Agent skill

Audit Dependencies

by payloadcms in payloadcms/payload

A skill your agent uses when fixing dependency vulnerabilities, running pnpm audit, or when the audit-dependencies CI check fails

MITAuto-check passedSecurity

Install Audit Dependencies

skills CLI
$ npx skills add payloadcms/payload --skill audit-dependencies -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install payloadcms/payload audit-dependencies --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/payloadcms/payload.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/audit-dependencies .claude/skills/audit-dependencies && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
audit-dependencies
GitHub stars
45k
Token cost
~2.8k tokens
SKILL.md length
925 words
Files
2
Skills in repo
9
Repo updated
First seen
Licence
MIT

At a glance

A skill your agent uses when fixing dependency vulnerabilities, running pnpm audit, or when the audit-dependencies CI check fails

  • Works in 8 steps: Run the Audit Script → For Each Vulnerable Package → Present Plan to User → …
  • Fixing dependency vulnerabilities
  • SKILL.md covers Overview, Core Workflow, Step-by-Step and Common Mistakes
  • Calls pnpm and gh; reaches github.com

What it does

Audit Dependencies is an agent skill from payloadcms/payload. Use when fixing dependency vulnerabilities, running pnpm audit, or when the audit-dependencies CI check fails

Its SKILL.md is about 2.8k tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files (for example `agents/openai.yaml`).

It sits in Security, covering Vulnerability scanning. It works with pnpm, Payload CMS and Next.js. The repository describes itself as: Payload is the open-source, fullstack Next.js framework, giving you instant backend superpowers. Get a full TypeScript backend and admin panel instantly. Use Payload as a… The licence is MIT.

When your agent uses it

  • Fixing dependency vulnerabilities
  • Running pnpm audit
  • The audit-dependencies CI check fails

Example prompts

  • “/audit-dependencies”

Workflow steps

8 steps, taken from the step headings in SKILL.md.

  1. Run the Audit Script
  2. For Each Vulnerable Package
  3. Present Plan to User
  4. Apply Fixes
  5. Install and Verify
  6. Build and Verify
  7. Look Up CVEs
  8. Commit and Create PR

What it can do on your machine

Read from SKILL.md and the folder at commit ed6a954. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • pnpm
    • gh

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • github.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Audit Dependencies loads about 2.8k tokens when it runs. Until then it costs about 32 tokens; SKILL.md has 925 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~32
When it runs · the whole SKILL.md, loaded when a task matches
~2.8k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from payloadcms/payload at commit ed6a954, republished under its MIT licence (© payloadcms). 925 words, ~2,768 tokens.

Download SKILL.mdSave it as .claude/skills/audit-dependencies/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
audit-dependencies
description
Use when fixing dependency vulnerabilities, running pnpm audit, or when the audit-dependencies CI check fails

Audit Dependencies

Overview

Fix dependency vulnerabilities reported by .github/workflows/audit-dependencies.sh. Prefer fixes in this order: direct dependency bump > lockfile update > pnpm override. Every override requires justification for why simpler approaches aren't feasible.

Core Workflow

dot
digraph audit {
    "Run audit script" [shape=box];
    "Group by package" [shape=box];
    "Trace dependency chain" [shape=box];
    "Can bump direct dep?" [shape=diamond];
    "Research breaking changes" [shape=box];
    "Breaking changes acceptable?" [shape=diamond];
    "Apply direct bump" [shape=box];
    "Is version pinned or ranged?" [shape=diamond];
    "Lockfile update" [shape=box];
    "Apply pnpm override" [shape=box];
    "More packages?" [shape=diamond];
    "Present plan to user" [shape=box];
    "Install and verify" [shape=box];
    "Build and verify" [shape=box];
    "Commit and create PR" [shape=box];

    "Run audit script" -> "Group by package";
    "Group by package" -> "Trace dependency chain";
    "Trace dependency chain" -> "Can bump direct dep?";
    "Can bump direct dep?" -> "Research breaking changes" [label="yes"];
    "Can bump direct dep?" -> "Is version pinned or ranged?" [label="no"];
    "Research breaking changes" -> "Breaking changes acceptable?";
    "Breaking changes acceptable?" -> "Apply direct bump" [label="yes"];
    "Breaking changes acceptable?" -> "Is version pinned or ranged?" [label="no"];
    "Is version pinned or ranged?" -> "Lockfile update" [label="ranged - fix is in range"];
    "Is version pinned or ranged?" -> "Apply pnpm override" [label="pinned - explain why"];
    "Apply direct bump" -> "More packages?";
    "Lockfile update" -> "More packages?";
    "Apply pnpm override" -> "More packages?";
    "More packages?" -> "Trace dependency chain" [label="yes"];
    "More packages?" -> "Present plan to user" [label="no"];
    "Present plan to user" -> "Install and verify";
    "Install and verify" -> "Build and verify";
    "Build and verify" -> "Commit and create PR";
}

