Record vetted Hex versions after security review. An agent skill from oliver-kriska/claude-elixir-phoenix.

MITAuto-check passedSecurity

Install Phx Deps Vet

skills CLI
$ npx skills add oliver-kriska/claude-elixir-phoenix --skill phx-deps-vet -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install oliver-kriska/claude-elixir-phoenix phx-deps-vet --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/oliver-kriska/claude-elixir-phoenix.git skills-src && mkdir -p .claude/skills && cp -r skills-src/targets/codex/skills/phx-deps-vet .claude/skills/phx-deps-vet && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
phx-deps-vet
GitHub stars
565
Token cost
~1.5k tokens
SKILL.md length
608 words
Files
4 (incl. references)
Skills in repo
109
Repo updated
First seen
Licence
MIT

At a glance

Record vetted Hex versions after security review. An agent skill from oliver-kriska/claude-elixir-phoenix.

  • Works in 7 steps: Locate or seed hex_vet.exs → Branch by mode → Fetch the tarball (single-vet) → …
  • Approve audited dependencies
  • SKILL.md covers Usage, Iron Laws, Execution flow and Integration, plus 2 more sections
  • Runs Elixir scripts from its folder

What it does

Phx Deps Vet is an agent skill from oliver-kriska/claude-elixir-phoenix. Record vetted Hex versions after security review. Use to approve audited dependencies, not to scan them.

Its SKILL.md is about 1.5k tokens, which your agent loads only when the skill is triggered. The skill folder holds 5 other files, including reference files (for example `references/hex-vet.md` and `references/seed.md`).

It sits in Security, covering Security review. The repository describes itself as: Claude Code plugin for Elixir/Phoenix/LiveView — 26 specialist agents, Iron Laws enforcement, and Tidewave MCP integration. Plan features with parallel research agents, execute… The licence is MIT.

When your agent uses it

  • Approve audited dependencies
  • Not to scan them

Example prompts

  • “/phx-deps-vet”

Workflow steps

7 steps, taken from the step headings in SKILL.md.

  1. Locate or seed hex_vet.exs
  2. Branch by mode
  3. Fetch the tarball (single-vet)
  4. Run Phase 1 rules
  5. Present findings
  6. Prompt for verdict
  7. Append to ledger

What it can do on your machine

Read from SKILL.md and the folder at commit 9767a82. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships script files (Elixir), which the agent can run.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Phx Deps Vet loads about 1.5k tokens when it runs, and up to ~5.5k if it reads all its reference files. Until then it costs about 29 tokens; SKILL.md has 608 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~29
When it runs · the whole SKILL.md, loaded when a task matches
~1.5k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~5.5k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from oliver-kriska/claude-elixir-phoenix at commit 9767a82, republished under its MIT licence (© oliver-kriska). 608 words, ~1,504 tokens.

Download SKILL.mdSave it as .claude/skills/phx-deps-vet/SKILL.md (or your agent's skills folder). This skill also uses 3 other files; get the full folder from GitHub.
name
phx-deps-vet
description
Record vetted Hex versions after security review. Use to approve audited dependencies, not to scan them.

Deps Vet — Hex package audit ledger

Review a Hex package version, run Phase 1 supply-chain rules against it, prompt the user for a verdict, append the result to hex_vet.exs (project-root audit ledger). Vetted versions get downgraded to INFO on subsequent $elixir-phoenix:phx-deps-audit runs.

Run this AFTER $elixir-phoenix:phx-deps-audit to clear findings. Run this BEFORE merging a mix.lock PR to certify new versions.

