Agent skill

Dependency Audit

by mohitagw15856 in mohitagw15856/pm-claude-skills

Audits project dependencies for security vulnerabilities, license compliance issues, outdated packages, and transitive dependency risk.

MITAuto-check passedLegal & Compliance

Install Dependency Audit

skills CLI
$ npx skills add mohitagw15856/pm-claude-skills --skill dependency-audit -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install mohitagw15856/pm-claude-skills dependency-audit --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/mohitagw15856/pm-claude-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/dependency-audit .claude/skills/dependency-audit && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
dependency-audit
GitHub stars
1.4k
Token cost
~3.7k tokens
SKILL.md length
1,445 words
Files
1
Skills in repo
1,348
Repo updated
First seen
Licence
MIT

At a glance

Audits project dependencies for security vulnerabilities, license compliance issues, outdated packages, and transitive dependency risk.

  • Works in 7 steps: Security Vulnerability Findings → License Compliance Matrix → Outdated Package Analysis → …
  • Asked to audit dependencies
  • SKILL.md covers Required Inputs, Output Format, Executive Summary and 1. Security Vulnerability…, plus 7 more sections
  • Calls npm, go and pip

What it does

Dependency Audit is an agent skill from mohitagw15856/pm-claude-skills. Audits project dependencies for security vulnerabilities, license compliance issues, outdated packages, and transitive dependency risk. Use when asked to audit dependencies, review package security, check license compliance, assess dependency health, or produce a vulnerability report. Produces a vulnerability findings table, license compliance matrix, update priority matrix, dependency health score, and 30-day remediation plan.

Its SKILL.md is about 3.7k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Legal & Compliance, covering Regulatory compliance and Customer success. It works with npm. The repository describes itself as: 1255 professional Agent Skills for Claude, ChatGPT, Gemini, Cursor & Codex — PRDs, postmortems, leases, medical bills, layoffs, go-bags, new countries. Plain markdown, MIT, in… The licence is MIT.

When your agent uses it

  • Asked to audit dependencies
  • Review package security
  • Check license compliance
  • Assess dependency health

Example prompts

  • “Use the dependency-audit skill to audit project dependencies for security vulnerabilities, license compliance issues, outdated packages, and…”
  • “/dependency-audit”

Requirements

  • Python 3
  • Node.js

Workflow steps

7 steps, taken from the step headings in SKILL.md.

  1. Security Vulnerability Findings
  2. License Compliance Matrix
  3. Outdated Package Analysis
  4. Dependency Graph Risk Analysis
  5. Remediation Plan
  6. Policy Recommendations
  7. Dependency Health Score Detail

What it can do on your machine

Read from SKILL.md and the folder at commit 1cbf1f0. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • npm
    • go
    • pip
    • mvn
    • npx

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use npm, pip and npx, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Dependency Audit loads about 3.7k tokens when it runs. Until then it costs about 112 tokens; SKILL.md has 1,445 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~112
When it runs · the whole SKILL.md, loaded when a task matches
~3.7k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from mohitagw15856/pm-claude-skills at commit 1cbf1f0, republished under its MIT licence (© mohitagw15856). 1,445 words, ~3,724 tokens.

Download SKILL.mdSave it as .claude/skills/dependency-audit/SKILL.md (or your agent's skills folder).
name
dependency-audit
description
Audits project dependencies for security vulnerabilities, license compliance issues, outdated packages, and transitive dependency risk. Use when asked to audit dependencies, review package security, check license compliance, assess dependency health, or produce a vulnerability report. Produces a vulnerability findings table, license compliance matrix, update priority matrix, dependency health score, and 30-day remediation plan.

Dependency Audit Skill

Produce a complete dependency audit report for a project — covering security vulnerabilities (with CVE references), license compliance against policy, outdated packages prioritised by risk, transitive dependency risk analysis, and a concrete remediation plan with timeline. A good dependency audit gives the team a clear, prioritised action list — not a raw dump of audit output that no one acts on.

