Codebase Cleanup Deps Audit
aiskillstore/marketplace
You are a dependency security expert specializing in vulnerability scanning, license compliance, and supply chain security.
Audits direct and transitive dependencies for license compliance, maintenance health, CVEs, abandoned packages, and bloat.
$ npx skills add Mathews-Tom/armory --skill dependency-audit -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install Mathews-Tom/armory dependency-audit --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/Mathews-Tom/armory.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/dependency-audit .claude/skills/dependency-audit && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "dependency-audit" agent skill from https://github.com/Mathews-Tom/armory/tree/main/skills/dependency-audit into .claude/skills/dependency-audit/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "dependency-audit", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/Mathews-Tom/armory/tree/main/skills/dependency-auditType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add Mathews-Tom/armory --skill dependency-audit -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install Mathews-Tom/armory dependency-audit --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/Mathews-Tom/armory.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/dependency-audit .agents/skills/dependency-audit && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "dependency-audit" agent skill from https://github.com/Mathews-Tom/armory/tree/main/skills/dependency-audit into .agents/skills/dependency-audit/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "dependency-audit", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add Mathews-Tom/armory --skill dependency-audit -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install Mathews-Tom/armory dependency-audit --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/Mathews-Tom/armory.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/dependency-audit .cursor/skills/dependency-audit && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "dependency-audit" agent skill from https://github.com/Mathews-Tom/armory/tree/main/skills/dependency-audit into .cursor/skills/dependency-audit/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "dependency-audit", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/Mathews-Tom/armory.git --path skills/dependency-audit--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add Mathews-Tom/armory --skill dependency-audit -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install Mathews-Tom/armory dependency-audit --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/Mathews-Tom/armory.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/dependency-audit .gemini/skills/dependency-audit && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "dependency-audit" agent skill from https://github.com/Mathews-Tom/armory/tree/main/skills/dependency-audit into .gemini/skills/dependency-audit/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "dependency-audit", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install Mathews-Tom/armory dependency-auditInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add Mathews-Tom/armory --skill dependency-audit -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/Mathews-Tom/armory.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/dependency-audit .github/skills/dependency-audit && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "dependency-audit" agent skill from https://github.com/Mathews-Tom/armory/tree/main/skills/dependency-audit into .github/skills/dependency-audit/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "dependency-audit", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add Mathews-Tom/armory --skill dependency-audit -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install Mathews-Tom/armory dependency-audit --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/Mathews-Tom/armory.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/dependency-audit .opencode/skills/dependency-audit && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "dependency-audit" agent skill from https://github.com/Mathews-Tom/armory/tree/main/skills/dependency-audit into .opencode/skills/dependency-audit/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "dependency-audit", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
dependency-auditAudits direct and transitive dependencies for license compliance, maintenance health, CVEs, abandoned packages, and bloat.
Dependency Audit is an agent skill from Mathews-Tom/armory. Audits direct and transitive dependencies for license compliance, maintenance health, CVEs, abandoned packages, and bloat. Triggers on: "audit dependencies", "license check", "dependency health", "abandoned packages", "unused dependencies", "license compliance", "supply chain", "dependency risk".
Its SKILL.md is about 2.7k tokens, which your agent loads only when the skill is triggered. The skill folder holds 7 other files, including reference files (for example `evals/cases.yaml`, `references/bloat-detection.md` and `references/cve-sources.md`).
It sits in Security, covering Regulatory compliance, Vulnerability scanning and Supply chain security. The repository describes itself as: Curated, production-grade skills for AI coding agents. Battle-tested workflows for developers who use AI seriously. The licence is MIT.
6 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 4594fb7. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
npmcargouvFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use npm and uv, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Dependency Audit loads about 2.7k tokens when it runs, and up to ~14k if it reads all its reference files. Until then it costs about 79 tokens; SKILL.md has 899 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from Mathews-Tom/armory at commit 4594fb7, republished under its MIT licence (© Mathews-Tom). 899 words, ~2,703 tokens.
.claude/skills/dependency-audit/SKILL.md (or your agent's skills folder). This skill also uses 5 other files; get the full folder from GitHub.Comprehensive dependency risk assessment: license compatibility analysis, maintenance health scoring, CVE detection, bloat identification, and transitive dependency risk mapping. Produces an actionable report with prioritized remediation steps organized by urgency (security → license → maintenance → bloat).
| File | Contents | Load When |
|---|---|---|
references/license-compatibility.md | License compatibility matrix, copyleft detection, commercial-safe licenses | Always |
references/health-metrics.md | Maintenance health indicators, scoring criteria, abandonment detection | Always |
references/bloat-detection.md | Identifying unused deps, duplicate functionality, heavy transitive trees | Bloat analysis requested |
references/cve-sources.md | CVE databases, advisory sources, vulnerability severity interpretation | Security audit requested |
pyproject.toml, requirements.txt,
package.json, Cargo.toml, go.mod)==1.2.3), ranged (>=1.0,<2.0), or floating (*).Tools:
uv pip list, pip-audit, pipdeptreenpm list --all, npm auditcargo tree, cargo auditFor each dependency:
Identify the license — Check package metadata, LICENSE file, pyproject.toml.