Step-by-Step

1. Run the Audit Script
bash
./.github/workflows/audit-dependencies.sh $ARGUMENTS

$ARGUMENTS is the severity passed to the skill (defaults to high if omitted). The script runs pnpm audit --prod --json and filters for actionable vulnerabilities (those with a patched version available). high includes critical.

Parse the output to build a deduplicated list of vulnerable packages with:

  • Package name and current version
  • Fixed version requirement
  • Full dependency chain (e.g., packages/plugin-sentry > @sentry/nextjs > rollup)
2. For Each Vulnerable Package
Trace the dependency chain

Identify whether the vulnerable package is:

  • Direct dependency: Listed in a workspace package's package.json
  • Transitive dependency: Pulled in by another package
Try direct bump first

For transitive deps, walk up the chain to find the nearest package you control:

  1. Check if bumping the parent package resolves the vulnerability
    • pnpm view <parent>@latest dependencies.<vulnerable-pkg>
    • Check intermediate versions too (the fix may exist in a minor bump)
  2. If the parent bump resolves it, research breaking changes:
    • Check changelogs/release notes
    • Search GitHub issues for compatibility problems
    • Review the API surface used in this repo (read the source files)
    • Check if the version range crosses a major version boundary
  3. Present findings to user with risk assessment

Parallelize research: When multiple packages need breaking change analysis, dispatch parallel agents (one per package) to research simultaneously.

Check if a lockfile update is sufficient

Before reaching for an override, check whether the parent's version specifier is pinned (exact version like 3.10.3) or ranged (like ^2.3.1, ~4.0.3):

bash
pnpm view <parent> dependencies.<vulnerable-pkg>

If the range already includes the fixed version, a lockfile update is all that's needed:

bash
pnpm update <vulnerable-pkg> --recursive

No package.json changes required — the lockfile was just stale.

Fall back to override only when justified

Add a pnpm override in root package.json only when:

  • The parent pins an exact version that doesn't satisfy the fix
  • No version of the parent package fixes the vulnerability
  • The parent bump has high breaking change risk (major API changes, no test coverage, requires code changes across many files)
  • The user explicitly decides to defer the parent bump to a separate PR

Override format: "<parent>><vulnerable-pkg>": "^<fixed-version>"

Override syntax rules:

  • Use ^ ranges, not >=. >= can cross major versions and cause unexpected resolutions (e.g., "picomatch": ">=2.3.2" can resolve to 4.x).
  • pnpm only supports single-level parent scoping: "parent>pkg" works, "grandparent>parent>pkg" does not.
  • pnpm does not support version selectors in override keys: "pkg@^2" does not work.
  • If the same vulnerable package appears through many transitive paths, a global override may be needed. Be careful that it doesn't affect unrelated consumers on a different major version — use parent-scoped overrides when the package spans multiple major versions across the tree.
  • pnpm only honors overrides in the root workspace package.json. Overrides in workspace packages are ignored.

Before adding any override, verify the target version exists:

bash
pnpm view <pkg>@<version> version
3. Present Plan to User

Before applying fixes, present a summary table to the user showing each vulnerability, the proposed fix strategy (direct bump / lockfile update / override), and justification. Get confirmation before proceeding.

4. Apply Fixes
  • Edit package.json files for direct bumps
  • Run pnpm update <pkg> --recursive for lockfile-only fixes
  • Edit root package.json pnpm.overrides for overrides (keep alphabetical)
  • If a direct bump changes behavior, update consuming code (e.g., adding allowOverwrite: true when an API default changes)
Show full SKILL.md (371 more words)Show less
5. Install and Verify
bash
pnpm install

If install fails due to native build errors (e.g., better-sqlite3), fall back to:

bash
pnpm install --ignore-scripts

Then re-run the audit script with the same severity:

bash
./.github/workflows/audit-dependencies.sh $ARGUMENTS

The audit script must exit 0. If vulnerabilities remain, check for additional instances of the same dependency in other workspace packages.

