Audit Fix
openplayerjs/openplayerjs
Resolve a pnpm audit (dependency-audit CI job) failure — high/critical CVEs in the dependency tree.
A skill your agent uses when fixing dependency vulnerabilities, running pnpm audit, or when the audit-dependencies CI check fails
$ npx skills add payloadcms/payload --skill audit-dependencies -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install payloadcms/payload audit-dependencies --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/payloadcms/payload.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/audit-dependencies .claude/skills/audit-dependencies && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "audit-dependencies" agent skill from https://github.com/payloadcms/payload/tree/main/.agents/skills/audit-dependencies into .claude/skills/audit-dependencies/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "audit-dependencies", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/payloadcms/payload/tree/main/.agents/skills/audit-dependenciesType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add payloadcms/payload --skill audit-dependencies -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install payloadcms/payload audit-dependencies --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/payloadcms/payload.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.agents/skills/audit-dependencies .agents/skills/audit-dependencies && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "audit-dependencies" agent skill from https://github.com/payloadcms/payload/tree/main/.agents/skills/audit-dependencies into .agents/skills/audit-dependencies/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "audit-dependencies", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add payloadcms/payload --skill audit-dependencies -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install payloadcms/payload audit-dependencies --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/payloadcms/payload.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.agents/skills/audit-dependencies .cursor/skills/audit-dependencies && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "audit-dependencies" agent skill from https://github.com/payloadcms/payload/tree/main/.agents/skills/audit-dependencies into .cursor/skills/audit-dependencies/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "audit-dependencies", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/payloadcms/payload.git --path .agents/skills/audit-dependencies--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add payloadcms/payload --skill audit-dependencies -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install payloadcms/payload audit-dependencies --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/payloadcms/payload.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.agents/skills/audit-dependencies .gemini/skills/audit-dependencies && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "audit-dependencies" agent skill from https://github.com/payloadcms/payload/tree/main/.agents/skills/audit-dependencies into .gemini/skills/audit-dependencies/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "audit-dependencies", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install payloadcms/payload audit-dependenciesInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add payloadcms/payload --skill audit-dependencies -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/payloadcms/payload.git skills-src && mkdir -p .github/skills && cp -r skills-src/.agents/skills/audit-dependencies .github/skills/audit-dependencies && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "audit-dependencies" agent skill from https://github.com/payloadcms/payload/tree/main/.agents/skills/audit-dependencies into .github/skills/audit-dependencies/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "audit-dependencies", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add payloadcms/payload --skill audit-dependencies -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install payloadcms/payload audit-dependencies --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/payloadcms/payload.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.agents/skills/audit-dependencies .opencode/skills/audit-dependencies && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "audit-dependencies" agent skill from https://github.com/payloadcms/payload/tree/main/.agents/skills/audit-dependencies into .opencode/skills/audit-dependencies/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "audit-dependencies", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
audit-dependenciesA skill your agent uses when fixing dependency vulnerabilities, running pnpm audit, or when the audit-dependencies CI check fails
Audit Dependencies is an agent skill from payloadcms/payload. Use when fixing dependency vulnerabilities, running pnpm audit, or when the audit-dependencies CI check fails
Its SKILL.md is about 2.8k tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files (for example `agents/openai.yaml`).
It sits in Security, covering Vulnerability scanning. It works with pnpm, Payload CMS and Next.js. The repository describes itself as: Payload is the open-source, fullstack Next.js framework, giving you instant backend superpowers. Get a full TypeScript backend and admin panel instantly. Use Payload as a… The licence is MIT.
8 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit ed6a954. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
pnpmghFrom the folder's file list and the shell code blocks in SKILL.md.
Hosts in commands or code, which the agent is likely to contact:
github.comFrom URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Audit Dependencies loads about 2.8k tokens when it runs. Until then it costs about 32 tokens; SKILL.md has 925 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from payloadcms/payload at commit ed6a954, republished under its MIT licence (© payloadcms). 925 words, ~2,768 tokens.
.claude/skills/audit-dependencies/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.Fix dependency vulnerabilities reported by .github/workflows/audit-dependencies.sh. Prefer fixes in this order: direct dependency bump > lockfile update > pnpm override. Every override requires justification for why simpler approaches aren't feasible.
