Record a vetted Hex package version in hexvet.exs after a security review — manages the audit ledger, not the scanner.

MITAuto-check passedSecurity

Install Phx Deps Vet

skills CLI
$ npx skills add oliver-kriska/claude-elixir-phoenix --skill phx-deps-vet -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install oliver-kriska/claude-elixir-phoenix phx-deps-vet --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/oliver-kriska/claude-elixir-phoenix.git skills-src && mkdir -p .claude/skills && cp -r skills-src/targets/amp/skills/phx-deps-vet .claude/skills/phx-deps-vet && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
phx-deps-vet
GitHub stars
565
Token cost
~1.5k tokens
SKILL.md length
608 words
Files
4 (incl. references)
Skills in repo
109
Repo updated
First seen
Licence
MIT

At a glance

Record a vetted Hex package version in hexvet.exs after a security review — manages the audit ledger, not the scanner.

  • Works in 7 steps: Locate or seed hex_vet.exs → Branch by mode → Fetch the tarball (single-vet) → …
  • Approve a dep after phx-deps-audit findings
  • SKILL.md covers Usage, Iron Laws, Execution flow and Integration, plus 2 more sections
  • Runs Elixir scripts from its folder

What it does

Phx Deps Vet is an agent skill from oliver-kriska/claude-elixir-phoenix. Record a vetted Hex package version in hexvet.exs after a security review — manages the audit ledger, not the scanner. Use to approve a dep after phx-deps-audit findings or to initialize hexvet.exs.

Its SKILL.md is about 1.5k tokens, which your agent loads only when the skill is triggered. The skill folder holds 5 other files, including reference files (for example `references/hex-vet.md` and `references/seed.md`).

It sits in Security, covering Security review and Audit readiness. The repository describes itself as: Claude Code plugin for Elixir/Phoenix/LiveView — 26 specialist agents, Iron Laws enforcement, and Tidewave MCP integration. Plan features with parallel research agents, execute… The licence is MIT.

When your agent uses it

  • Approve a dep after phx-deps-audit findings
  • Initialize hexvet.exs

Example prompts

  • “/phx-deps-vet”

Workflow steps

7 steps, taken from the step headings in SKILL.md.

  1. Locate or seed hex_vet.exs
  2. Branch by mode
  3. Fetch the tarball (single-vet)
  4. Run Phase 1 rules
  5. Present findings
  6. Prompt for verdict
  7. Append to ledger

What it can do on your machine

Read from SKILL.md and the folder at commit 9767a82. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships script files (Elixir), which the agent can run.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Phx Deps Vet loads about 1.5k tokens when it runs, and up to ~5.5k if it reads all its reference files. Until then it costs about 53 tokens; SKILL.md has 608 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~53
When it runs · the whole SKILL.md, loaded when a task matches
~1.5k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~5.5k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from oliver-kriska/claude-elixir-phoenix at commit 9767a82, republished under its MIT licence (© oliver-kriska). 608 words, ~1,488 tokens.

Download SKILL.mdSave it as .claude/skills/phx-deps-vet/SKILL.md (or your agent's skills folder). This skill also uses 3 other files; get the full folder from GitHub.
name
phx-deps-vet
description
Record a vetted Hex package version in hex_vet.exs after a security review — manages the audit ledger, not the scanner. Use to approve a dep after phx-deps-audit findings or to initialize hex_vet.exs.

Deps Vet — Hex package audit ledger

Review a Hex package version, run Phase 1 supply-chain rules against it, prompt the user for a verdict, append the result to hex_vet.exs (project-root audit ledger). Vetted versions get downgraded to INFO on subsequent phx-deps-audit runs.

Run this AFTER phx-deps-audit to clear findings. Run this BEFORE merging a mix.lock PR to certify new versions.

