Dependency Scanning
sickn33/agentic-awesome-skills
Scan package dependencies for known vulnerabilities using Snyk, Dependabot, and OWASP Dependency-Check.
L9-L12 依賴關係驗證 - 檢查導入語句、標準庫、第三方庫、循環依賴. An agent skill from peijun1700/bluemouse.
$ npx skills add peijun1700/bluemouse --skill validate-dependencies -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install peijun1700/bluemouse validate-dependencies --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/peijun1700/bluemouse.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/validate-dependencies .claude/skills/validate-dependencies && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "validate-dependencies" agent skill from https://github.com/peijun1700/bluemouse/tree/main/.claude/skills/validate-dependencies into .claude/skills/validate-dependencies/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "validate-dependencies", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/peijun1700/bluemouse/tree/main/.claude/skills/validate-dependenciesType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add peijun1700/bluemouse --skill validate-dependencies -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install peijun1700/bluemouse validate-dependencies --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/peijun1700/bluemouse.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.claude/skills/validate-dependencies .agents/skills/validate-dependencies && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "validate-dependencies" agent skill from https://github.com/peijun1700/bluemouse/tree/main/.claude/skills/validate-dependencies into .agents/skills/validate-dependencies/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "validate-dependencies", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add peijun1700/bluemouse --skill validate-dependencies -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install peijun1700/bluemouse validate-dependencies --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/peijun1700/bluemouse.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.claude/skills/validate-dependencies .cursor/skills/validate-dependencies && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "validate-dependencies" agent skill from https://github.com/peijun1700/bluemouse/tree/main/.claude/skills/validate-dependencies into .cursor/skills/validate-dependencies/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "validate-dependencies", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/peijun1700/bluemouse.git --path .claude/skills/validate-dependencies--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add peijun1700/bluemouse --skill validate-dependencies -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install peijun1700/bluemouse validate-dependencies --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/peijun1700/bluemouse.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.claude/skills/validate-dependencies .gemini/skills/validate-dependencies && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "validate-dependencies" agent skill from https://github.com/peijun1700/bluemouse/tree/main/.claude/skills/validate-dependencies into .gemini/skills/validate-dependencies/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "validate-dependencies", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install peijun1700/bluemouse validate-dependenciesInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add peijun1700/bluemouse --skill validate-dependencies -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/peijun1700/bluemouse.git skills-src && mkdir -p .github/skills && cp -r skills-src/.claude/skills/validate-dependencies .github/skills/validate-dependencies && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "validate-dependencies" agent skill from https://github.com/peijun1700/bluemouse/tree/main/.claude/skills/validate-dependencies into .github/skills/validate-dependencies/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "validate-dependencies", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add peijun1700/bluemouse --skill validate-dependencies -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install peijun1700/bluemouse validate-dependencies --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/peijun1700/bluemouse.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.claude/skills/validate-dependencies .opencode/skills/validate-dependencies && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "validate-dependencies" agent skill from https://github.com/peijun1700/bluemouse/tree/main/.claude/skills/validate-dependencies into .opencode/skills/validate-dependencies/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "validate-dependencies", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
validate-dependenciesL9-L12 依賴關係驗證 - 檢查導入語句、標準庫、第三方庫、循環依賴. An agent skill from peijun1700/bluemouse.
Validate Dependencies is an agent skill from peijun1700/bluemouse. L9-L12 依賴關係驗證 - 檢查導入語句、標準庫、第三方庫、循環依賴。 BlueMouse 17-Layer Validation Group 3。 Triggers: "dependencies", "imports", "依賴檢查", "circular"
Its SKILL.md is about 1k tokens, which your agent loads only when the skill is triggered. The skill folder holds 1 other file (for example `validator.py`).
The licence is AGPL-3.0.
2 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 4f32ef0. It shows what the files ask for, not the result of running them.
Pre-approves these tools, so the agent can use them without asking each time:
ReadBashGrepFrom allowed-tools in the SKILL.md frontmatter.
Ships script files (Python), which the agent can run.
