Agent skill

Phx Deps Audit

by oliver-kriska in oliver-kriska/claude-elixir-phoenix

Audit Hex deps for supply-chain security risk — bidi chars, compile-time exec, maintainer changes, typosquats, CVEs.

MITAuto-check passedSecurity

Install Phx Deps Audit

skills CLI
$ npx skills add oliver-kriska/claude-elixir-phoenix --skill phx-deps-audit -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install oliver-kriska/claude-elixir-phoenix phx-deps-audit --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/oliver-kriska/claude-elixir-phoenix.git skills-src && mkdir -p .claude/skills && cp -r skills-src/targets/pi/skills/phx-deps-audit .claude/skills/phx-deps-audit && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
phx-deps-audit
GitHub stars
565
Token cost
~2.2k tokens
SKILL.md length
991 words
Files
30 (incl. scripts, references)
Skills in repo
109
Repo updated
First seen
Licence
MIT

At a glance

Audit Hex deps for supply-chain security risk — bidi chars, compile-time exec, maintainer changes, typosquats, CVEs.

  • Works in 9 steps: Resolve the diff → Fetch tarballs (per-run tmpdir) → Run the 8 MVP rules on each NEW tarball → …
  • Tasks that involve Supply chain security
  • SKILL.md covers When to Use, Iron Laws, Operating Modes and Execution Flow, plus 2 more sections
  • Calls git

What it does

Phx Deps Audit is an agent skill from oliver-kriska/claude-elixir-phoenix. Audit Hex deps for supply-chain security risk — bidi chars, compile-time exec, maintainer changes, typosquats, CVEs. Use after mix deps.update, when checking if a package upgrade is safe, or reviewing mix.lock PR diffs.

Its SKILL.md is about 2.2k tokens, which your agent loads only when the skill is triggered. The skill folder holds 33 other files, including scripts and reference files (for example `priv/semgrep/elixir-supply-chain.yaml`, `references/audit-tmpdir.md` and `references/cassettes.md`).

It sits in Security, covering Supply chain security and Vulnerability scanning. The repository describes itself as: Claude Code plugin for Elixir/Phoenix/LiveView — 26 specialist agents, Iron Laws enforcement, and Tidewave MCP integration. Plan features with parallel research agents, execute… The licence is MIT.

When your agent uses it

  • Tasks that involve Supply chain security
  • Tasks that involve Vulnerability scanning

Example prompts

  • “/phx-deps-audit”

Workflow steps

9 steps, taken from the step headings in SKILL.md.

  1. Resolve the diff
  2. Fetch tarballs (per-run tmpdir)
  3. Run the 8 MVP rules on each NEW tarball
  4. External tool wrappers (parallel)
  5. Hex API enrichment (per package)
  6. 5: Apply hex_vet.exs ledger (if present)
  7. 7: Differential subtract
  8. 8: LLM triage (when score > threshold)
  9. Score & render

What it can do on your machine

Read from SKILL.md and the folder at commit 9767a82. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/, which the agent can run.

    Shell commands in SKILL.md call:

    • git

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use git, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Phx Deps Audit loads about 2.2k tokens when it runs, and up to ~43k if it reads all its reference files. Until then it costs about 59 tokens; SKILL.md has 991 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~59
When it runs · the whole SKILL.md, loaded when a task matches
~2.2k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~43k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from oliver-kriska/claude-elixir-phoenix at commit 9767a82, republished under its MIT licence (© oliver-kriska). 991 words, ~2,163 tokens.

Download SKILL.mdSave it as .claude/skills/phx-deps-audit/SKILL.md (or your agent's skills folder). This skill also uses 29 other files; get the full folder from GitHub.
name
phx-deps-audit
description
Audit Hex deps for supply-chain security risk — bidi chars, compile-time exec, maintainer changes, typosquats, CVEs. Use after mix deps.update, when checking if a package upgrade is safe, or reviewing mix.lock PR diffs.

