps Audit

    aiskillstore/marketplace

    You are a dependency security expert specializing in vulnerability scanning, license compliance, and supply chain security.

    430 GitHub starsUsed in 6 repos~490 tokens
    SecurityAuto-check passed
  • Open source governance, security posture badges, license compliance, SBOM generation, and vulnerability management for transparency-driven development

    239 GitHub stars~4.6k tokensUpdated today
    SecurityAuto-check passed
  • Sca Trivy

    AgentSecOps/SecOpsAgentKit

    Software Composition Analysis (SCA) and container vulnerability scanning using Aqua Trivy for identifying CVE vulnerabilities in dependencies, container images, IaC misconfigurations, and license…

    219 GitHub starsUsed in 2 repos~3.7k tokens
    SecurityAuto-check passed
  • Sbom Syft

    AgentSecOps/SecOpsAgentKit

    Software Bill of Materials (SBOM) generation using Syft for container images, filesystems, and archives.

    219 GitHub starsUsed in 1 repo~3.5k tokens
    SecurityAuto-check passed
  • Sca Security

    hardw00t/ai-security-arsenal

    Software Composition Analysis: find vulnerable dependencies, correlate CVE/GHSA/OSV across ecosystems, generate CycloneDX/SPDX SBOMs, assess license compliance, and run reachability-aware triage to…

    104 GitHub stars~3k tokensUpdated 5 mo ago
    SecurityAuto-check passed
  • Vulnerability Scanning

    secondsky/claude-skills

    Automated security scanning for dependencies, code, containers with Trivy, Snyk, npm audit.

    227 GitHub stars~799 tokensUpdated 9 days ago
    SecurityAuto-check passed

More from Mathews-Tom/armory

All 80 skills in this repo
  • Architecture Reviewer

    Mathews-Tom/armory

    Architecture reviews across 7 dimensions (structural, scalability, enterprise readiness, performance, security, ops, data) with scored reports.

    327 GitHub stars~4.6k tokensUpdated yesterday
    Auto-check passed
  • Concept To Image

    Mathews-Tom/armory

    Turn concepts into static HTML visuals exported as PNG or SVG files via HTML/CSS/SVG.

    327 GitHub stars~2.6k tokensUpdated yesterday
    Auto-check passed
  • Watch

    Mathews-Tom/armory

    A skill your agent uses when analyzing an existing video URL or local recording: "watch this video", "analyze youtube video", "summarize this video", "youtube transcript", "find this moment", "what…

    327 GitHub stars~2.8k tokensUpdated yesterday
    Auto-check passed
  • Code Refiner

    Mathews-Tom/armory

    Deep code simplification and refactoring preserving behavior across Python, Go, TypeScript, Rust.

    327 GitHub stars~3.1k tokensUpdated yesterday
    Auto-check passed
  • Concept To Video

    Mathews-Tom/armory

    Turn concepts into animated explainer videos using Manim (Python) with MP4/GIF output, audio overlay, multi-scene composition.

    327 GitHub stars~4.9k tokensUpdated yesterday
    Auto-check passed
  • Decision Map

    Mathews-Tom/armory

    Maps the unresolved architecture, policy, and scope decisions that must be answered before planning can start: one durable decision ticket per question on the issue tracker, typed and blocker-linked…

    327 GitHub stars~2.7k tokensUpdated yesterday
    Auto-check passed

Questions about Dependency Audit

What does Dependency Audit do?

Audits direct and transitive dependencies for license compliance, maintenance health, CVEs, abandoned packages, and bloat. Dependency Audit is an agent skill from Mathews-Tom/armory. Audits direct and transitive dependencies for license compliance, maintenance health, CVEs, abandoned packages, and bloat.

When should I use Dependency Audit?

Dependency Audit fits situations like: : audit dependencies; dependency health; abandoned packages; unused dependencies.

How do I install Dependency Audit in Claude Code?

Run `npx skills add Mathews-Tom/armory --skill dependency-audit -a claude-code`. Or copy the skill folder (skills/dependency-audit in Mathews-Tom/armory) into .claude/skills/dependency-audit in your project. Claude Code loads it when a task matches its description.

How do I install Dependency Audit in Codex?

Run `npx skills add Mathews-Tom/armory --skill dependency-audit -a codex`. Or copy the skill folder (skills/dependency-audit in Mathews-Tom/armory) into .agents/skills/dependency-audit in your project. Codex loads it when a task matches its description.

Can I use Dependency Audit in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add Mathews-Tom/armory --skill dependency-audit -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/dependency-audit, .gemini/skills/dependency-audit, .github/skills/dependency-audit and .opencode/skills/dependency-audit in your project.

What does Dependency Audit need to run?

Going by SKILL.md and its folder, Dependency Audit needs the command-line tools its instructions call (npm, cargo and uv). Our summary lists: Node.js.

Does Dependency Audit access the network?

SKILL.md contains no URLs. Its commands use npm and uv, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Dependency Audit safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Dependency Audit use?

Dependency Audit is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Dependency Audit use?

About 2.7k tokens (SKILL.md is roughly 11k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 11k tokens, read only when the agent opens those files.

What are the alternatives to Dependency Audit?

Skills that share tags, products or a category with Dependency Audit: Codebase Cleanup Deps Audit (aiskillstore/marketplace, 430 stars), Open Source Policy (Hack23/cia, 239 stars), Sca Trivy (AgentSecOps/SecOpsAgentKit, 219 stars) and Sbom Syft (AgentSecOps/SecOpsAgentKit, 219 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Dependency Audit?

Mathews-Tom (a GitHub user) maintains it in Mathews-Tom/armory, which has 327 GitHub stars. The repository holds 80 skills in this directory. The repository was last updated on October 6, 2026.

Source: Mathews-Tom/armory on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.