Agent skill

Dependency Audit

by PlamenTSV in PlamenTSV/plamen

Trigger EXTERNALLIB flag detected (protocol uses third-party Move dependencies) - Used by Breadth agents, depth-external

MITAuto-check passed

Install Dependency Audit

skills CLI
$ npx skills add PlamenTSV/plamen --skill dependency-audit -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install PlamenTSV/plamen dependency-audit --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/PlamenTSV/plamen.git skills-src && mkdir -p .claude/skills && cp -r skills-src/agents/skills/aptos/dependency-audit .claude/skills/dependency-audit && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
dependency-audit
GitHub stars
303
Token cost
~2.4k tokens
SKILL.md length
976 words
Files
1
Skills in repo
87
Repo updated
First seen
Licence
MIT

At a glance

Trigger EXTERNALLIB flag detected (protocol uses third-party Move dependencies) - Used by Breadth agents, depth-external

  • Works in 4 steps: Dependency Inventory → Upgrade Policy Risk Assessment → Critical Function Audit → …
  • EXTERNALLIB flag detected (protocol uses third-party Move dependencies) - Used by Breadth agents
  • SKILL.md covers Purpose, Methodology, Key Questions (Must Answer All) and Common False Positives, plus 2 more sections
  • Calls git

What it does

Dependency Audit is an agent skill from PlamenTSV/plamen. Trigger EXTERNALLIB flag detected (protocol uses third-party Move dependencies) - Used by Breadth agents, depth-external

Its SKILL.md is about 2.4k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

The repository describes itself as: Autonomous Web3 security audit agent for Claude Code. The licence is MIT.

When your agent uses it

  • EXTERNALLIB flag detected (protocol uses third-party Move dependencies) - Used by Breadth agents

Example prompts

  • “/dependency-audit”

Workflow steps

4 steps, taken from the step headings in SKILL.md.

  1. Dependency Inventory
  2. Upgrade Policy Risk Assessment
  3. Critical Function Audit
  4. Transitive Dependency Analysis

What it can do on your machine

Read from SKILL.md and the folder at commit 795962b. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • git

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use git, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Dependency Audit loads about 2.4k tokens when it runs. Until then it costs about 35 tokens; SKILL.md has 976 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~35
When it runs · the whole SKILL.md, loaded when a task matches
~2.4k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from PlamenTSV/plamen at commit 795962b, republished under its MIT licence (© PlamenTSV). 976 words, ~2,447 tokens.

Download SKILL.mdSave it as .claude/skills/dependency-audit/SKILL.md (or your agent's skills folder).
name
dependency-audit
description
Trigger EXTERNAL_LIB flag detected (protocol uses third-party Move dependencies) - Used by Breadth agents, depth-external

Skill: DEPENDENCY_AUDIT

Trigger: EXTERNAL_LIB flag detected (protocol uses third-party Move dependencies) Used by: Breadth agents, depth-external Covers: Third-party library security, upgrade policy risks, critical function correctness, transitive dependency chains

Purpose

Audit third-party Move dependencies for security risks. Aptos protocols commonly depend on external math libraries, utility modules, and protocol SDKs. Unlike EVM (where dependencies are compiled into the contract), Move dependencies are on-chain modules that can be independently upgraded. A dependency upgrade can silently change the behavior of the audited protocol.

Methodology

STEP 1: Dependency Inventory

Parse Move.toml for all dependencies. Categorize each:

#DependencySourceCategoryUpgrade PolicyRevision Pinned?
1AptosFrameworkaptos-framework repoFRAMEWORKFramework governance{rev hash or branch}
2AptosStdaptos-framework repoFRAMEWORKFramework governance{rev hash or branch}
3AptosTokenaptos-framework repoFRAMEWORKFramework governance{rev hash or branch}
4{third_party_lib}{git URL}THIRD_PARTY{compatible/immutable/unknown}{YES: rev=abc123 / NO: branch=main}
5{sub_module}local pathIN_SCOPEN/A (part of audit)N/A

Categories:

  • FRAMEWORK: aptos_framework, aptos_std, aptos_token, aptos_token_objects - trusted, framework-governance-controlled. Audit framework USAGE, not framework internals.
  • THIRD_PARTY: External libraries (math utils, oracle SDKs, DEX interfaces). MUST audit all called functions.
  • IN_SCOPE: Protocol's own sub-modules. Fully in scope.