Required Inputs

Ask for these if not already provided:

  • Project language and ecosystem — npm, pip/PyPI, Maven/Gradle, Go modules, Cargo, RubyGems, NuGet, or mixed
  • Dependency list or package manifest — paste the contents of package.json, requirements.txt, go.mod, pom.xml, etc., or provide the audit tool output
  • License policy — which licenses are allowed, which are restricted (e.g. "GPL is prohibited", "MIT/Apache/BSD only", or "no policy yet — recommend one")
  • Current security tooling — Dependabot, Snyk, OWASP Dependency-Check, npm audit, pip-audit, or none

Output Format


Dependency Audit Report: [Project Name]

Ecosystem: [npm / pip / Maven / Go / etc.] Audit date: [Date] Auditor: [Name] Total direct dependencies: [N] Total transitive dependencies: [N] Audit tool(s) used: [npm audit / pip-audit / Snyk / OWASP Dependency-Check / etc.]


Executive Summary

CategoryFindingRisk level
Critical vulnerabilities[N] CVEs requiring immediate action[Critical / High / Low]
High vulnerabilities[N] CVEs — fix within 7 days[High / Medium]
License violations[N] packages with non-compliant licenses[High / Low]
Severely outdated packages[N] packages > 2 major versions behind[Medium]
Packages with no active maintenance[N] packages — no commits in 12+ months[Medium]
Overall dependency health score[Score]/100[Red / Amber / Green]

Scoring methodology: Critical CVEs: −20 each. High CVEs: −10 each. License violations: −15 each. Abandoned packages: −5 each. Maximum deduction: 100. Score ≥80 = Green, 60–79 = Amber, <60 = Red.

Immediate actions required:

  1. [Most critical action — e.g. "Upgrade lodash from 4.17.11 to 4.17.21 to fix CVE-2021-23337 (Critical — prototype pollution)"]
  2. [Second action]
  3. [Third action]

1. Security Vulnerability Findings

Critical and High Severity (Act within 24–72 hours)
PackageInstalled versionFix versionCVESeverityCVSS scoreDescriptionExploitability
[package-name][X.Y.Z][A.B.C][CVE-YYYY-NNNNN]Critical[9.x][e.g. Prototype pollution via merge function — remote code execution possible][Known exploit / PoC available / No known exploit]
[package-name][X.Y.Z][A.B.C][CVE-YYYY-NNNNN]High[7.x][e.g. Path traversal in file serving utility][PoC available]
[package-name][X.Y.Z][A.B.C][CVE-YYYY-NNNNN]High[7.x][e.g. Regular expression denial of service (ReDoS)][No known exploit]
Medium Severity (Fix within 30 days)
PackageInstalled versionFix versionCVESeverityCVSS scoreDescription
[package-name][X.Y.Z][A.B.C][CVE-YYYY-NNNNN]Medium[5.x][Description]
[package-name][X.Y.Z][A.B.C][CVE-YYYY-NNNNN]Medium[4.x][Description]
Low Severity (Fix within 90 days or accept risk)
PackageInstalled versionFix versionCVESeverityDescription
[package-name][X.Y.Z][A.B.C]Low[Description]
Vulnerabilities With No Fix Available
PackageCVESeverityRecommended mitigation
[package-name][CVE-YYYY-NNNNN][High][e.g. "Remove this package — alternative: [replacement]"]
[package-name][CVE-YYYY-NNNNN][Medium][e.g. "Vendor has a fix in progress — track issue [URL]. Mitigate by [X]"]