Usage

text
$elixir-phoenix:phx-deps-vet phoenix 1.7.21      # vet a single package version
$elixir-phoenix:phx-deps-vet --seed              # import curated baseline seed (~30 pkgs)
$elixir-phoenix:phx-deps-vet --list              # show existing ledger entries
$elixir-phoenix:phx-deps-vet --check             # cross-check mix.lock vs ledger

Iron Laws

  1. NEVER auto-approve. Every entry MUST come from an AskUserQuestion confirmation. Drive-by trust ruins the ledger's value.
  2. Lock wins on disagreement. If mix.lock has version X and the ledger vets X-1, emit INFO and treat X as unvetted. Don't silently trust the older entry.
  3. Ledger lives at project root. hex_vet.exs is a first-class security artifact, visible in PR review. Don't move it into .claude/.
  4. Round-trip via inspect/2. When appending, read the file with Code.eval_file/1, mutate the map, and write back via inspect(term, pretty: true, limit: :infinity). Hand-rolled string appends drift over time.
  5. Always show findings before prompting. The user must see what's being vetted. No silent :safe_to_deploy defaults.
  6. Confirmation counts are COMPUTED, never estimated. Any number in an AskUserQuestion (criteria split, new/overwrite/no-op) MUST be derived from the loaded data before prompting — e.g. Enum.frequencies_by(seed.audits, & &1.criteria). Eyeballing the file and approving on wrong numbers corrupts the consent.

Execution flow

Step 1: Locate or seed hex_vet.exs
text
If hex_vet.exs exists at project root:
    Read it via Code.eval_file/1
Else:
    Write the empty-ledger stub (see references/hex-vet.md §"Empty ledger")
    Inform user: "Created hex_vet.exs at project root."
Step 2: Branch by mode
  • <pkg> <version> → single-vet path (Step 3-7).
  • --seed → import priv/hex_vet_seed.exs. Before prompting, Code.eval_file/1 the seed and compute (Iron Law #6): the criteria split (Enum.frequencies_by(seed.audits, & &1.criteria)) and, against any existing ledger, exact new / overwrite / no-op counts. Put those computed numbers in the AskUserQuestion. Also state up front that the seed is a provenance baseline, not certification of your current mix.lock (per Iron Law #2, seed versions older than the locked ones stay unvetted). Ask before overwriting existing entries.
  • --list → render the audits table; exit.
  • --check → compare ledger entries with mix.lock; warn on drift. Read the lock via Code.eval_file("mix.lock") with 2>/dev/null — modern locks have quoted keys and emit a found quoted keyword warning per package (tens of KB of noise that gets persisted as an oversized tool result otherwise).
Step 3: Fetch the tarball (single-vet)

Run the deps-audit corpus loader. Cache lives at ~/.cache/phx-deps-audit/corpus/<pkg>/<version>/contents/. Use:

text
bash ../phx-deps-audit/scripts/fetch_tarball.sh \
    <pkg> <version>
Show full SKILL.md (240 more words)Show less
Step 4: Run Phase 1 rules

Source the rules from ../phx-deps-audit/references/rules-impl.md. Run run_all_rules over the cached dir. Write findings to a temp vet-findings.jsonl. Set FINDINGS_FILE to override default path.

Step 5: Present findings

Print the findings table per ../phx-deps-audit/references/output-renderer.md. On zero findings: say "No findings — vet from a clean baseline." On any finding: show severity, file, line, snippet inline.

Step 6: Prompt for verdict

Call AskUserQuestion with these 4 options:

  • :safe_to_deploy — full trust; findings investigated and cleared.
  • :safe_to_run — trust in non-production envs only (test deps).
  • :does_not_implement_crypto — Mozilla-style sub-criterion.
  • Skip — defer decision; don't write an entry.

If any finding is BLOCK severity: default-highlight Skip. Require explicit override before writing :safe_to_deploy over a BLOCK.

Step 7: Append to ledger

Read existing hex_vet.exs via Code.eval_file/1. Append the audit map below to :audits. Write back via Code.format_string!(inspect(...)).

elixir
%{
  package: "<pkg>",
  version: "<version>",
  criteria: <verdict_atom>,
  reviewer: "<git config user.email>",
  notes: "<user-provided one-liner OR findings summary>",
  reviewed_at: ~D[<today>]
}

Write back via Code.format_string!(inspect(term, pretty: true)). Confirm to user: "Added <pkg> <version> to hex_vet.exs."