Classify compatibility — Against the project's own license:
| License | Commercial OK | Copyleft | Risk Level |
|---|---|---|---|
| MIT, BSD, ISC, Apache 2.0 | Yes | No | Low |
| LGPL | With care | Weak | Medium |
| GPL-2.0, GPL-3.0 | No (unless GPL project) | Strong | High |
| AGPL | No (unless AGPL project) | Strong + network | Critical |
| Unknown | Cannot determine | Unknown | Critical |
Flag issues — Copyleft licenses in proprietary projects, unknown licenses, license changes between versions.
For each dependency, evaluate maintenance signals:
| Indicator | Healthy | Warning | Abandoned |
|---|---|---|---|
| Last release | < 6 months | 6-18 months | > 18 months |
| Commits (90 days) | 10+ | 1-9 | 0 |
| Open issues response | < 2 weeks | 2-8 weeks | > 8 weeks or no response |
| Bus factor | 3+ maintainers | 2 | 1 |
| CI status | Passing | Flaky | Failing or absent |
Known CVEs — Check against advisory databases:
pip-audit, PyPI advisory databasenpm audit, GitHub Advisory DatabaseSeverity classification — CVSS score interpretation:
| CVSS Score | Severity | Action |
|---|---|---|
| 9.0-10.0 | Critical | Upgrade immediately |
| 7.0-8.9 | High | Upgrade within days |
| 4.0-6.9 | Medium | Upgrade within weeks |
| 0.1-3.9 | Low | Upgrade at convenience |
Fix availability — Is there a patched version? If not, what's the workaround?
Produce a prioritized report with action items.
## Dependency Audit: {Project Name}
### Summary
| Metric | Count |
|--------|-------|
| Direct dependencies | {N} |
| Transitive dependencies | {N} |
| License issues | {N} |
| Maintenance concerns | {N} |
| Security vulnerabilities | {N} |
| Bloat candidates | {N} |
### License Compliance
| Package | Version | License | Compatible | Issue |
|---------|---------|---------|------------|-------|
| {pkg} | {ver} | MIT | Yes | None |
| {pkg} | {ver} | GPL-3.0 | No | Copyleft in proprietary project |
| {pkg} | {ver} | Unknown | Unknown | License not identifiable |
### Maintenance Health
| Package | Last Release | Commits (90d) | Maintainers | Status |
|---------|-------------|---------------|-------------|--------|
| {pkg} | {date} | {N} | {N} | {Healthy/Warning/Abandoned} |
### Security Vulnerabilities
| Package | Version | CVE | Severity | Fix Available | Fixed In |
|---------|---------|-----|----------|---------------|----------|
| {pkg} | {ver} | {CVE-ID} | {severity} | {Yes/No} | {version} |
### Bloat Analysis
| Package | Install Size | Used By | Recommendation |
|---------|-------------|---------|----------------|
| {pkg} | {size} | {usage description} | {Remove/Replace/Keep} |
### Action Items
#### Immediate (Security)
1. Upgrade {pkg} to {version} — fixes {CVE-ID} ({severity})
#### Short-term (License)
1. Review {pkg} GPL usage — may require license change or removal
#### Medium-term (Maintenance)
1. Find alternative to {pkg} — abandoned since {date}
#### Long-term (Bloat)
1. Remove {pkg} — unused in codebase
2. Replace {pkg} with lighter alternative
### Transitive Risk
- {direct-dep} depends on {transitive-dep} which has {issue}| Problem | Resolution |
|---|---|
| No lock file available | Audit based on declared dependencies. Note that transitive analysis is incomplete without a lock file. |
| License metadata missing | Check the package's repository for LICENSE file. Note packages where license cannot be determined. |
| Package registry unavailable | Work from cached metadata and local lockfile data. |
| Too many dependencies to audit manually | Prioritize: production deps first, then direct deps, then transitive deps with known issues. |
Push back if:
| Rationalization | Reality |
|---|---|
| "It's a trusted package" | Trust is not a security model — trusted packages get compromised (event-stream, ua-parser-js, colors.js) |
| "Only a minor version bump" | Minor versions can introduce vulnerabilities, change behavior, or add transitive dependencies — semver is a promise, not a guarantee |
| "We don't use the vulnerable function" | Transitive dependencies might — and attack surface includes any code loaded into the process |
| "The CVE is low severity" | Low severity in isolation can be critical in your context — a "low" SSRF in an internal service with cloud metadata access is critical |
| "We'll update when there's a known exploit" | Known exploits mean you're already behind — patch within SLA, not after breach |
| "Too many dependencies to audit" | That's the problem, not an excuse — high dependency count IS a risk finding |
npm audit / pip-audit / cargo audit© Mathews-Tom, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 5 other files (references) in skills/dependency-audit of Mathews-Tom/armory.