2. License Compliance Matrix

License Policy Reference
LicenseCategoryPolicyNotes
MITPermissiveAllowedAttribution required in distributed products
Apache 2.0PermissiveAllowedAttribution + NOTICE file required
BSD 2-Clause / 3-ClausePermissiveAllowedAttribution required
ISCPermissiveAllowed
MPL 2.0Weak copyleftAllowed with reviewSource disclosure required for modified MPL files only
LGPL v2 / v3Weak copyleftAllowed with reviewDynamic linking permitted; static linking may require disclosure
GPL v2 / v3Strong copyleftRestrictedMay require open-sourcing the entire codebase — legal review required
AGPL v3Strong copyleftRestrictedNetwork use triggers copyleft — especially risky for SaaS
SSPLSource availableProhibitedNot OSI-approved — treat as proprietary
Proprietary / CommercialCommercialRequires contractVerify license covers current use case and scale
Unknown / Unlicensed—ProhibitedNo license = all rights reserved — cannot use legally
Findings: Packages With Compliance Issues
PackageLicenseIssueRecommendationRisk if unaddressed
[package-name]GPL v3Copyleft — may require open-sourcing this projectReplace with [alternative] or get legal sign-offLegal / IP risk
[package-name]AGPL v3Network copyleft — SaaS use triggers disclosureReplace with [alternative]Legal / IP risk
[package-name]ProprietaryLicense may not cover current usage tierVerify license scope with vendorContract breach
[package-name]UnknownNo license declared in package metadataContact maintainer or replaceCannot use legally
All Licenses in Use (Full Inventory)
LicensePackage countCompliance status
MIT[N]Compliant
Apache 2.0[N]Compliant
BSD-3-Clause[N]Compliant
ISC[N]Compliant
MPL 2.0[N]Review required
GPL v3[N]Non-compliant
Unknown[N]Non-compliant

3. Outdated Package Analysis

Severely Outdated (2+ major versions behind — high upgrade effort)
PackageInstalledLatest stableVersions behindLast updatedBreaking changes summary
[package-name][1.x.x][3.x.x]2 major[Date][e.g. "API redesign in v2; async support added in v3"]
[package-name][0.x.x][2.x.x]2 major[Date][Summary]
Moderately Outdated (1 major version behind)
PackageInstalledLatest stableVersions behindSecurity fix in newer version?
[package-name][2.x.x][3.x.x]1 major[Yes — CVE-YYYY-NNNNN / No]
[package-name][4.x.x][5.x.x]1 major[No]
Minor/Patch Updates Available (Low risk to update)
PackageInstalledLatestContains security fix?
[package-name][2.3.1][2.3.9][Yes / No]
[package-name][1.0.0][1.2.1][No]

4. Dependency Graph Risk Analysis

Transitive Dependency Risk

Transitive (indirect) dependencies carry risk because they are not explicitly managed. These are the highest-risk transitive dependencies in this project:

Vulnerable transitive depPulled in byInstalled versionFix availableAction
[transitive-package][direct-parent][X.Y.Z][Yes — upgrade [parent] to [version]]Upgrade direct dependency [parent]
[transitive-package][direct-parent][X.Y.Z][No]Remove [parent] or use [alternative]
Show full SKILL.md (585 more words)Show less
Dependency Concentration Risk

These packages are depended on by many other packages in the project — a vulnerability or deprecation would have cascading effects:

PackageDepended on by (N packages)Actively maintained?Risk level
[package-name][N][Yes / No — last commit: date][High / Medium]
[package-name][N][Yes][Medium]
Abandoned / Unmaintained Packages
PackageLast releaseLast commitWeekly downloadsRecommended alternative
[package-name][Date][Date][N][alternative-package]
[package-name][Date][Date][N][Maintained fork: URL]

5. Remediation Plan

30-Day Plan

Week 1 — Critical vulnerabilities (Days 1–7)

ActionOwnerPackageEffortNotes
Upgrade [package] [old] → [new][Name][package-name][30 min][No API changes / check breaking changes guide: URL]
Replace [package] with [alternative][Name][package-name][2 hours][No fix available — must replace]
Patch override for [transitive-dep][Name][transitive-dep][15 min][Add resolutions/overrides entry in manifest]
bash
# Commands for Week 1 upgrades:

# npm
npm install [package]@[target-version]
npm audit fix --force  # use with caution — may introduce breaking changes

# pip
pip install --upgrade [package]==[target-version]
pip-audit --fix  # if using pip-audit

# Go
go get [module]@[version]
go mod tidy

# Maven
# Update pom.xml version property, then:
mvn versions:use-latest-releases -DallowMajorUpdates=false
mvn dependency:resolve

Week 2 — High vulnerabilities and license violations (Days 8–14)

ActionOwnerPackageEffortNotes
Upgrade [package][Name][package-name][1 hour]
Replace GPL-licensed [package][Name][package-name][4 hours][Alternative: [package]]
Legal review for [package] licenseLegal team[package-name][Legal team SLA][Submit via [process]]

Week 3 — Medium vulnerabilities and abandoned packages (Days 15–21)

ActionOwnerPackageEffortNotes
Upgrade [package][Name][package-name][30 min]
Replace abandoned [package][Name][package-name][2 hours][Maintained fork or alternative: [URL]]

Week 4 — Process improvements (Days 22–30)

ActionOwnerEffortNotes
Enable Dependabot / Renovate for automated PRs[Name][2 hours][Config in Section 6]
Add npm audit / pip-audit to CI — fail on Critical/High[Name][1 hour][Config in Section 6]
Document license policy in CONTRIBUTING.md[Name][1 hour][Based on policy in Section 2]
Schedule next quarterly audit[Name][15 min][Add to team calendar]

6. Policy Recommendations

Automated Vulnerability Scanning in CI

Add the following to your CI pipeline to catch vulnerabilities before they merge:

yaml
# GitHub Actions — adapt for your CI platform
dependency-audit:
  runs-on: ubuntu-latest
  steps:
    - uses: actions/checkout@v3

    # npm
    - name: npm audit
      run: npm audit --audit-level=high
      # Fails build on High or Critical vulnerabilities

    # pip
    - name: pip-audit
      run: |
        pip install pip-audit
        pip-audit --requirement requirements.txt --severity high

    # Go
    - name: govulncheck
      run: |
        go install golang.org/x/vuln/cmd/govulncheck@latest
        govulncheck ./...
Dependabot / Renovate Configuration
yaml
# .github/dependabot.yml — automated dependency update PRs
version: 2
updates:
  - package-ecosystem: "[npm / pip / gomod / maven]"
    directory: "/"
    schedule:
      interval: "weekly"
      day: "monday"
    open-pull-requests-limit: 10
    labels:
      - "dependencies"
      - "automated"
    ignore:
      # Ignore major version bumps — review these manually
      - dependency-name: "*"
        update-types: ["version-update:semver-major"]
License Scanning
bash
# npm — license checker
npx license-checker --onlyAllow 'MIT;Apache-2.0;BSD-2-Clause;BSD-3-Clause;ISC' \
  --failOn 'GPL;AGPL;LGPL'

# Python — pip-licenses
pip install pip-licenses
pip-licenses --allow-only="MIT;Apache Software License;BSD License;ISC License" \
  --fail-on="GNU General Public License"

# Go — go-licenses
go install github.com/google/go-licenses@latest
go-licenses check ./... --allowed_licenses=MIT,Apache-2.0,BSD-2-Clause,BSD-3-Clause

7. Dependency Health Score Detail

CategoryMax pointsScoreNotes
No critical vulnerabilities30[N]/30−20 per critical CVE
No high vulnerabilities20[N]/20−10 per high CVE
License compliance20[N]/20−15 per violation
No abandoned packages15[N]/15−5 per abandoned package
Up-to-date major versions10[N]/10−2 per major version behind
Automated scanning enabled5[N]/5All-or-nothing
Total100[Score]/100[Red / Amber / Green]

Quality Checks

  • Every Critical and High CVE has a named owner and a resolution date in the 30-day plan
  • License findings have been reviewed by legal or a named engineer with authority to accept the risk
  • Transitive dependency vulnerabilities are included — not just direct dependencies
  • Abandoned packages have a concrete replacement recommendation, not just "consider replacing"
  • CI pipeline change is included — the audit findings should be the last time these are caught manually
  • The dependency health score is calculated from actual findings, not estimated
  • Remediation plan actions are specific commands or steps, not "upgrade package X" without version targets