MANDATORY PARSE: Read Move.toml (and any sub-package Move.toml files) for:

  1. [dependencies] section entries
  2. git = "..." URLs - identify the source repository
  3. rev = "..." - pinned revision hash (safe) vs branch = "main" (dangerous)
  4. local = "..." - in-scope sub-modules
STEP 2: Upgrade Policy Risk Assessment

For each THIRD_PARTY dependency:

DependencyOn-Chain AddressUpgrade PolicyCan Upgrade Without Protocol Knowledge?Risk Level
{lib}{0x...}immutableNOLOW
{lib}{0x...}compatibleYES - publisher can add functions, change logicHIGH
{lib}{0x...}unknownVERIFY ON-CHAINASSESS

Check for each compatible dependency:

  1. Can the dependency publisher add new friend declarations (giving new modules access to internal state)?
  2. Can the dependency publisher change function implementations (same signature, different logic)?
  3. Can the dependency publisher add new public functions that interact with stored state?
  4. Does the audited protocol store any state that the dependency module can access?
  5. Is there a governance/multisig controlling the dependency's publisher address?

Severity: If a compatible third-party dependency can be upgraded to change behavior of functions the protocol calls, AND the protocol has no way to detect or prevent this -> minimum MEDIUM finding.

Pinning check: If Move.toml uses branch = "main" instead of rev = "abc123":

  • Build reproducibility is broken
  • Developer may unknowingly compile against a different version
  • Document as INFO finding (build hygiene)
STEP 3: Critical Function Audit

For each function called from a THIRD_PARTY dependency:

3a. Function Inventory
#Called FunctionFrom ModuleParametersReturn TypeFrequencyImpact If Wrong
1{lib::func()}{our_module}{params}{return}{every tx / periodic / init only}{describe}
3b. Correctness Verification

For each critical function (called frequently OR high impact if wrong):

Overflow/underflow check:

  1. Does the function handle multiplication overflow? (e.g., a * b where both are u64 - can overflow)
  2. Does it handle division by zero?
  3. Does it use intermediate u128 for precision in u64 arithmetic?
  4. Bit shift safety: Does it use << or >>? If so, is the shift amount bounded to < 64 (for u64) or < 128 (for u128)? Unbounded bit shifts are a known attack vector (historical exploit: bit shift overflow in a custom shift helper allowed minting tokens from minimal liquidity).

Edge case check:

InputExpected OutputActual OutputCorrect?
0{expected}{verify}YES/NO
1{expected}{verify}YES/NO
MAX_U64{expected: revert or handled}{verify}YES/NO
MAX_U128{expected}{verify}YES/NO

Specification check:

  • Does the function have documented behavior? (comments, spec blocks)
  • Does the implementation match the specification?
  • If the function is a math operation: verify against a reference implementation or mathematical formula
Show full SKILL.md (383 more words)Show less
3c. Trust Boundary Analysis

For each third-party function call:

CallTrusts Dependency ToWhat If Dependency Lies/BreaksDetection?
{lib::get_price()}Return accurate priceProtocol uses wrong price → fund loss{sanity check present?}
{lib::sqrt(x)}Return correct sqrtWrong math → accounting error{no detection}

Check: Does the protocol validate the RETURN VALUE of third-party calls? Or does it blindly trust the result?

If no validation AND high impact -> FINDING.

STEP 4: Transitive Dependency Analysis

Check whether third-party dependencies have their own dependencies:

4a. Dependency Tree
Protocol
├── aptos_framework (FRAMEWORK)
├── third_party_lib_A
│   ├── aptos_framework (FRAMEWORK - OK, shared)
│   └── third_party_lib_B (THIRD_PARTY - audit this!)
│       └── aptos_std (FRAMEWORK - OK)
└── third_party_lib_C
    └── (no additional deps)
4b. Transitive Risk Assessment
Transitive DependencyReached ViaUpgrade PolicyAudited?Risk
{lib_B}lib_A -> lib_B{policy}YES/NO{assess}

Check:

  1. Are ALL transitive dependencies pinned to specific revisions?
  2. Can a transitive dependency be upgraded independently, changing the behavior of the direct dependency?
  3. Are there version conflicts (two dependencies requiring different versions of the same module)?

Key Questions (Must Answer All)

  1. Pinning: Are all third-party dependencies pinned to specific git revisions?
  2. Upgrade risk: Can any dependency be upgraded without the protocol's knowledge?
  3. Math safety: Do all third-party math functions handle overflow, zero, and boundary inputs correctly?
  4. Bit shift safety: Are all bit shift operations bounded? (Critical after Cetus exploit)
  5. Trust validation: Does the protocol validate return values from third-party calls?
  6. Transitive exposure: Are there unaudited transitive dependencies?