Hex Dependency Audit

Non-mutating supply-chain audit for Hex packages. Runs an 8-rule MVP catalogue against changed packages, enriches with Hex API metadata, wraps existing tools (mix hex.audit, mix_audit, OSV-Scanner), and emits a triage table.

When to Use

  • After mix deps.update or mix deps.get brought in new versions
  • On PRs that touch mix.lock (pre-merge gate)
  • Before manually updating a single package (--preview <pkg>)
  • When investigating a dependency you don't recognize

Iron Laws

  1. NEVER claim a diff is clean without inspecting it. Run all 8 rules on the unpacked NEW tarball. "Looks fine" without a tool run is a false pass. Always write .claude/deps-audit/last-run.json — its absence is evidence the audit didn't actually run.
  2. NEVER install mix_audit / osv-scanner — even if asked. Detect, warn with install instructions, skip cleanly if missing. If the user says "install it," respond with the install command (e.g., mix deps.add mix_audit --only dev) and do not execute it. The audit skill is non-mutating; mix.exs / mix.lock are off-limits regardless of consent.
  3. NEVER promote a finding to BLOCK without rule citation. Every finding shows rule_id, severity, file:line, snippet, message. No handwaving.
  4. NEVER fetch from Hex API without rate-limiting. Cap at 5 req/sec. Cache metadata 7 days, top-500 list 1 day.
  5. NEVER run the audit on already-committed lock changes silently — tell the user which mode (A/B/C) is active and which (old, new) pairs resolved.
  6. LLM triage only above threshold. Native rules + Semgrep + YARA are deterministic. The hex-deps-triager agent runs only when score

    10 (1 BLOCK or 3+ WARNs), and its verdicts are advisory — never auto-suppress a finding without human review.

Operating Modes

ModeTriggerOld sourceNew source
B (default)/skill:phx-deps-auditgit show HEAD:mix.lockworking mix.lock
C (PR)/skill:phx-deps-audit --base maingit show <ref>:mix.lockworking mix.lock
A (preview)/skill:phx-deps-audit --preview httpoisonlocked versionHex API latest

See references/operating-modes.md for full resolver logic.

Execution Flow

Default = full 8-rule scan with streaming progress. --quick opts out to CVE + retirement only. See references/execution-flow.md.

Step 1: Resolve the diff

Parse the mix.lock Erlang term format for both old and new sources. Emit a list of {pkg, old_version, new_version} tuples. Surface new-only and removed-only packages separately (a removed package is not audited; a brand-new package gets old_version = nil and skips diff-only rules).

See references/diff-resolver.md for shell + mix run -e snippets per mode and the JSON output contract.

Step 2: Fetch tarballs (per-run tmpdir)

For each (pkg, old, new):

mix hex.package fetch <pkg> <old> --unpack -o ${AUDIT_TMPDIR}/tarballs/<pkg>/<old>/
mix hex.package fetch <pkg> <new> --unpack -o ${AUDIT_TMPDIR}/tarballs/<pkg>/<new>/

All ephemeral artifacts live under ${AUDIT_TMPDIR} (driver-owned, removed on exit). See references/audit-tmpdir.md and references/tarball-fetcher.md.

Step 3: Run the 8 MVP rules on each NEW tarball
#RuleSevMethod
1Bidi Unicode control chars in .ex/.exs/.erlBLOCKgrep
2Code.eval_* / :erlang.apply with non-literal MFA at module scopeBLOCKAST (Sourceror or regex+scope)
3System.cmd / :os.cmd / Port.open at compile timeBLOCKAST
4:erlang.binary_to_term/1 on literal without :safeBLOCKAST
5New :git/:path dep in mix.exs (vs old)BLOCKAST diff
6Maintainer change between versionsBLOCKHex API
7Base64 blobs >256 chars outside priv/static/, test/fixtures/, assets/WARNregex
8Levenshtein ≤2 from top-500 + download delta >1000×BLOCKHex API + fuzzy

Full catalogue (35 rules, MVP marked) in references/heuristics.md. Bash + mix run -e implementations for all 8 MVP rules in references/rules-impl.md (single-pass NEW + diff rules + Hex API rules, with run_all_rules master loop).

