Agent skill

Audit Fix

by openplayerjs in openplayerjs/openplayerjs

Resolve a pnpm audit (dependency-audit CI job) failure — high/critical CVEs in the dependency tree.

MITAuto-check passedSecurity

Install Audit Fix

skills CLI
$ npx skills add openplayerjs/openplayerjs --skill audit-fix -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install openplayerjs/openplayerjs audit-fix --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/openplayerjs/openplayerjs.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/audit-fix .claude/skills/audit-fix && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
audit-fix
GitHub stars
649
Token cost
~1k tokens
SKILL.md length
514 words
Files
1
Skills in repo
5
Repo updated
First seen
Licence
MIT

At a glance

Resolve a pnpm audit (dependency-audit CI job) failure — high/critical CVEs in the dependency tree.

  • Works in 2 steps: The fix is an entry in… → pnpm install followed by pnpm audit…
  • Asked to fix an audit finding
  • SKILL.md covers Why this doesn't need E1…, Procedure and What it refuses to touch, and…
  • Calls pnpm and npm

What it does

Audit Fix is an agent skill from openplayerjs/openplayerjs. Resolve a pnpm audit (dependency-audit CI job) failure — high/critical CVEs in the dependency tree. Use when asked to fix an audit finding, a CVE, a GHSA advisory, or when the "Dependency audit" GitHub check is red. Covers the deterministic pnpm-workspace.yaml override procedure, what it can't fix, and why the E1 "ask before adding/upgrading a dependency" rule doesn't block this specific case.

Its SKILL.md is about 1k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Security, covering Vulnerability scanning, Audit readiness and Monorepo tooling. It works with pnpm, GitHub and TypeScript. The repository describes itself as: Lightweight HTML5 video/audio player with smooth controls and ability to play VAST/VMAP/SIMID/OMID/non-linear ads. The licence is MIT.

When your agent uses it

  • Asked to fix an audit finding
  • A GHSA advisory
  • The Dependency audit GitHub check is red

Example prompts

  • “Dependency audit”
  • “t fix, and why the E1”
  • “rule doesn”
  • “/audit-fix”

Requirements

  • Node.js

Workflow steps

2 steps, taken from the first numbered list in SKILL.md.

  1. The fix is an entry in pnpm-workspace.yaml's overrides: block — never a
  2. pnpm install followed by pnpm audit --audit-level=high comes back clean afterward.

What it can do on your machine

Read from SKILL.md and the folder at commit c26914a. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • pnpm
    • npm

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use pnpm and npm, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Audit Fix loads about 1k tokens when it runs. Until then it costs about 102 tokens; SKILL.md has 514 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~102
When it runs · the whole SKILL.md, loaded when a task matches
~1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from openplayerjs/openplayerjs at commit c26914a, republished under its MIT licence (© openplayerjs). 514 words, ~1,037 tokens.

Download SKILL.mdSave it as .claude/skills/audit-fix/SKILL.md (or your agent's skills folder).
name
audit-fix
description
Resolve a `pnpm audit` (dependency-audit CI job) failure — high/critical CVEs in the dependency tree. Use when asked to fix an audit finding, a CVE, a GHSA advisory, or when the "Dependency audit" GitHub check is red. Covers the deterministic pnpm-workspace.yaml override procedure, what it can't fix, and why the E1 "ask before adding/upgrading a dependency" rule doesn't block this specific case.

Resolving a dependency-audit finding

This procedure is implemented as a script, not just documentation: scripts/audit-fix.cjs does exactly what this page describes, and .github/workflows/dependency-audit.yml's audit-fix job runs it automatically on same-repo PRs when the audit job goes red, pushing the fix onto the PR branch and commenting the result. Run the same script yourself for a manual fix, a fork PR (which the bot can't push to), or a push-to-master failure (the bot only acts on PRs) — the procedure and the guardrails are identical either way.

Why this doesn't need E1 sign-off

Root CLAUDE.md E1 lists "adding or upgrading any dependency" as ask-first. This procedure is exempt from that only when both hold:

  1. The fix is an entry in pnpm-workspace.yaml's overrides: block — never a dependencies/devDependencies edit in any package.json.
  2. pnpm install followed by pnpm audit --audit-level=high comes back clean afterward.