Usage

text
phx-deps-vet phoenix 1.7.21      # vet a single package version
phx-deps-vet --seed              # import curated baseline seed (~30 pkgs)
phx-deps-vet --list              # show existing ledger entries
phx-deps-vet --check             # cross-check mix.lock vs ledger

Iron Laws

  1. NEVER auto-approve. Every entry MUST come from an AskUserQuestion confirmation. Drive-by trust ruins the ledger's value.
  2. Lock wins on disagreement. If mix.lock has version X and the ledger vets X-1, emit INFO and treat X as unvetted. Don't silently trust the older entry.
  3. Ledger lives at project root. hex_vet.exs is a first-class security artifact, visible in PR review. Don't move it into .claude/.
  4. Round-trip via inspect/2. When appending, read the file with Code.eval_file/1, mutate the map, and write back via inspect(term, pretty: true, limit: :infinity). Hand-rolled string appends drift over time.
  5. Always show findings before prompting. The user must see what's being vetted. No silent :safe_to_deploy defaults.
  6. Confirmation counts are COMPUTED, never estimated. Any number in an AskUserQuestion (criteria split, new/overwrite/no-op) MUST be derived from the loaded data before prompting — e.g. Enum.frequencies_by(seed.audits, & &1.criteria). Eyeballing the file and approving on wrong numbers corrupts the consent.

Execution flow

Step 1: Locate or seed hex_vet.exs
text
If hex_vet.exs exists at project root:
    Read it via Code.eval_file/1
Else:
    Write the empty-ledger stub (see references/hex-vet.md §"Empty ledger")
    Inform user: "Created hex_vet.exs at project root."
Step 2: Branch by mode
  • <pkg> <version> → single-vet path (Step 3-7).
  • --seed → import priv/hex_vet_seed.exs. Before prompting, Code.eval_file/1 the seed and compute (Iron Law #6): the criteria split (Enum.frequencies_by(seed.audits, & &1.criteria)) and, against any existing ledger, exact new / overwrite / no-op counts. Put those computed numbers in the AskUserQuestion. Also state up front that the seed is a provenance baseline, not certification of your current mix.lock (per Iron Law #2, seed versions older than the locked ones stay unvetted). Ask before overwriting existing entries.
  • --list → render the audits table; exit.
  • --check → compare ledger entries with mix.lock; warn on drift. Read the lock via Code.eval_file("mix.lock") with 2>/dev/null — modern locks have quoted keys and emit a found quoted keyword warning per package (tens of KB of noise that gets persisted as an oversized tool result otherwise).
Step 3: Fetch the tarball (single-vet)

Run the deps-audit corpus loader. Cache lives at ~/.cache/phx-deps-audit/corpus/<pkg>/<version>/contents/. Use:

text
bash ../phx-deps-audit/scripts/fetch_tarball.sh \
    <pkg> <version>
Show full SKILL.md (240 more words)Show less
Step 4: Run Phase 1 rules

Source the rules from ../phx-deps-audit/references/rules-impl.md. Run run_all_rules over the cached dir. Write findings to a temp vet-findings.jsonl. Set FINDINGS_FILE to override default path.

Step 5: Present findings

Print the findings table per ../phx-deps-audit/references/output-renderer.md. On zero findings: say "No findings — vet from a clean baseline." On any finding: show severity, file, line, snippet inline.

Step 6: Prompt for verdict

Call AskUserQuestion with these 4 options:

  • :safe_to_deploy — full trust; findings investigated and cleared.
  • :safe_to_run — trust in non-production envs only (test deps).
  • :does_not_implement_crypto — Mozilla-style sub-criterion.
  • Skip — defer decision; don't write an entry.

If any finding is BLOCK severity: default-highlight Skip. Require explicit override before writing :safe_to_deploy over a BLOCK.

Step 7: Append to ledger

Read existing hex_vet.exs via Code.eval_file/1. Append the audit map below to :audits. Write back via Code.format_string!(inspect(...)).

elixir
%{
  package: "<pkg>",
  version: "<version>",
  criteria: <verdict_atom>,
  reviewer: "<git config user.email>",
  notes: "<user-provided one-liner OR findings summary>",
  reviewed_at: ~D[<today>]
}

Write back via Code.format_string!(inspect(term, pretty: true)). Confirm to user: "Added <pkg> <version> to hex_vet.exs."