Step 4: External tool wrappers (parallel)
  • mix hex.audit — retired-package check, always available
  • mix_audit — CVE check via GHSA, if installed (else warn + skip; do NOT install)
  • osv-scanner — CVE check via OSV.dev, if installed (else warn + skip; do NOT install)

See references/external-tools.md for detection, output parsing, and severity mapping per tool.

Show full SKILL.md (404 more words)Show less
Step 5: Hex API enrichment (per package)
  • GET /api/packages/:name — owners, downloads, inserted_at
  • GET /api/packages/:name/releases/:version — per-release publisher
  • Compute: days_since_publish, owner_age_days, download_velocity

Cap at 5 req/sec. Per-run cache under ${AUDIT_TMPDIR}/hex-api/. See references/hex-api.md for endpoint contracts, caching strategy, Rule 6/8 detection, and Levenshtein implementation.

Step 5.5: Apply hex_vet.exs ledger (if present)

If hex_vet.exs exists at project root, vetted-version findings are downgraded to INFO. Unvetted versions retain their severity. Lock-vs-ledger disagreement: lock wins. See the deps-vet skill's hex-vet schema doc for the "Lock-vs-ledger disagreement" section.

Use /skill:phx-deps-vet <pkg> <version> (separate skill) to add entries.

Step 5.7: Differential subtract

When run with DIFFERENTIAL=1 (default), findings that existed in the OLD tarball are downgraded to INFO. Net-new signals reach the renderer at full severity. See references/differential.md.

Step 5.8: LLM triage (when score > threshold)

For packages where the aggregate score exceeds 10, the hex-deps-triager sonnet agent reads finding + diff windows and produces structured verdicts (confidence, verdict, rationale, fp_reasons[]). A context-supervisor consolidates verdicts across packages into triage/consolidated.md. Main skill reads only the consolidated file.

See references/llm-triage.md.

Step 6: Score & render

Per-package weighted sum: BLOCK = 10, WARN = 3, INFO = 1. Risk band: 0 clean · 1–5 low · 6–15 medium · 16+ high.

Output:

  1. Stdout: markdown table — pkg | old → new | risk | findings | diff.hex.pm | maintainer-change plus a per-package detail section for any non-clean row.
  2. Sidecar (MANDATORY): Write .claude/deps-audit/last-run.json. The Phase 3 gate reads this; an audit that doesn't write it is a no-op for the gate. Always emit, even on clean runs.

--json flag emits JSON to stdout instead of markdown. See references/output-renderer.md for table format, sidecar schema, exit-code rubric, and --quiet mode.

Out of scope / Phase 3 surface

  • NEVER modify mix.lock, mix.exs, or any project file (non-mutating)
  • NEVER auto-install missing tools (warn + skip)
  • Gate mix deps.{get,update,compile} via deps-audit-gate.sh. See references/hook.md.
  • Prompt for /skill:phx-compound after BLOCK findings — corpus self-feeds.
  • Emit SARIF 2.1.0 via --sarif <path> and gate CI via --ci.

References

  • references/heuristics.md — full 35-rule catalogue
  • references/rules-impl.md — bash + mix run -e for the 8 MVP rules
  • references/operating-modes.md — Mode A/B/C resolver
  • references/diff-resolver.md — shell snippets, lock parser
  • references/tarball-fetcher.md — fetch wrapper, parallel cap, cache prune
  • references/external-tools.md — mix_audit, osv-scanner wrappers
  • references/hex-api.md — endpoint contracts, rate limit, Rule 6/8
  • references/output-renderer.md — markdown, JSON v1, exit codes, SARIF
  • references/testing.md — smoke runner, fixture matrix
  • references/differential.md / llm-triage.md — Phase 2 NDJSON subtract + triager
  • references/semgrep.md / yara.md — Phase 2 precision layers (soft deps)
  • references/cassettes.md / sarif.md / hook.md / ci-integration.md — Phase 3 surface
  • references/trusted-publishers.md / skill-checklist.md — upstream + eval
  • references/audit-tmpdir.md — Phase 5 per-run ephemeral storage contract
  • references/execution-flow.md / differential-cve.md — Phase 5 default scan + CVE diff

© oliver-kriska, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 29 other files (scripts, references) in targets/pi/skills/phx-deps-audit of oliver-kriska/claude-elixir-phoenix.