Integration

  • Run after $elixir-phoenix:phx-deps-audit to clear vetted findings.
  • Run before merging a mix.lock PR to certify new versions.
  • Run $elixir-phoenix:phx-deps-vet --check to detect ledger drift vs mix.lock.
  • $elixir-phoenix:phx-deps-audit auto-downgrades vetted findings to INFO.
  • policy.block_on_unvetted is enforced by the plugin's deps-audit-gate.sh PreToolUse hook on mix deps.get / mix deps.update.

References

  • references/hex-vet.md — schema, parser, lookup
  • references/seed.md — --seed flag, curated baseline
  • ../phx-deps-audit/references/rules-impl.md — the same rules $elixir-phoenix:phx-deps-audit runs

Out of scope (Phase 3+)

  • Mix task surface — defer mix phx.deps_vet to a separate Hex package phx_deps_vet for non-CC users.
  • Distributed imports — defer cargo-vet imports: until trust-chain semantics are designed.

© oliver-kriska, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 3 other files (references) in targets/codex/skills/phx-deps-vet of oliver-kriska/claude-elixir-phoenix.

  • SKILL.md
  • priv/hex_vet_seed.exs
  • references/hex-vet.md
  • references/seed.md

Open the folder on GitHubat commit 9767a82

Compare with similar skills

Phx Deps Vet next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Phx Deps Vet compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Phx Deps Vet this skilloliver-kriska/claude-elixir-phoenix565—~1.5kAutomated safety check: PassMIT
Deepsec Documentation Guidevercel-labs/deepsec8.1k—~956Automated safety check: PassApache-2.0
Kubernetes Network Security Auditkubeshark/kubeshark12k—~7.3kAutomated safety check: NotesApache-2.0
Native Dependency Updatemono/SkiaSharp5.6k—~4.1kAutomated safety check: PassMIT
Semgrep Security Scantrailofbits/skills7.5k—~3.7kAutomated safety check: NotesCC-BY-SA-4.0
Skillward AuditFangcun-AI/SkillWard143—~2.9kAutomated safety check: PassCustom licence

Similar skills

  • Deepsec Documentation Guide

    vercel-labs/deepsec

    Official

    Points the agent at deepsec's own docs to answer questions about initializing, configuring, resuming, scanning with and extending the vulnerability scanner.

    8.1k GitHub stars~956 tokensUpdated 12 days ago
    SecurityAuto-check passed
  • Hunts for compromised workloads and malicious traffic in a Kubernetes cluster by sweeping network data through Kubeshark MCP, mapped to MITRE ATT&CK.

    12k GitHub stars~7.3k tokensUpdated yesterday
    SecurityAuto-check: notes
  • Update native dependencies (libpng, libexpat, zlib, libwebp, harfbuzz, freetype, libjpeg-turbo, etc.) in SkiaSharp's Skia fork.

    5.6k GitHub stars~4.1k tokensUpdated yesterday
    SecurityAuto-check passed
  • Semgrep Security Scan

    trailofbits/skills

    Official

    Detects languages, proposes rulesets for approval, then runs the approved Semgrep scan across a codebase and merges the output into one SARIF file.

    7.5k GitHub stars~3.7k tokensUpdated yesterday
    SecurityAuto-check: notes
  • Skillward Audit

    Fangcun-AI/SkillWard

    Security-audit a third-party skill bundle (folder with SKILL.md, or .zip / .tar.gz archive) before installing it, using the SkillWard cloud scanner.

    143 GitHub stars~2.9k tokensUpdated 2 mo ago
    SecurityAuto-check passed
  • Security Audit

    TheDecipherist/claude-code-mastery

    Checks a codebase for hardcoded secrets, vulnerable dependencies, weak input handling, weak authentication and unsafe transport settings before deployment or merge.

    551 GitHub stars~1.3k tokensUpdated 5 mo ago
    SecurityAuto-check: notes

More from oliver-kriska/claude-elixir-phoenix

All 109 skills in this repo
  • Codex Ab

    oliver-kriska/claude-elixir-phoenix

    Run an A/B codex review experiment — holistic codex review vs 3 focused dimension passes (security, ecto, liveview) on the branch diff, classify findings, report a panel-value verdict.