Anti-Patterns

  • Do not report only direct dependencies — transitive dependency vulnerabilities are often more dangerous and are the most commonly missed
  • Do not present raw audit tool output without interpretation — a table of 200 CVEs with no prioritisation is worse than no audit at all
  • Do not assign all Critical CVEs as "fix immediately" without checking whether an exploitable path exists in your usage context
  • Do not make license compliance decisions without legal input — flagging a GPL dependency without a recommendation is incomplete work
  • Do not complete the audit without including a CI/CD pipeline step — a one-time audit that leaves the door open for new vulnerabilities is not a remediation

Example Trigger Phrases

  • "Audit dependencies."
  • "Review package security."
  • "Check license compliance."
  • "Assess dependency health."
  • "Produce a vulnerability report."

© mohitagw15856, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/dependency-audit of mohitagw15856/pm-claude-skills.

Open the folder on GitHubat commit 1cbf1f0

Compare with similar skills

Dependency Audit next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Dependency Audit compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Dependency Audit this skillmohitagw15856/pm-claude-skills1.4k—~3.7kAutomated safety check: PassMIT
Dependency Auditoralirezarezvani/claude-skills28k—~1.1kAutomated safety check: PassMIT
Checking License Compliancejeremylongshore/tons-of-skills-marketplace2.8k—~2.1kAutomated safety check: NotesMIT
Dependency Audit Assistantaiskillstore/marketplace430—~2.2kAutomated safety check: NotesNone
Dependency Managementaiskillstore/marketplace4301 repos~1.1kAutomated safety check: PassNone
HIPAA Pre-Deployment Compliance Checkmaziyarpanahi/openmed5.5k—~2kAutomated safety check: PassApache-2.0

Similar skills

  • Dependency Auditor

    alirezarezvani/claude-skills

    Audit and manage dependencies across multi-language projects.

    28k GitHub stars~1.1k tokensUpdated 1 mo ago
    Legal & ComplianceAuto-check passed
  • Checking License Compliance

    jeremylongshore/tons-of-skills-marketplace

    Audit a project's dependency licenses against an explicit policy (allow-list / deny-list / review-required) and flag incompatibilities before they ship to production.

    2.8k GitHub stars~2.1k tokensUpdated today
    Legal & ComplianceAuto-check: notes
  • Dependency Audit Assistant

    aiskillstore/marketplace

    Reviews package dependencies for security vulnerabilities, outdated versions, and license compliance.

    430 GitHub stars~2.2k tokensUpdated today
    SecurityAuto-check: notes
  • Dependency Management

    aiskillstore/marketplace

    Dependency management specialist. An agent skill from aiskillstore/marketplace.

    430 GitHub starsUsed in 1 repo~1.1k tokens
    DevelopmentAuto-check passed
  • Walks a data pipeline against the HIPAA Privacy and Security Rule checklist and produces a gap report before it processes patient data.

    5.5k GitHub stars~2k tokensUpdated today
    Legal & ComplianceAuto-check passed
  • Hipaa Compliance

    Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

    Expert HIPAA compliance assistant for healthcare and software contexts.

    943 GitHub starsUsed in 1 repo~2.3k tokens
    Legal & ComplianceAuto-check passed

More from mohitagw15856/pm-claude-skills

All 1,348 skills in this repo
  • Car Tco

    mohitagw15856/pm-claude-skills

    Compare the total cost of car ownership across buy-new, buy-used, lease, and keep-your-current-car — depreciation, insurance, maintenance ramp, and fuel over a real horizon, not just the monthly…

    1.4k GitHub stars~1.1k tokensUpdated yesterday
    Auto-check passed
  • Cs Health Scorecard

    mohitagw15856/pm-claude-skills

    Build a customer health scorecard for a specific account. An agent skill from mohitagw15856/pm-claude-skills.