digraph audit {
"Run audit script" [shape=box];
"Group by package" [shape=box];
"Trace dependency chain" [shape=box];
"Can bump direct dep?" [shape=diamond];
"Research breaking changes" [shape=box];
"Breaking changes acceptable?" [shape=diamond];
"Apply direct bump" [shape=box];
"Is version pinned or ranged?" [shape=diamond];
"Lockfile update" [shape=box];
"Apply pnpm override" [shape=box];
"More packages?" [shape=diamond];
"Present plan to user" [shape=box];
"Install and verify" [shape=box];
"Build and verify" [shape=box];
"Commit and create PR" [shape=box];
"Run audit script" -> "Group by package";
"Group by package" -> "Trace dependency chain";
"Trace dependency chain" -> "Can bump direct dep?";
"Can bump direct dep?" -> "Research breaking changes" [label="yes"];
"Can bump direct dep?" -> "Is version pinned or ranged?" [label="no"];
"Research breaking changes" -> "Breaking changes acceptable?";
"Breaking changes acceptable?" -> "Apply direct bump" [label="yes"];
"Breaking changes acceptable?" -> "Is version pinned or ranged?" [label="no"];
"Is version pinned or ranged?" -> "Lockfile update" [label="ranged - fix is in range"];
"Is version pinned or ranged?" -> "Apply pnpm override" [label="pinned - explain why"];
"Apply direct bump" -> "More packages?";
"Lockfile update" -> "More packages?";
"Apply pnpm override" -> "More packages?";
"More packages?" -> "Trace dependency chain" [label="yes"];
"More packages?" -> "Present plan to user" [label="no"];
"Present plan to user" -> "Install and verify";
"Install and verify" -> "Build and verify";
"Build and verify" -> "Commit and create PR";
}./.github/workflows/audit-dependencies.sh $ARGUMENTS$ARGUMENTS is the severity passed to the skill (defaults to high if omitted). The script runs pnpm audit --prod --json and filters for actionable vulnerabilities (those with a patched version available). high includes critical.
Parse the output to build a deduplicated list of vulnerable packages with:
packages/plugin-sentry > @sentry/nextjs > rollup)Identify whether the vulnerable package is:
package.jsonFor transitive deps, walk up the chain to find the nearest package you control:
pnpm view <parent>@latest dependencies.<vulnerable-pkg>Parallelize research: When multiple packages need breaking change analysis, dispatch parallel agents (one per package) to research simultaneously.
Before reaching for an override, check whether the parent's version specifier is pinned (exact version like 3.10.3) or ranged (like ^2.3.1, ~4.0.3):
pnpm view <parent> dependencies.<vulnerable-pkg>If the range already includes the fixed version, a lockfile update is all that's needed:
pnpm update <vulnerable-pkg> --recursiveNo package.json changes required — the lockfile was just stale.
Add a pnpm override in root package.json only when:
Override format: "<parent>><vulnerable-pkg>": "^<fixed-version>"
Override syntax rules:
^ ranges, not >=. >= can cross major versions and cause unexpected resolutions (e.g., "picomatch": ">=2.3.2" can resolve to 4.x)."parent>pkg" works, "grandparent>parent>pkg" does not."pkg@^2" does not work.overrides in the root workspace package.json. Overrides in workspace packages are ignored.Before adding any override, verify the target version exists:
pnpm view <pkg>@<version> versionBefore applying fixes, present a summary table to the user showing each vulnerability, the proposed fix strategy (direct bump / lockfile update / override), and justification. Get confirmation before proceeding.
package.json files for direct bumpspnpm update <pkg> --recursive for lockfile-only fixespackage.json pnpm.overrides for overrides (keep alphabetical)allowOverwrite: true when an API default changes)pnpm installIf install fails due to native build errors (e.g., better-sqlite3), fall back to:
pnpm install --ignore-scriptsThen re-run the audit script with the same severity:
./.github/workflows/audit-dependencies.sh $ARGUMENTSThe audit script must exit 0. If vulnerabilities remain, check for additional instances of the same dependency in other workspace packages.
pnpm run build:coreFor packages with changed dependencies, also run their specific build:
pnpm run build:<package-name>For each fixed vulnerability, find the GitHub Security Advisory (GHSA):
https://github.com/<org>/<repo>/security/advisories for each package<package-name> GHSA <fixed-version>https://github.com/advisories/GHSA-xxxx-xxxx-xxxx) over NVD linksParallelize CVE lookups: Dispatch parallel agents to search for CVEs across all packages simultaneously.
Commit with conventional commit format:
fix(deps): resolve $ARGUMENTS severity audit vulnerabilitiesCreate PR using gh pr create with this body structure:
# Overview
[What the PR fixes, mention `pnpm audit --prod`]
## Key Changes
- **[Package name] in [workspace path]**
- [old version] → [new version]. Fixes [GHSA-xxxx-xxxx-xxxx](https://github.com/advisories/GHSA-xxxx-xxxx-xxxx) ([description]).
- [Why this approach: direct bump because X / lockfile update because Y / override because Z]
- [Any code changes required by the bump]
## Design Decisions
[Why direct bumps were preferred, justification for any remaining overrides]| Mistake | Fix |
|---|---|
| Jumping straight to overrides | Check: can you bump the parent? If not, does the semver range already allow the fix (lockfile update)? Only then override. |
Using >= in override ranges | Use ^ to stay within the same major version. >=2.3.2 can resolve to 4.x. |
| Not checking pinned vs ranged | pnpm view <parent> dependencies.<pkg> — if ranged and the fix is in range, just pnpm update. |
Nested override scoping (a>b>c) | pnpm only supports single-level: "parent>pkg". For deeper chains, override the direct parent or use a global override. |
Version selectors in override keys (pkg@^2) | Not supported by pnpm. Use parent-scoped or global overrides instead. |
| Global override affecting multiple major versions | "picomatch": ">=4.0.4" forces all picomatch to 4.x, breaking consumers that need 2.x. Scope overrides to the parent when a package spans multiple majors. |
| Not checking all workspace packages | Same dep may appear in multiple package.json files (e.g., changelogen in both tools/releaser and tools/scripts) |
| Overriding with a nonexistent version | Verify the target version exists with pnpm view before installing |
Not falling back to --ignore-scripts | Pre-existing native build failures block pnpm install; use --ignore-scripts to get lockfile updated |
| Missing code changes for breaking bumps | If a bump changes API defaults, update the calling code |
| Forgetting advisory links in PR | Always look up and include GHSA links for each vulnerability |
| Applying fixes without user confirmation | Present the full plan (strategy per vuln + justification) and get confirmation before making changes |
© payloadcms, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 1 other file in .agents/skills/audit-dependencies of payloadcms/payload.