    565 GitHub stars~977 tokensUpdated 5 days ago
    Auto-check passed
  • Audit

    oliver-kriska/claude-elixir-phoenix

    Project health audit and health check — architecture, performance, tests, dependencies, code quality.

    565 GitHub stars~2k tokensUpdated 5 days ago
    Auto-check passed
  • Compound Docs

    oliver-kriska/claude-elixir-phoenix

    Searchable Elixir/Phoenix/Ecto solution documentation system with; Use when consulting past solutions…

    565 GitHub stars~528 tokensUpdated 5 days ago
    Auto-check passed
  • Compound Docs

    oliver-kriska/claude-elixir-phoenix

    Searchable Elixir/Phoenix/Ecto solution documentation system with YAML frontmatter.

    565 GitHub stars~547 tokensUpdated 5 days ago
    Auto-check passed
  • Deploy

    oliver-kriska/claude-elixir-phoenix

    Elixir/Phoenix deployment patterns — Dockerfile, fly.toml, runtime.exs, mix release, rel/ overlays.

    565 GitHub stars~1.1k tokensUpdated 5 days ago
    Auto-check passed
  • Deps Update

    oliver-kriska/claude-elixir-phoenix

    Bump outdated Hex deps — inventory, snapshot changelogs, update, fix breaks, split reviewable PRs (patches bundled, majors solo).

    565 GitHub stars~1.4k tokensUpdated 5 days ago
    Auto-check passed

Categories

Questions about Phx Deps Vet

What does Phx Deps Vet do?

Record vetted Hex versions after security review. An agent skill from oliver-kriska/claude-elixir-phoenix. Phx Deps Vet is an agent skill from oliver-kriska/claude-elixir-phoenix. Record vetted Hex versions after security review.

When should I use Phx Deps Vet?

Phx Deps Vet fits situations like: approve audited dependencies; not to scan them.

How do I install Phx Deps Vet in Claude Code?

Run `npx skills add oliver-kriska/claude-elixir-phoenix --skill phx-deps-vet -a claude-code`. Or copy the skill folder (targets/codex/skills/phx-deps-vet in oliver-kriska/claude-elixir-phoenix) into .claude/skills/phx-deps-vet in your project. Claude Code loads it when a task matches its description.

How do I install Phx Deps Vet in Codex?

Run `npx skills add oliver-kriska/claude-elixir-phoenix --skill phx-deps-vet -a codex`. Or copy the skill folder (targets/codex/skills/phx-deps-vet in oliver-kriska/claude-elixir-phoenix) into .agents/skills/phx-deps-vet in your project. Codex loads it when a task matches its description.

Can I use Phx Deps Vet in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add oliver-kriska/claude-elixir-phoenix --skill phx-deps-vet -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/phx-deps-vet, .gemini/skills/phx-deps-vet, .github/skills/phx-deps-vet and .opencode/skills/phx-deps-vet in your project.

What does Phx Deps Vet need to run?

Going by SKILL.md and its folder, Phx Deps Vet needs Elixir for the scripts in its folder.

Does Phx Deps Vet access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Phx Deps Vet safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Phx Deps Vet use?

Phx Deps Vet is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Phx Deps Vet use?

About 1.5k tokens (SKILL.md is roughly 6k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 4k tokens, read only when the agent opens those files.

What are the alternatives to Phx Deps Vet?

Skills that share tags, products or a category with Phx Deps Vet: Deepsec Documentation Guide (vercel-labs/deepsec, 8.1k stars), Kubernetes Network Security Audit (kubeshark/kubeshark, 12k stars), Native Dependency Update (mono/SkiaSharp, 5.6k stars) and Semgrep Security Scan (trailofbits/skills, 7.5k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Phx Deps Vet?

oliver-kriska (a GitHub user) maintains it in oliver-kriska/claude-elixir-phoenix, which has 565 GitHub stars. The repository holds 109 skills in this directory. The repository was last updated on October 5, 2026.

Source: oliver-kriska/claude-elixir-phoenix on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.