6. Build and Verify
bash
pnpm run build:core

For packages with changed dependencies, also run their specific build:

bash
pnpm run build:<package-name>
7. Look Up CVEs

For each fixed vulnerability, find the GitHub Security Advisory (GHSA):

  • Check https://github.com/<org>/<repo>/security/advisories for each package
  • Search the web for <package-name> GHSA <fixed-version>
  • Record: GHSA ID, CVE ID, severity, one-line description
  • Prefer GHSA links (https://github.com/advisories/GHSA-xxxx-xxxx-xxxx) over NVD links

Parallelize CVE lookups: Dispatch parallel agents to search for CVEs across all packages simultaneously.

8. Commit and Create PR

Commit with conventional commit format:

fix(deps): resolve $ARGUMENTS severity audit vulnerabilities

Create PR using gh pr create with this body structure:

markdown
# Overview

[What the PR fixes, mention `pnpm audit --prod`]

## Key Changes

- **[Package name] in [workspace path]**
  - [old version] → [new version]. Fixes [GHSA-xxxx-xxxx-xxxx](https://github.com/advisories/GHSA-xxxx-xxxx-xxxx) ([description]).
  - [Why this approach: direct bump because X / lockfile update because Y / override because Z]
  - [Any code changes required by the bump]

## Design Decisions

[Why direct bumps were preferred, justification for any remaining overrides]

Common Mistakes

MistakeFix
Jumping straight to overridesCheck: can you bump the parent? If not, does the semver range already allow the fix (lockfile update)? Only then override.
Using >= in override rangesUse ^ to stay within the same major version. >=2.3.2 can resolve to 4.x.
Not checking pinned vs rangedpnpm view <parent> dependencies.<pkg> — if ranged and the fix is in range, just pnpm update.
Nested override scoping (a>b>c)pnpm only supports single-level: "parent>pkg". For deeper chains, override the direct parent or use a global override.
Version selectors in override keys (pkg@^2)Not supported by pnpm. Use parent-scoped or global overrides instead.
Global override affecting multiple major versions"picomatch": ">=4.0.4" forces all picomatch to 4.x, breaking consumers that need 2.x. Scope overrides to the parent when a package spans multiple majors.
Not checking all workspace packagesSame dep may appear in multiple package.json files (e.g., changelogen in both tools/releaser and tools/scripts)
Overriding with a nonexistent versionVerify the target version exists with pnpm view before installing
Not falling back to --ignore-scriptsPre-existing native build failures block pnpm install; use --ignore-scripts to get lockfile updated
Missing code changes for breaking bumpsIf a bump changes API defaults, update the calling code
Forgetting advisory links in PRAlways look up and include GHSA links for each vulnerability
Applying fixes without user confirmationPresent the full plan (strategy per vuln + justification) and get confirmation before making changes

© payloadcms, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file in .agents/skills/audit-dependencies of payloadcms/payload.

  • SKILL.md
  • agents/openai.yaml

Open the folder on GitHubat commit ed6a954

Compare with similar skills

Audit Dependencies next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Audit Dependencies compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Audit Dependencies this skillpayloadcms/payload45k—~2.8kAutomated safety check: PassMIT
Audit Fixopenplayerjs/openplayerjs649—~1kAutomated safety check: PassMIT
Security Vuln Remediationstacklok/toolhive-studio170—~2.3kAutomated safety check: NotesApache-2.0
Cve Scansoftspark/ai-toolkit179—~1.3kAutomated safety check: NotesApache-2.0
Dependency AwarenessGoldziher/ai-rulez153—~250Automated safety check: PassMIT
Testingtrieb-work/nextjs-turbo-redis-cache151—~1.1kAutomated safety check: PassMIT

Similar skills

  • Audit Fix

    openplayerjs/openplayerjs

    Resolve a pnpm audit (dependency-audit CI job) failure — high/critical CVEs in the dependency tree.

    649 GitHub stars~1k tokensUpdated 2 days ago
    SecurityAuto-check passed
  • Security Vuln Remediation

    stacklok/toolhive-studio

    Remediate security vulnerabilities found by Grype or pnpm audit.

    170 GitHub stars~2.3k tokensUpdated yesterday
    SecurityAuto-check: notes
  • Cve Scan

    softspark/ai-toolkit

    Scans deps for known CVEs via native audit (npm, pip, composer, cargo, go, bundler, dart).

    179 GitHub stars~1.3k tokensUpdated yesterday
    SecurityAuto-check: notes
  • Dependency Awareness

    Goldziher/ai-rulez

    Per-language dependency vulnerability audit tool reference (cargo audit/deny, pip-audit, npm/pnpm audit, govulncheck, bundler-audit, composer audit, OWASP dependency-check, dotnet vulnerable…

    153 GitHub stars~250 tokensUpdated today
    SecurityAuto-check passed
  • Testing

    trieb-work/nextjs-turbo-redis-cache

    Run tests and add Next.js version coverage for the cache handler.