  • SKILL.md
  • priv/semgrep/elixir-supply-chain.yaml
  • priv/yara/hex-malware.yar
  • references/audit-tmpdir.md
  • references/cassettes.md
  • references/ci-integration.md
  • references/diff-resolver.md
  • references/differential-cve.md
  • references/differential.md
  • references/execution-flow.md
  • references/external-tools.md
  • references/heuristics.md
  • references/hex-api.md
  • references/hook.md
  • references/llm-triage.md
  • references/operating-modes.md
  • references/output-renderer.md
  • … and 13 more

Open the folder on GitHubat commit 9767a82

Compare with similar skills

Phx Deps Audit next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Phx Deps Audit compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Phx Deps Audit this skilloliver-kriska/claude-elixir-phoenix565—~2.2kAutomated safety check: PassMIT
Warp Vulnerability Triagewarpdotdev/warp65k1 repos~2.1kAutomated safety check: PassAGPL-3.0
Dependency Triagecobusgreyling/loop-engineering11k—~626Automated safety check: PassMIT
Container Scanning with GrypeAgentSecOps/SecOpsAgentKit2201 repos~2.5kAutomated safety check: PassCustom licence
Kesekit Startcdppcorp/KESE-KIT360—~2.3kAutomated safety check: PassMIT
Snapshotboostsecurityio/poutine523—~214Automated safety check: PassApache-2.0

Similar skills

  • Gathers security findings from Dependabot, GCP container scanning, Docker Scout and Linear security issues, then triages and remediates them across Warp's repos and images.

    65k GitHub starsUsed in 1 repo~2.1k tokens
    SecurityAuto-check passed
  • Dependency Triage

    cobusgreyling/loop-engineering

    Scans package manifests and lockfiles for outdated packages and known CVEs, then classifies each possible update as patch, minor, major or escalate-human for a dependency sweeper loop.

    11k GitHub stars~626 tokensUpdated today
    SecurityAuto-check passed
  • Container Scanning with Grype

    AgentSecOps/SecOpsAgentKit

    Scans container images, filesystems and SBOMs with Grype for known vulnerabilities, ranks them by CVSS, EPSS and CISA KEV, and wires scans into CI/CD thresholds.

    220 GitHub starsUsed in 1 repo~2.5k tokens
    SecurityAuto-check passed
  • Kesekit Start

    cdppcorp/KESE-KIT

    Run a security vulnerability assessment based on KISA guidelines.

    360 GitHub stars~2.3k tokensUpdated 6 mo ago
    SecurityAuto-check passed
  • Snapshot

    boostsecurityio/poutine

    Run snapshot regression tests after changes to OPA rules, scanners, analyzers, or formatters to detect output regressions.

    523 GitHub stars~214 tokensUpdated yesterday
    SecurityAuto-check passed
  • Container Security

    hardw00t/ai-security-arsenal

    Container and Kubernetes security assessment — image vulnerability scanning, SBOM diff analysis, K8s cluster auditing, RBAC privilege mapping, NetworkPolicy review, container escape testing, and…

    105 GitHub stars~2.8k tokensUpdated 5 mo ago
    SecurityAuto-check passed

More from oliver-kriska/claude-elixir-phoenix

All 109 skills in this repo
  • Codex Ab

    oliver-kriska/claude-elixir-phoenix

    Run an A/B codex review experiment — holistic codex review vs 3 focused dimension passes (security, ecto, liveview) on the branch diff, classify findings, report a panel-value verdict.

    565 GitHub stars~977 tokensUpdated 5 days ago
    Auto-check passed
  • Audit

    oliver-kriska/claude-elixir-phoenix

    Project health audit and health check — architecture, performance, tests, dependencies, code quality.