Open the folder on GitHubat commit 4594fb7
Dependency Audit next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Dependency Audit this skillMathews-Tom/armory | 327 | — | ~2.7k | Automated safety check: Pass | MIT | |
| Codebase Cleanup Deps Auditaiskillstore/marketplace | 430 | 6 repos | ~490 | Automated safety check: Pass | None | |
| Open Source PolicyHack23/cia | 239 | — | ~4.6k | Automated safety check: Pass | Apache-2.0 | |
| Sca TrivyAgentSecOps/SecOpsAgentKit | 219 | 2 repos | ~3.7k | Automated safety check: Pass | Custom licence | |
| Sbom SyftAgentSecOps/SecOpsAgentKit | 219 | 1 repos | ~3.5k | Automated safety check: Pass | Custom licence | |
| Sca Securityhardw00t/ai-security-arsenal | 104 | — | ~3k | Automated safety check: Pass | None |
aiskillstore/marketplace
You are a dependency security expert specializing in vulnerability scanning, license compliance, and supply chain security.
Hack23/cia
Open source governance, security posture badges, license compliance, SBOM generation, and vulnerability management for transparency-driven development
AgentSecOps/SecOpsAgentKit
Software Composition Analysis (SCA) and container vulnerability scanning using Aqua Trivy for identifying CVE vulnerabilities in dependencies, container images, IaC misconfigurations, and license…
AgentSecOps/SecOpsAgentKit
Software Bill of Materials (SBOM) generation using Syft for container images, filesystems, and archives.
hardw00t/ai-security-arsenal
Software Composition Analysis: find vulnerable dependencies, correlate CVE/GHSA/OSV across ecosystems, generate CycloneDX/SPDX SBOMs, assess license compliance, and run reachability-aware triage to…
secondsky/claude-skills
Automated security scanning for dependencies, code, containers with Trivy, Snyk, npm audit.
Mathews-Tom/armory
Architecture reviews across 7 dimensions (structural, scalability, enterprise readiness, performance, security, ops, data) with scored reports.
Mathews-Tom/armory
Turn concepts into static HTML visuals exported as PNG or SVG files via HTML/CSS/SVG.
Mathews-Tom/armory
A skill your agent uses when analyzing an existing video URL or local recording: "watch this video", "analyze youtube video", "summarize this video", "youtube transcript", "find this moment", "what…
Mathews-Tom/armory
Deep code simplification and refactoring preserving behavior across Python, Go, TypeScript, Rust.
Mathews-Tom/armory
Turn concepts into animated explainer videos using Manim (Python) with MP4/GIF output, audio overlay, multi-scene composition.
Mathews-Tom/armory
Maps the unresolved architecture, policy, and scope decisions that must be answered before planning can start: one durable decision ticket per question on the issue tracker, typed and blocker-linked…
Categories
Audits direct and transitive dependencies for license compliance, maintenance health, CVEs, abandoned packages, and bloat. Dependency Audit is an agent skill from Mathews-Tom/armory. Audits direct and transitive dependencies for license compliance, maintenance health, CVEs, abandoned packages, and bloat.
Dependency Audit fits situations like: : audit dependencies; dependency health; abandoned packages; unused dependencies.
Run `npx skills add Mathews-Tom/armory --skill dependency-audit -a claude-code`. Or copy the skill folder (skills/dependency-audit in Mathews-Tom/armory) into .claude/skills/dependency-audit in your project. Claude Code loads it when a task matches its description.
Run `npx skills add Mathews-Tom/armory --skill dependency-audit -a codex`. Or copy the skill folder (skills/dependency-audit in Mathews-Tom/armory) into .agents/skills/dependency-audit in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add Mathews-Tom/armory --skill dependency-audit -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/dependency-audit, .gemini/skills/dependency-audit, .github/skills/dependency-audit and .opencode/skills/dependency-audit in your project.
Going by SKILL.md and its folder, Dependency Audit needs the command-line tools its instructions call (npm, cargo and uv). Our summary lists: Node.js.
SKILL.md contains no URLs. Its commands use npm and uv, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Dependency Audit is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 2.7k tokens (SKILL.md is roughly 11k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 11k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Dependency Audit: Codebase Cleanup Deps Audit (aiskillstore/marketplace, 430 stars), Open Source Policy (Hack23/cia, 239 stars), Sca Trivy (AgentSecOps/SecOpsAgentKit, 219 stars) and Sbom Syft (AgentSecOps/SecOpsAgentKit, 219 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
Mathews-Tom (a GitHub user) maintains it in Mathews-Tom/armory, which has 327 GitHub stars. The repository holds 80 skills in this directory. The repository was last updated on October 6, 2026.
Source: Mathews-Tom/armory on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.