    1.4k GitHub stars~2.4k tokensUpdated yesterday
    Auto-check passed
  • Exit Waterfall

    mohitagw15856/pm-claude-skills

    Compute who gets what at each exit price from a cap table — liquidation preferences, conversion points, and where the founders' share collapses.

    1.4k GitHub stars~1.1k tokensUpdated yesterday
    Auto-check passed
  • Feature Prioritisation

    mohitagw15856/pm-claude-skills

    Apply prioritisation frameworks (RICE, MoSCoW, Kano, ICE, Opportunity Scoring) to rank features and backlog items.

    1.4k GitHub stars~2k tokensUpdated yesterday
    Auto-check passed
  • Fire Number

    mohitagw15856/pm-claude-skills

    Compute a financial-independence (FIRE) target and years-to-reach with every assumption labeled as an assumption — plus a sensitivity table instead of a single false-precision answer.

    1.4k GitHub stars~1.1k tokensUpdated yesterday
    Auto-check passed
  • Freelance Rate

    mohitagw15856/pm-claude-skills

    Derive a freelance day/hourly rate backwards from target income, honest billable utilization, overhead, and the self-employment tax premium — the arithmetic that proves a rate is not salary÷2000.

    1.4k GitHub stars~1.2k tokensUpdated yesterday
    Auto-check passed

Works with

Questions about Dependency Audit

What does Dependency Audit do?

Audits project dependencies for security vulnerabilities, license compliance issues, outdated packages, and transitive dependency risk. Dependency Audit is an agent skill from mohitagw15856/pm-claude-skills. Audits project dependencies for security vulnerabilities, license compliance issues, outdated packages, and transitive dependency risk.

When should I use Dependency Audit?

Dependency Audit fits situations like: asked to audit dependencies; review package security; check license compliance; assess dependency health.

How do I install Dependency Audit in Claude Code?

Run `npx skills add mohitagw15856/pm-claude-skills --skill dependency-audit -a claude-code`. Or copy the skill folder (skills/dependency-audit in mohitagw15856/pm-claude-skills) into .claude/skills/dependency-audit in your project. Claude Code loads it when a task matches its description.

How do I install Dependency Audit in Codex?

Run `npx skills add mohitagw15856/pm-claude-skills --skill dependency-audit -a codex`. Or copy the skill folder (skills/dependency-audit in mohitagw15856/pm-claude-skills) into .agents/skills/dependency-audit in your project. Codex loads it when a task matches its description.

Can I use Dependency Audit in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add mohitagw15856/pm-claude-skills --skill dependency-audit -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/dependency-audit, .gemini/skills/dependency-audit, .github/skills/dependency-audit and .opencode/skills/dependency-audit in your project.

What does Dependency Audit need to run?

Going by SKILL.md and its folder, Dependency Audit needs the command-line tools its instructions call (npm, go, pip, mvn and npx). Our summary lists: Python 3; Node.js.

Does Dependency Audit access the network?

SKILL.md contains no URLs. Its commands use npm, pip and npx, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Dependency Audit safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Dependency Audit use?

Dependency Audit is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Dependency Audit use?

About 3.7k tokens (SKILL.md is roughly 15k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Dependency Audit?

Skills that share tags, products or a category with Dependency Audit: Dependency Auditor (alirezarezvani/claude-skills, 28k stars), Checking License Compliance (jeremylongshore/tons-of-skills-marketplace, 2.8k stars), Dependency Audit Assistant (aiskillstore/marketplace, 430 stars) and Dependency Management (aiskillstore/marketplace, 430 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Dependency Audit?

mohitagw15856 (a GitHub user) maintains it in mohitagw15856/pm-claude-skills, which has 1,433 GitHub stars. The repository holds 1,348 skills in this directory. The repository was last updated on October 8, 2026.

Source: mohitagw15856/pm-claude-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.