That's the same mechanism every existing entry in that block already uses (see the "Supply-chain security" comment above it) — this skill just makes running it repeatable instead of ad hoc. Anything that doesn't fit those two constraints (below) still needs a human, same as any other dependency change.

Procedure

sh
pnpm run audit:fix

What it does, in order (see scripts/audit-fix.cjs for the implementation):

  1. Runs pnpm audit --json, keeps advisories at high/critical (matches the --audit-level=high gate).
  2. For each, resolves the lowest published version satisfying patched_versions — smallest possible diff, not necessarily latest.
  3. Writes/updates that version into pnpm-workspace.yaml's overrides: block (alphabetically, matching its existing convention).
  4. pnpm install, then re-runs pnpm audit to confirm the advisory is gone.

Then run the standard gate before committing:

sh
pnpm run build && pnpm run test

(The audit-fix job in CI skips this — the existing build/coveralls workflows already re-run on the commit it pushes. A manual run should still verify locally.)

Commit as chore(deps): ... (scope deps, R12) — scripts/audit-fix-report.cjs --format=commit <summary.json> renders a ready message from the JSON summary if AUDIT_FIX_SUMMARY_PATH was set when you ran the fix.

Show full SKILL.md (201 more words)Show less

What it refuses to touch, and why

  • A finding whose module is a direct dependencies entry of a published package (currently: @dailymotion/vast-client, @dailymotion/vmap in packages/ads). An overrides entry only fixes this workspace's lockfile/audit — it does not change what npm installing that published package resolves for a downstream consumer, because overrides are a pnpm/root-lockfile-only concept. This needs an actual version bump in that package's package.json, which changes what ships to consumers — ask first, same as any dependency change. Cross-check with pnpm why <pkg> to see the real path.
  • No published version satisfies the patched range yet. Wait for the fix to ship upstream; there's nothing to pin to.
  • The resolved version is blocked by minimumReleaseAge (the 5-day supply-chain cooldown in pnpm-workspace.yaml). This surfaces as a pnpm install failure. Do not add the package to minimumReleaseAgeExclude to work around it — that list is a deliberate, reviewed exception, not a bypass valve. Wait for the cooldown to pass, or ask the user if it's urgent enough to warrant a reviewed exclusion.

Any advisory in one of these buckets stays unfixed by design — the audit CI job stays red until a human resolves it, which is the correct outcome, not a bug in the automation.

© openplayerjs, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .claude/skills/audit-fix of openplayerjs/openplayerjs.

Open the folder on GitHubat commit c26914a

Compare with similar skills

Audit Fix next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Audit Fix compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Audit Fix this skillopenplayerjs/openplayerjs649—~1kAutomated safety check: PassMIT
Linea Dependency MaintenanceConsensys-Incorporated/linea-attestation-registry1771 repos~3.7kAutomated safety check: WarnMIT
Fix Security PRunional/typescript-blackbook133—~1.4kAutomated safety check: WarnMIT
Archestra Dev Override Sweeparchestra-ai/archestra4.3k—~1.4kAutomated safety check: PassCustom licence
Link Workspace Packagesnomcopter/react-mosaic4.8k5 repos~760Automated safety check: PassCustom licence
Pnpm Engineteambit/bit18k—~1.9kAutomated safety check: PassCustom licence

Similar skills

  • Linea Dependency Maintenance

    Consensys-Incorporated/linea-attestation-registry

    Safely plan and execute dependency maintenance for JavaScript/TypeScript (npm, pnpm) and GitHub Actions, including npm lockfiles, pnpm workspaces, catalogs, overrides, SHA-pinned action versions…

    177 GitHub starsUsed in 1 repo~3.7k tokens
    DevelopmentAuto-check: warnings
  • Fix Security PR

    unional/typescript-blackbook

    Fix a PR that is failing due to security or vulnerability issues — npm/pnpm/yarn/bun audit failures, CVE alerts, Dependabot merge conflicts, Snyk failures, or GitHub security advisory blocks.

    133 GitHub stars~1.4k tokensUpdated 2 days ago
    DevelopmentAuto-check: warnings
  • Archestra Dev Override Sweep

    archestra-ai/archestra

    A skill your agent uses when asked to sweep, clean up, or revisit pnpm overrides and minimumReleaseAge exclusions in platform/pnpm-workspace.yaml — unwinding a matured temporary CVE pin once its fix…

    4.3k GitHub stars~1.4k tokensUpdated today
    SecurityAuto-check passed
  • Link Workspace Packages

    nomcopter/react-mosaic

    Link workspace packages in monorepos (npm, yarn, pnpm, bun).