    151 GitHub stars~1.1k tokensUpdated 13 days ago
    Testing & QAAuto-check passed
  • Fix Security PR

    unional/typescript-blackbook

    Fix a PR that is failing due to security or vulnerability issues — npm/pnpm/yarn/bun audit failures, CVE alerts, Dependabot merge conflicts, Snyk failures, or GitHub security advisory blocks.

    133 GitHub stars~1.4k tokensUpdated 3 days ago
    DevelopmentAuto-check: warnings

More from payloadcms/payload

All 9 skills in this repo
  • Record PR Demo

    payloadcms/payload

    A skill your agent uses when a Payload pull request needs a concise visual walkthrough for reviewers.

    45k GitHub stars~1k tokensUpdated today
    Auto-check passed
  • Payload

    payloadcms/payload

    A skill your agent uses when working with Payload projects (payload.config.ts, collections, fields, hooks, access control, Payload API).

    45k GitHub starsUsed in 5 repos~6.2k tokens
    Auto-check passed
  • Generate Translations

    payloadcms/payload

    A skill your agent uses when new translation keys are added to packages to generate new translations strings

    45k GitHub stars~1.1k tokensUpdated today
    Auto-check passed
  • Triage CI Flake

    payloadcms/payload

    A skill your agent uses when CI tests fail on main branch after PR merge, when investigating flaky test failures, or when user provides a PR URL/number to aggregate all failing tests

    45k GitHub stars~4.4k tokensUpdated today
    Auto-check passed
  • Ui4 Convert Tests

    payloadcms/payload

    A skill your agent uses when UI changes are complete and e2e tests need updating.

    45k GitHub stars~3.5k tokensUpdated today
    Auto-check passed
  • Payload Accessibility

    payloadcms/payload

    A skill your agent uses when changing or reviewing rendered Payload UI, interaction or focus behavior, semantic markup, accessibility tests, or WCAG/VPAT evidence.

    45k GitHub stars~808 tokensUpdated today
    Auto-check passed

Questions about Audit Dependencies

What does Audit Dependencies do?

A skill your agent uses when fixing dependency vulnerabilities, running pnpm audit, or when the audit-dependencies CI check fails. Audit Dependencies is an agent skill from payloadcms/payload.

When should I use Audit Dependencies?

Audit Dependencies fits situations like: fixing dependency vulnerabilities; running pnpm audit; the audit-dependencies CI check fails.

How do I install Audit Dependencies in Claude Code?

Run `npx skills add payloadcms/payload --skill audit-dependencies -a claude-code`. Or copy the skill folder (.agents/skills/audit-dependencies in payloadcms/payload) into .claude/skills/audit-dependencies in your project. Claude Code loads it when a task matches its description.

How do I install Audit Dependencies in Codex?

Run `npx skills add payloadcms/payload --skill audit-dependencies -a codex`. Or copy the skill folder (.agents/skills/audit-dependencies in payloadcms/payload) into .agents/skills/audit-dependencies in your project. Codex loads it when a task matches its description.

Can I use Audit Dependencies in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add payloadcms/payload --skill audit-dependencies -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/audit-dependencies, .gemini/skills/audit-dependencies, .github/skills/audit-dependencies and .opencode/skills/audit-dependencies in your project.

What does Audit Dependencies need to run?

Going by SKILL.md and its folder, Audit Dependencies needs the command-line tools its instructions call (pnpm and gh).

Does Audit Dependencies access the network?

SKILL.md names 1 domain. In commands or code: github.com; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.

Is Audit Dependencies safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Audit Dependencies use?

Audit Dependencies is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Audit Dependencies use?

About 2.8k tokens (SKILL.md is roughly 11k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Audit Dependencies?

Skills that share tags, products or a category with Audit Dependencies: Audit Fix (openplayerjs/openplayerjs, 649 stars), Security Vuln Remediation (stacklok/toolhive-studio, 170 stars), Cve Scan (softspark/ai-toolkit, 179 stars) and Dependency Awareness (Goldziher/ai-rulez, 153 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Audit Dependencies?

payloadcms (a GitHub organization) maintains it in payloadcms/payload, which has 45,120 GitHub stars. The repository holds 9 skills in this directory. The repository was last updated on October 7, 2026.

Source: payloadcms/payload on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.