Shell commands in SKILL.md call:
python3From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Validate Dependencies loads about 1k tokens when it runs. Until then it costs about 39 tokens; SKILL.md has 170 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check noted patterns worth knowing about, such as sudo or a known installer.
allowed-tools: Read, Bash, GrepAutomated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from peijun1700/bluemouse at commit 4f32ef0, republished under its AGPL-3.0 licence (© peijun1700). 170 words, ~1,016 tokens.
.claude/skills/validate-dependencies/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.BlueMouse 17-Layer Validation System - Group 3: 依賴關係驗證
Follow the checklist below to analyze code.
python3 .claude/skills/validate-dependencies/validator.py myfile.py
python3 .claude/skills/validate-dependencies/validator.py --verbose myfile.pyWhat: Count import statements in code
How:
imports = [
node for node in ast.walk(tree)
if isinstance(node, (ast.Import, ast.ImportFrom))
]Output: "找到 N 個導入語句"
Pass: Always (informational only)
What: Identify Python standard library usage
Known Stdlib:
stdlib = {
'os', 'sys', 'json', 're', 'datetime', 'typing',
'asyncio', 'time', 'math', 'hashlib', 'collections',
'functools', 'itertools', 'pathlib', 'subprocess',
'threading', 'multiprocessing', 'logging', 'unittest',
'argparse', 'copy', 'io', 'tempfile'
}How:
import_names = []
for node in ast.walk(tree):
if isinstance(node, ast.Import):
for n in node.names:
import_names.append(n.name.split('.')[0])
elif isinstance(node, ast.ImportFrom):
if node.module:
import_names.append(node.module.split('.')[0])
used = [name for name in import_names if name in stdlib]Output: "精確識別出 N 個標準庫導入"
Pass: Always (informational only)
What: Identify common third-party library usage
Known Third-Party:
third_party = {
'django', 'flask', 'fastapi', 'requests', 'numpy',
'pandas', 'pytest', 'aiohttp', 'sqlalchemy', 'pydantic',
'httpx', 'redis', 'celery', 'boto3', 'tensorflow',
'torch', 'scikit-learn'
}How:
used = []
for module in third_party:
if f"import {module}" in code or f"from {module}" in code:
used.append(module)Output:
"使用了 N 個第三方庫""未使用第三方庫"Pass: Always (informational only)
What: Detect risky relative imports that may cause circular dependencies
How:
for node in ast.walk(tree):
if isinstance(node, ast.ImportFrom) and node.level > 0:
has_relative = TrueImport Level Explanation:
| Code | Level | Risk |
|---|---|---|
import os | 0 | ✅ Safe |
from module import x | 0 | ✅ Safe |
from .sibling import x | 1 | ⚠️ Risky |
from ..parent import x | 2 | ⚠️ Risky |
Pass: No relative imports → "通過 (未檢測到危險的相對導入)"
Fail: "檢測到相對導入,可能存在循環依賴風險"
Examples:
# ✅ PASS: Absolute imports only
import os
from package.module import func
from typing import Dict
# ❌ FAIL: Relative imports
from .sibling import helper # level=1
from ..parent import config # level=2Why Relative Imports Are Risky:
project/
├── package_a/
│ └── module_a.py # from ..package_b import func_b
└── package_b/
└── module_b.py # from ..package_a import func_a
# ❌ Circular dependency!==================================================
L9-L12: 依賴關係驗證
==================================================
Status: ✅ PASSED / ❌ FAILED
Score: X/100 (N/4 layers)
✅ L9: 導入檢查 - 找到 N 個導入語句
✅ L10: 標準庫檢查 - 精確識別出 N 個標準庫導入
✅ L11: 第三方庫檢查 - 使用了 N 個第三方庫
✅/❌ L12: 循環依賴檢查 - [message]
[Verbose mode shows detected libraries]| Skill | Layers |
|---|---|
/validate-17-layers | L1-L17 (完整) |
/validate-syntax | L1-L4 |
/validate-signature | L5-L8 |
/validate-dependencies | L9-L12 |
/validate-logic | L13-L17 |
Part of BlueMouse 17-Layer Validation System
© peijun1700, AGPL-3.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 1 other file in .claude/skills/validate-dependencies of peijun1700/bluemouse.