Common False Positives

  1. Framework dependencies: aptos_framework, aptos_std, aptos_token are framework-governed and heavily audited - do not flag as third-party risk (but DO audit usage patterns)
  2. Immutable dependencies: If the on-chain module is published with immutable policy, upgrade risk is zero
  3. Pinned to audited revision: If the dependency is pinned to a specific, known-audited revision, transitive upgrade risk is build-time only (not runtime)
  4. Standard math operations: Framework-provided math64::mul_div() and similar are well-tested - focus audit on third-party math libraries

Output Schema

markdown
## Finding [DEP-N]: Title

**Verdict**: CONFIRMED / PARTIAL / REFUTED / CONTESTED
**Step Execution**: ✓1,2,3,4 | ✗N(reason) | ?N(uncertain)
**Rules Applied**: [R1:✓/✗, R4:✓/✗, R8:✓/✗, R10:✓/✗]
**Severity**: Critical/High/Medium/Low/Info
**Location**: Move.toml or module_name.move:LineN

**Dependency**: {name and source}
**Risk Type**: UPGRADE_RISK / MATH_ERROR / TRUST_BOUNDARY / TRANSITIVE_EXPOSURE
**Upgrade Policy**: {immutable/compatible/unknown}

**Description**: What's wrong
**Impact**: What can happen (silent behavior change, math error, fund loss)
**Evidence**: Code showing the dependency usage and risk

### Precondition Analysis (if PARTIAL/REFUTED)
**Missing Precondition**: [What blocks exploitation]
**Precondition Type**: STATE / ACCESS / TIMING / EXTERNAL / BALANCE

### Postcondition Analysis (if CONFIRMED/PARTIAL)
**Postconditions Created**: [What conditions this creates]
**Postcondition Types**: [List applicable types]
**Who Benefits**: [Who can use these]

Step Execution Checklist (MANDATORY)

StepRequiredCompleted?Notes
1. Dependency InventoryYES✓/✗/?All Move.toml entries parsed and categorized
2. Upgrade Policy RiskFOR EACH third-party dep✓/✗/?On-chain policy verified
3a. Function InventoryYES✓/✗/?All called functions from third-party listed
3b. Correctness VerificationFOR EACH critical function✓/✗/?Overflow, zero, MAX tested
3c. Trust Boundary AnalysisYES✓/✗/?Return value validation checked
4. Transitive Dependency AnalysisIF transitive deps exist✓/✗(N/A)/?Full tree mapped

If any step skipped, document valid reason (N/A, no third-party deps, all deps immutable).

© PlamenTSV, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in agents/skills/aptos/dependency-audit of PlamenTSV/plamen.

Open the folder on GitHubat commit 795962b

Compare with similar skills

Dependency Audit next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Dependency Audit compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Dependency Audit this skillPlamenTSV/plamen303—~2.4kAutomated safety check: PassMIT
Detecting Dependency Confusionmukul975/Anthropic-Cybersecurity-Skills34k—~2.9kAutomated safety check: WarnApache-2.0
Flagsvercel/next.js143k—~746Automated safety check: PassMIT
Dependency Scanningsickn33/agentic-awesome-skills47k1 repos~2.4kAutomated safety check: PassMIT
Dependency Checkruvnet/ruflo74k—~258Automated safety check: PassMIT
Detect Static Dependenciesdotnet/skills5.6k1 repos~3.8kAutomated safety check: PassMIT

Similar skills

  • Detecting Dependency Confusion

    mukul975/Anthropic-Cybersecurity-Skills

    Detect and prevent dependency confusion (public-over-private package name resolution) in npm, PyPI, and Maven by enumerating claimable internal package names with tools like confused and OWASP…

    34k GitHub stars~2.9k tokensUpdated 1 mo ago
    SecurityAuto-check: warnings
  • Flags

    vercel/next.js

    Official

    How to add or modify Next.js experimental feature flags end-to-end.

    143k GitHub stars~746 tokensUpdated today
    DevelopmentAuto-check passed
  • Dependency Scanning

    sickn33/agentic-awesome-skills

    Scan package dependencies for known vulnerabilities using Snyk, Dependabot, and OWASP Dependency-Check.

    47k GitHub starsUsed in 1 repo~2.4k tokens
    SecurityAuto-check passed
  • Dependency Check

    ruvnet/ruflo

    Scan project dependencies for known vulnerabilities and CVEs.