Integration

  • Run after phx-deps-audit to clear vetted findings.
  • Run before merging a mix.lock PR to certify new versions.
  • Run phx-deps-vet --check to detect ledger drift vs mix.lock.
  • phx-deps-audit auto-downgrades vetted findings to INFO.
  • policy.block_on_unvetted is enforced by the plugin's deps-audit-gate.sh PreToolUse hook on mix deps.get / mix deps.update.

References

  • references/hex-vet.md — schema, parser, lookup
  • references/seed.md — --seed flag, curated baseline
  • ../phx-deps-audit/references/rules-impl.md — the same rules phx-deps-audit runs

Out of scope (Phase 3+)

  • Mix task surface — defer mix phx.deps_vet to a separate Hex package phx_deps_vet for non-CC users.
  • Distributed imports — defer cargo-vet imports: until trust-chain semantics are designed.

© oliver-kriska, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 3 other files (references) in targets/amp/skills/phx-deps-vet of oliver-kriska/claude-elixir-phoenix.

  • SKILL.md
  • priv/hex_vet_seed.exs
  • references/hex-vet.md
  • references/seed.md

Open the folder on GitHubat commit 9767a82

Compare with similar skills

Phx Deps Vet next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Phx Deps Vet compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Phx Deps Vet this skilloliver-kriska/claude-elixir-phoenix565—~1.5kAutomated safety check: PassMIT
Audit PrepPlamenTSV/plamen303—~3.7kAutomated safety check: PassMIT
Audit Finding Fixapache/magpie114—~4.9kAutomated safety check: PassApache-2.0
Xray Pre Auditccashwell/evm-cortex131—~25kAutomated safety check: PassMIT
Isms Audit Expertdavila7/claude-code-templates33k1 repos~3.1kAutomated safety check: PassMIT
Fp Checkvibeeval/vibecosystem532—~1.6kAutomated safety check: PassMIT

Similar skills

  • Audit Prep

    PlamenTSV/plamen

    Prepare Solidity projects for a security audit — test coverage, test quality, NatSpec docs, code hygiene, dependency health, best-practice enforcement, deployment readiness, and project…

    303 GitHub stars~3.7k tokensUpdated 15 days ago
    SecurityAuto-check passed
  • Audit Finding Fix

    apache/magpie

    For a batch of findings from a non-security audit tool (<audit-tool — ruff / flake8 / mypy / pylint / CodeQL / Apache Verum / Apache Caer / equivalent; full list in the body) against <upstream…

    114 GitHub stars~4.9k tokensUpdated yesterday
    SecurityAuto-check passed
  • Xray Pre Audit

    ccashwell/evm-cortex

    A skill your agent uses when preparing for a security audit, performing reconnaissance on a new codebase, or creating a protocol overview.

    131 GitHub stars~25k tokensUpdated 11 days ago
    SecurityAuto-check passed
  • Isms Audit Expert

    davila7/claude-code-templates

    Senior ISMS Audit Expert for internal and external information security management system auditing.

    33k GitHub starsUsed in 1 repo~3.1k tokens
    SecurityAuto-check passed
  • Fp Check

    vibeeval/vibecosystem

    Systematic false positive verification for security findings.

    532 GitHub stars~1.6k tokensUpdated 2 mo ago
    SecurityAuto-check passed
  • Common LLM Security

    HoangNguyen0403/agent-skills-standard

    OWASP LLM Top 10 (2025) audit checklist for AI applications, agent tools, RAG pipelines, and prompt construction.

    572 GitHub stars~921 tokensUpdated yesterday
    SecurityAuto-check passed

More from oliver-kriska/claude-elixir-phoenix

All 109 skills in this repo
  • Codex Ab

    oliver-kriska/claude-elixir-phoenix

    Run an A/B codex review experiment — holistic codex review vs 3 focused dimension passes (security, ecto, liveview) on the branch diff, classify findings, report a panel-value verdict.