Open the folder on GitHubat commit 4f32ef0
Validate Dependencies next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Validate Dependencies this skillpeijun1700/bluemouse | 109 | — | ~1k | Automated safety check: Notes | AGPL-3.0 | |
| Dependency Scanningsickn33/agentic-awesome-skills | 47k | 1 repos | ~2.4k | Automated safety check: Pass | MIT | |
| Dependency Checkruvnet/ruflo | 74k | — | ~258 | Automated safety check: Pass | MIT | |
| Dependency Updatecodewhale-hq/Codewhale | 41k | — | ~142 | Automated safety check: Pass | MIT | |
| Bump Sentry Dependencygetsentry/sentry | 46k | — | ~815 | Automated safety check: Pass | Custom licence | |
| Logseq Dependency Upgradelogseq/logseq | 45k | — | ~1.1k | Automated safety check: Pass | AGPL-3.0 |
sickn33/agentic-awesome-skills
Scan package dependencies for known vulnerabilities using Snyk, Dependabot, and OWASP Dependency-Check.
ruvnet/ruflo
Scan project dependencies for known vulnerabilities and CVEs.
codewhale-hq/Codewhale
Read release notes/changelogs, update a defined dependency scope, handle breaking changes, and verify.
getsentry/sentry
Bumps an existing Python dependency in getsentry/sentry through the repository's self-serve GitHub Actions workflow.
logseq/logseq
Audit, plan, and refresh dependency upgrades for the Logseq repository by scanning every non-gitignored package.json, deps.edn, bb.edn and nbb.edn manifest, checking latest upstream versions…
payloadcms/payload
A skill your agent uses when fixing dependency vulnerabilities, running pnpm audit, or when the audit-dependencies CI check fails
peijun1700/bluemouse
L13-L17 類型和邏輯驗證 - 檢查類型一致性、邏輯完整性、錯誤處理、安全性、性能. An agent skill from peijun1700/bluemouse.
peijun1700/bluemouse
L5-L8 函數簽名驗證 - 檢查參數、返回值、類型提示、文檔字符串. An agent skill from peijun1700/bluemouse.
peijun1700/bluemouse
L1-L4 語法和結構驗證 - 檢查 Python 語法、AST 結構、縮進格式、命名規範. An agent skill from peijun1700/bluemouse.
peijun1700/bluemouse
The BlueMouse 17-Layer Alpha Scale (Static Standard). An agent skill from peijun1700/bluemouse.
L9-L12 依賴關係驗證 - 檢查導入語句、標準庫、第三方庫、循環依賴. An agent skill from peijun1700/bluemouse. Validate Dependencies is an agent skill from peijun1700/bluemouse.
Run `npx skills add peijun1700/bluemouse --skill validate-dependencies -a claude-code`. Or copy the skill folder (.claude/skills/validate-dependencies in peijun1700/bluemouse) into .claude/skills/validate-dependencies in your project. Claude Code loads it when a task matches its description.
Run `npx skills add peijun1700/bluemouse --skill validate-dependencies -a codex`. Or copy the skill folder (.claude/skills/validate-dependencies in peijun1700/bluemouse) into .agents/skills/validate-dependencies in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add peijun1700/bluemouse --skill validate-dependencies -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/validate-dependencies, .gemini/skills/validate-dependencies, .github/skills/validate-dependencies and .opencode/skills/validate-dependencies in your project.
Going by SKILL.md and its folder, Validate Dependencies needs Python for the scripts in its folder and the command-line tools its instructions call (python3). Our summary lists: Python 3. Its frontmatter pre-approves these tools: Read, Bash, Grep.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found notes only (pre-approves every shell command (allowed-tools: bash)), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.
Validate Dependencies is published under the AGPL-3.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 1k tokens (SKILL.md is roughly 4.1k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Validate Dependencies: Dependency Scanning (sickn33/agentic-awesome-skills, 47k stars), Dependency Check (ruvnet/ruflo, 74k stars), Dependency Update (codewhale-hq/Codewhale, 41k stars) and Bump Sentry Dependency (getsentry/sentry, 46k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
peijun1700 (a GitHub user) maintains it in peijun1700/bluemouse, which has 109 GitHub stars. The repository holds 5 skills in this directory. The repository was last updated on January 29, 2026.
Source: peijun1700/bluemouse on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.