Open the folder on GitHubat commit ed6a954
Audit Dependencies next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Audit Dependencies this skillpayloadcms/payload | 45k | — | ~2.8k | Automated safety check: Pass | MIT | |
| Audit Fixopenplayerjs/openplayerjs | 649 | — | ~1k | Automated safety check: Pass | MIT | |
| Security Vuln Remediationstacklok/toolhive-studio | 170 | — | ~2.3k | Automated safety check: Notes | Apache-2.0 | |
| Cve Scansoftspark/ai-toolkit | 179 | — | ~1.3k | Automated safety check: Notes | Apache-2.0 | |
| Dependency AwarenessGoldziher/ai-rulez | 153 | — | ~250 | Automated safety check: Pass | MIT | |
| Testingtrieb-work/nextjs-turbo-redis-cache | 151 | — | ~1.1k | Automated safety check: Pass | MIT |
openplayerjs/openplayerjs
Resolve a pnpm audit (dependency-audit CI job) failure — high/critical CVEs in the dependency tree.
stacklok/toolhive-studio
Remediate security vulnerabilities found by Grype or pnpm audit.
softspark/ai-toolkit
Scans deps for known CVEs via native audit (npm, pip, composer, cargo, go, bundler, dart).
Goldziher/ai-rulez
Per-language dependency vulnerability audit tool reference (cargo audit/deny, pip-audit, npm/pnpm audit, govulncheck, bundler-audit, composer audit, OWASP dependency-check, dotnet vulnerable…
trieb-work/nextjs-turbo-redis-cache
Run tests and add Next.js version coverage for the cache handler.
unional/typescript-blackbook
Fix a PR that is failing due to security or vulnerability issues — npm/pnpm/yarn/bun audit failures, CVE alerts, Dependabot merge conflicts, Snyk failures, or GitHub security advisory blocks.
payloadcms/payload
A skill your agent uses when a Payload pull request needs a concise visual walkthrough for reviewers.
payloadcms/payload
A skill your agent uses when working with Payload projects (payload.config.ts, collections, fields, hooks, access control, Payload API).
payloadcms/payload
A skill your agent uses when new translation keys are added to packages to generate new translations strings
payloadcms/payload
A skill your agent uses when CI tests fail on main branch after PR merge, when investigating flaky test failures, or when user provides a PR URL/number to aggregate all failing tests
payloadcms/payload
A skill your agent uses when UI changes are complete and e2e tests need updating.
payloadcms/payload
A skill your agent uses when changing or reviewing rendered Payload UI, interaction or focus behavior, semantic markup, accessibility tests, or WCAG/VPAT evidence.
Works with
Categories
A skill your agent uses when fixing dependency vulnerabilities, running pnpm audit, or when the audit-dependencies CI check fails. Audit Dependencies is an agent skill from payloadcms/payload.
Audit Dependencies fits situations like: fixing dependency vulnerabilities; running pnpm audit; the audit-dependencies CI check fails.
Run `npx skills add payloadcms/payload --skill audit-dependencies -a claude-code`. Or copy the skill folder (.agents/skills/audit-dependencies in payloadcms/payload) into .claude/skills/audit-dependencies in your project. Claude Code loads it when a task matches its description.
Run `npx skills add payloadcms/payload --skill audit-dependencies -a codex`. Or copy the skill folder (.agents/skills/audit-dependencies in payloadcms/payload) into .agents/skills/audit-dependencies in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add payloadcms/payload --skill audit-dependencies -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/audit-dependencies, .gemini/skills/audit-dependencies, .github/skills/audit-dependencies and .opencode/skills/audit-dependencies in your project.
Going by SKILL.md and its folder, Audit Dependencies needs the command-line tools its instructions call (pnpm and gh).
SKILL.md names 1 domain. In commands or code: github.com; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Audit Dependencies is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 2.8k tokens (SKILL.md is roughly 11k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Audit Dependencies: Audit Fix (openplayerjs/openplayerjs, 649 stars), Security Vuln Remediation (stacklok/toolhive-studio, 170 stars), Cve Scan (softspark/ai-toolkit, 179 stars) and Dependency Awareness (Goldziher/ai-rulez, 153 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
payloadcms (a GitHub organization) maintains it in payloadcms/payload, which has 45,120 GitHub stars. The repository holds 9 skills in this directory. The repository was last updated on October 7, 2026.
Source: payloadcms/payload on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.