    565 GitHub stars~977 tokensUpdated 5 days ago
    Auto-check passed
  • Audit

    oliver-kriska/claude-elixir-phoenix

    Project health audit and health check — architecture, performance, tests, dependencies, code quality.

    565 GitHub stars~2k tokensUpdated 5 days ago
    Auto-check passed
  • Compound Docs

    oliver-kriska/claude-elixir-phoenix

    Searchable Elixir/Phoenix/Ecto solution documentation system with; Use when consulting past solutions…

    565 GitHub stars~528 tokensUpdated 5 days ago
    Auto-check passed
  • Compound Docs

    oliver-kriska/claude-elixir-phoenix

    Searchable Elixir/Phoenix/Ecto solution documentation system with YAML frontmatter.

    565 GitHub stars~547 tokensUpdated 5 days ago
    Auto-check passed
  • Deploy

    oliver-kriska/claude-elixir-phoenix

    Elixir/Phoenix deployment patterns — Dockerfile, fly.toml, runtime.exs, mix release, rel/ overlays.

    565 GitHub stars~1.1k tokensUpdated 5 days ago
    Auto-check passed
  • Deps Update

    oliver-kriska/claude-elixir-phoenix

    Bump outdated Hex deps — inventory, snapshot changelogs, update, fix breaks, split reviewable PRs (patches bundled, majors solo).

    565 GitHub stars~1.4k tokensUpdated 5 days ago
    Auto-check passed

Categories

Questions about Phx Deps Vet

What does Phx Deps Vet do?

Record a vetted Hex package version in hexvet.exs after a security review — manages the audit ledger, not the scanner. Phx Deps Vet is an agent skill from oliver-kriska/claude-elixir-phoenix.exs after a security review — manages the audit ledger, not the scanner.

When should I use Phx Deps Vet?

Phx Deps Vet fits situations like: approve a dep after phx-deps-audit findings; initialize hexvet.exs.

How do I install Phx Deps Vet in Claude Code?

Run `npx skills add oliver-kriska/claude-elixir-phoenix --skill phx-deps-vet -a claude-code`. Or copy the skill folder (targets/amp/skills/phx-deps-vet in oliver-kriska/claude-elixir-phoenix) into .claude/skills/phx-deps-vet in your project. Claude Code loads it when a task matches its description.

How do I install Phx Deps Vet in Codex?

Run `npx skills add oliver-kriska/claude-elixir-phoenix --skill phx-deps-vet -a codex`. Or copy the skill folder (targets/amp/skills/phx-deps-vet in oliver-kriska/claude-elixir-phoenix) into .agents/skills/phx-deps-vet in your project. Codex loads it when a task matches its description.

Can I use Phx Deps Vet in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add oliver-kriska/claude-elixir-phoenix --skill phx-deps-vet -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/phx-deps-vet, .gemini/skills/phx-deps-vet, .github/skills/phx-deps-vet and .opencode/skills/phx-deps-vet in your project.

What does Phx Deps Vet need to run?

Going by SKILL.md and its folder, Phx Deps Vet needs Elixir for the scripts in its folder.

Does Phx Deps Vet access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Phx Deps Vet safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Phx Deps Vet use?

Phx Deps Vet is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Phx Deps Vet use?

About 1.5k tokens (SKILL.md is roughly 6k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 4k tokens, read only when the agent opens those files.

What are the alternatives to Phx Deps Vet?

Skills that share tags, products or a category with Phx Deps Vet: Audit Prep (PlamenTSV/plamen, 303 stars), Audit Finding Fix (apache/magpie, 114 stars), Xray Pre Audit (ccashwell/evm-cortex, 131 stars) and Isms Audit Expert (davila7/claude-code-templates, 33k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Phx Deps Vet?

oliver-kriska (a GitHub user) maintains it in oliver-kriska/claude-elixir-phoenix, which has 565 GitHub stars. The repository holds 109 skills in this directory. The repository was last updated on October 5, 2026.

Source: oliver-kriska/claude-elixir-phoenix on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.