    74k GitHub stars~258 tokensUpdated today
    SecurityAuto-check passed
  • Official

    ACTIVATION PREREQUISITE: the request or discovered target must explicitly identify C, .NET, .cs, or .csproj; otherwise stay dormant without invoking this skill.

    5.6k GitHub starsUsed in 1 repo~3.8k tokens
    DevelopmentAuto-check passed
  • Pii Detect

    ruvnet/ruflo

    Detect and flag personally identifiable information (PII) in text, code, and configurations.

    74k GitHub starsUsed in 1 repo~350 tokens
    Auto-check: notes

More from PlamenTSV/plamen

All 87 skills in this repo
  • Audit Prep

    PlamenTSV/plamen

    Prepare Solidity projects for a security audit — test coverage, test quality, NatSpec docs, code hygiene, dependency health, best-practice enforcement, deployment readiness, and project…

    303 GitHub stars~3.7k tokensUpdated 12 days ago
    Auto-check passed
  • Verification Protocol

    PlamenTSV/plamen

    Trigger Pattern Always (used by all verifier agents) - Inject Into security-verifier agents (Phase 5)

    303 GitHub stars~3.5k tokensUpdated 12 days ago
    Auto-check passed
  • Ability Analysis

    PlamenTSV/plamen

    Trigger Pattern Always (Aptos Move) - foundational security check - Inject Into Breadth agents, depth agents

    303 GitHub stars~3.3k tokensUpdated 12 days ago
    Auto-check passed
  • Ability Analysis

    PlamenTSV/plamen

    Trigger Pattern Always (Sui Move) -- foundational security check - Inject Into Breadth agents, depth agents

    303 GitHub stars~3.2k tokensUpdated 12 days ago
    Auto-check passed
  • Account Lifecycle

    PlamenTSV/plamen

    Trigger Pattern ACCOUNTCLOSING flag detected (close/CloseAccount usage) - Inject Into Breadth agents, depth agents

    303 GitHub stars~1.2k tokensUpdated 12 days ago
    Auto-check passed
  • Account Validation

    PlamenTSV/plamen

    Trigger Pattern Always required for Solana audits - Inject Into Breadth agents, depth agents

    303 GitHub stars~1.7k tokensUpdated 12 days ago
    Auto-check passed

Questions about Dependency Audit

What does Dependency Audit do?

Trigger EXTERNALLIB flag detected (protocol uses third-party Move dependencies) - Used by Breadth agents, depth-external. Dependency Audit is an agent skill from PlamenTSV/plamen.

When should I use Dependency Audit?

Dependency Audit fits situations like: EXTERNALLIB flag detected (protocol uses third-party Move dependencies) - Used by Breadth agents.

How do I install Dependency Audit in Claude Code?

Run `npx skills add PlamenTSV/plamen --skill dependency-audit -a claude-code`. Or copy the skill folder (agents/skills/aptos/dependency-audit in PlamenTSV/plamen) into .claude/skills/dependency-audit in your project. Claude Code loads it when a task matches its description.

How do I install Dependency Audit in Codex?

Run `npx skills add PlamenTSV/plamen --skill dependency-audit -a codex`. Or copy the skill folder (agents/skills/aptos/dependency-audit in PlamenTSV/plamen) into .agents/skills/dependency-audit in your project. Codex loads it when a task matches its description.

Can I use Dependency Audit in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add PlamenTSV/plamen --skill dependency-audit -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/dependency-audit, .gemini/skills/dependency-audit, .github/skills/dependency-audit and .opencode/skills/dependency-audit in your project.

What does Dependency Audit need to run?

Going by SKILL.md and its folder, Dependency Audit needs the command-line tools its instructions call (git).

Does Dependency Audit access the network?

SKILL.md contains no URLs. Its commands use git, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Dependency Audit safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Dependency Audit use?

Dependency Audit is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Dependency Audit use?

About 2.4k tokens (SKILL.md is roughly 9.8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Dependency Audit?

Skills that share tags, products or a category with Dependency Audit: Detecting Dependency Confusion (mukul975/Anthropic-Cybersecurity-Skills, 34k stars), Flags (vercel/next.js, 143k stars), Dependency Scanning (sickn33/agentic-awesome-skills, 47k stars) and Dependency Check (ruvnet/ruflo, 74k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Dependency Audit?

PlamenTSV (a GitHub user) maintains it in PlamenTSV/plamen, which has 303 GitHub stars. The repository holds 87 skills in this directory. The repository was last updated on September 26, 2026.

Source: PlamenTSV/plamen on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.