    4.8k GitHub starsUsed in 5 repos~760 tokens
    DevelopmentAuto-check passed
  • Pnpm Engine

    teambit/bit

    Work on the pnpm Rust engine (@pnpm/napi, the pacquet crates) that bit install runs through.

    18k GitHub stars~1.9k tokensUpdated yesterday
    DevelopmentAuto-check passed
  • Release

    seasonedcc/remix-forms

    Release a new version of the remix-forms npm package. An agent skill from seasonedcc/remix-forms.

    514 GitHub stars~1.3k tokensUpdated 5 mo ago
    DevelopmentAuto-check passed

More from openplayerjs/openplayerjs

  • Add Event

    openplayerjs/openplayerjs

    Add, rename, change the payload of, or remove a typed player event in OpenPlayerJS.

    649 GitHub stars~1.7k tokensUpdated 2 days ago
    Auto-check passed
  • Preship

    openplayerjs/openplayerjs

    Run the full OpenPlayerJS verification gauntlet before committing, opening a PR, or preparing a release.

    649 GitHub stars~1.2k tokensUpdated 2 days ago
    Auto-check passed
  • Write Tests

    openplayerjs/openplayerjs

    Write or extend Jest tests for OpenPlayerJS to this repo's exact conventions — makeCore factories, typed internals handles instead of as any, media property mocking, fake timers, ads/vast mocks, and…

    649 GitHub stars~1.8k tokensUpdated 2 days ago
    Auto-check passed
  • Optimize

    openplayerjs/openplayerjs

    Find and safely apply ONE worthwhile code optimization (reuse, simplification, efficiency, or a dead-weight cleanup) somewhere in packages//src, with new regression tests proving behavior is…

    649 GitHub stars~1.9k tokensUpdated 2 days ago
    Auto-check passed

Categories

Questions about Audit Fix

What does Audit Fix do?

Resolve a pnpm audit (dependency-audit CI job) failure — high/critical CVEs in the dependency tree. Audit Fix is an agent skill from openplayerjs/openplayerjs. Resolve a pnpm audit (dependency-audit CI job) failure — high/critical CVEs in the dependency tree.

When should I use Audit Fix?

Audit Fix fits situations like: asked to fix an audit finding; A GHSA advisory; the Dependency audit GitHub check is red.

How do I install Audit Fix in Claude Code?

Run `npx skills add openplayerjs/openplayerjs --skill audit-fix -a claude-code`. Or copy the skill folder (.claude/skills/audit-fix in openplayerjs/openplayerjs) into .claude/skills/audit-fix in your project. Claude Code loads it when a task matches its description.

How do I install Audit Fix in Codex?

Run `npx skills add openplayerjs/openplayerjs --skill audit-fix -a codex`. Or copy the skill folder (.claude/skills/audit-fix in openplayerjs/openplayerjs) into .agents/skills/audit-fix in your project. Codex loads it when a task matches its description.

Can I use Audit Fix in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add openplayerjs/openplayerjs --skill audit-fix -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/audit-fix, .gemini/skills/audit-fix, .github/skills/audit-fix and .opencode/skills/audit-fix in your project.

What does Audit Fix need to run?

Going by SKILL.md and its folder, Audit Fix needs the command-line tools its instructions call (pnpm and npm). Our summary lists: Node.js.

Does Audit Fix access the network?

SKILL.md contains no URLs. Its commands use npm, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Audit Fix safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Audit Fix use?

Audit Fix is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Audit Fix use?

About 1k tokens (SKILL.md is roughly 4.1k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Audit Fix?

Skills that share tags, products or a category with Audit Fix: Linea Dependency Maintenance (Consensys-Incorporated/linea-attestation-registry, 177 stars), Fix Security PR (unional/typescript-blackbook, 133 stars), Archestra Dev Override Sweep (archestra-ai/archestra, 4.3k stars) and Link Workspace Packages (nomcopter/react-mosaic, 4.8k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Audit Fix?

openplayerjs (a GitHub organization) maintains it in openplayerjs/openplayerjs, which has 649 GitHub stars. The repository holds 5 skills in this directory. The repository was last updated on October 5, 2026.

Source: openplayerjs/openplayerjs on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.