    565 GitHub stars~2k tokensUpdated 5 days ago
    Auto-check passed
  • Compound Docs

    oliver-kriska/claude-elixir-phoenix

    Searchable Elixir/Phoenix/Ecto solution documentation system with; Use when consulting past solutions…

    565 GitHub stars~528 tokensUpdated 5 days ago
    Auto-check passed
  • Compound Docs

    oliver-kriska/claude-elixir-phoenix

    Searchable Elixir/Phoenix/Ecto solution documentation system with YAML frontmatter.

    565 GitHub stars~547 tokensUpdated 5 days ago
    Auto-check passed
  • Deploy

    oliver-kriska/claude-elixir-phoenix

    Elixir/Phoenix deployment patterns — Dockerfile, fly.toml, runtime.exs, mix release, rel/ overlays.

    565 GitHub stars~1.1k tokensUpdated 5 days ago
    Auto-check passed
  • Deps Update

    oliver-kriska/claude-elixir-phoenix

    Bump outdated Hex deps — inventory, snapshot changelogs, update, fix breaks, split reviewable PRs (patches bundled, majors solo).

    565 GitHub stars~1.4k tokensUpdated 5 days ago
    Auto-check passed

Categories

Questions about Phx Deps Audit

What does Phx Deps Audit do?

Audit Hex deps for supply-chain security risk — bidi chars, compile-time exec, maintainer changes, typosquats, CVEs. Phx Deps Audit is an agent skill from oliver-kriska/claude-elixir-phoenix. Audit Hex deps for supply-chain security risk — bidi chars, compile-time exec, maintainer changes, typosquats, CVEs.

When should I use Phx Deps Audit?

Phx Deps Audit fits situations like: tasks that involve Supply chain security; tasks that involve Vulnerability scanning.

How do I install Phx Deps Audit in Claude Code?

Run `npx skills add oliver-kriska/claude-elixir-phoenix --skill phx-deps-audit -a claude-code`. Or copy the skill folder (targets/pi/skills/phx-deps-audit in oliver-kriska/claude-elixir-phoenix) into .claude/skills/phx-deps-audit in your project. Claude Code loads it when a task matches its description.

How do I install Phx Deps Audit in Codex?

Run `npx skills add oliver-kriska/claude-elixir-phoenix --skill phx-deps-audit -a codex`. Or copy the skill folder (targets/pi/skills/phx-deps-audit in oliver-kriska/claude-elixir-phoenix) into .agents/skills/phx-deps-audit in your project. Codex loads it when a task matches its description.

Can I use Phx Deps Audit in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add oliver-kriska/claude-elixir-phoenix --skill phx-deps-audit -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/phx-deps-audit, .gemini/skills/phx-deps-audit, .github/skills/phx-deps-audit and .opencode/skills/phx-deps-audit in your project.

What does Phx Deps Audit need to run?

Going by SKILL.md and its folder, Phx Deps Audit needs the command-line tools its instructions call (git).

Does Phx Deps Audit access the network?

SKILL.md contains no URLs. Its commands use git, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Phx Deps Audit safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Phx Deps Audit use?

Phx Deps Audit is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Phx Deps Audit use?

About 2.2k tokens (SKILL.md is roughly 8.7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 41k tokens, read only when the agent opens those files.

What are the alternatives to Phx Deps Audit?

Skills that share tags, products or a category with Phx Deps Audit: Warp Vulnerability Triage (warpdotdev/warp, 65k stars), Dependency Triage (cobusgreyling/loop-engineering, 11k stars), Container Scanning with Grype (AgentSecOps/SecOpsAgentKit, 220 stars) and Kesekit Start (cdppcorp/KESE-KIT, 360 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Phx Deps Audit?

oliver-kriska (a GitHub user) maintains it in oliver-kriska/claude-elixir-phoenix, which has 565 GitHub stars. The repository holds 109 skills in this directory. The repository was last updated on October 5, 2026.

Source: oliver-kriska/claude-elixir-phoenix on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.