Agent skill

Dependency Scanning

by seb1n in seb1n/awesome-ai-agent-skills

Scan project dependencies for known vulnerabilities, generate software bills of materials, and enforce license compliance across the software supply chain.

MITAuto-check passedLegal & Compliance

Install Dependency Scanning

skills CLI
$ npx skills add seb1n/awesome-ai-agent-skills --skill dependency-scanning -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install seb1n/awesome-ai-agent-skills dependency-scanning --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/seb1n/awesome-ai-agent-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/security/dependency-scanning .claude/skills/dependency-scanning && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
dependency-scanning
GitHub stars
206
Token cost
~2.1k tokens
SKILL.md length
915 words
Files
1
Skills in repo
91
Repo updated
First seen
Licence
MIT

At a glance

Scan project dependencies for known vulnerabilities, generate software bills of materials, and enforce license compliance across the software supply chain.

  • Works in 6 steps: Detect Package Ecosystem and Manifest… → Resolve the Full Dependency Tree — Parse… → Scan Against Vulnerability Databases —… → …
  • The user requests dependency scanning
  • SKILL.md covers Workflow, Supported Technologies, Usage and Examples, plus 3 more sections
  • Calls npm

What it does

Dependency Scanning is an agent skill from seb1n/awesome-ai-agent-skills. Scan project dependencies for known vulnerabilities, generate software bills of materials, and enforce license compliance across the software supply chain. Use when the user requests dependency scanning or provides relevant inputs for this workflow.

Its SKILL.md is about 2.1k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Legal & Compliance, covering Regulatory compliance and Supply chain security. The repository describes itself as: 103 ready-to-use AI agent skills for Claude Code, OpenAI Codex, Gemini CLI, Cursor, GitHub Copilot, Windsurf, and other Agent Skills-compatible tools. Complete SKILL.md… The licence is MIT.

When your agent uses it

  • The user requests dependency scanning
  • Provides relevant inputs for this workflow

Example prompts

  • “/dependency-scanning”

Requirements

  • Python 3
  • Node.js

Workflow steps

6 steps, taken from the first numbered list in SKILL.md.

  1. Detect Package Ecosystem and Manifest Files — Identify the project's language ecosystem by locating dependency manifests such as…
  2. Resolve the Full Dependency Tree — Parse lock files to build the complete dependency graph including transitive dependencies. Identify…
  3. Scan Against Vulnerability Databases — Query the National Vulnerability Database (NVD), GitHub Advisory Database, and OSV for each…
  4. Assess License Compliance — Extract the declared license for each dependency and compare it against the project's license policy. Flag…
  5. Generate SBOM and Vulnerability Report — Produce a Software Bill of Materials in CycloneDX or SPDX format. Generate a vulnerability report…
  6. Recommend and Apply Fixes — Suggest the minimum version upgrades required to resolve vulnerabilities without breaking changes. Where…

What it can do on your machine

Read from SKILL.md and the folder at commit 75865a5. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • npm

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use npm, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Dependency Scanning loads about 2.1k tokens when it runs. Until then it costs about 67 tokens; SKILL.md has 915 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~67
When it runs · the whole SKILL.md, loaded when a task matches
~2.1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from seb1n/awesome-ai-agent-skills at commit 75865a5, republished under its MIT licence (© seb1n). 915 words, ~2,099 tokens.

Download SKILL.mdSave it as .claude/skills/dependency-scanning/SKILL.md (or your agent's skills folder).
name
dependency-scanning
description
Scan project dependencies for known vulnerabilities, generate software bills of materials, and enforce license compliance across the software supply chain. Use when the user requests dependency scanning or provides relevant inputs for this workflow.
license
MIT
metadata.author
awesome-ai-agent-skills
metadata.version
1.0.0

Dependency Scanning

This skill enables the agent to analyze a project's direct and transitive dependencies for known security vulnerabilities, outdated packages, and license compliance issues. The agent parses manifest and lock files, queries vulnerability databases (NVD, GitHub Advisory, OSV), produces structured reports with CVE identifiers and remediation guidance, and can generate a Software Bill of Materials (SBOM) in standard formats.

Workflow

  1. Detect Package Ecosystem and Manifest Files — Identify the project's language ecosystem by locating dependency manifests such as package.json and package-lock.json (Node.js), requirements.txt and Pipfile.lock (Python), pom.xml or build.gradle (Java), go.sum (Go), or Gemfile.lock (Ruby). Detect monorepo structures with multiple manifests.

  2. Resolve the Full Dependency Tree — Parse lock files to build the complete dependency graph including transitive dependencies. Identify dependency depth, shared sub-dependencies, and version constraints. Flag phantom dependencies that are used in code but missing from the manifest.

  3. Scan Against Vulnerability Databases — Query the National Vulnerability Database (NVD), GitHub Advisory Database, and OSV for each resolved package and version. Match results by CPE or PURL identifier. Record CVE IDs, CVSS scores, severity levels, affected version ranges, and fixed versions where available.

  4. Assess License Compliance — Extract the declared license for each dependency and compare it against the project's license policy. Flag copyleft licenses (GPL, AGPL) in proprietary projects, identify packages with no declared license, and detect license conflicts between direct and transitive dependencies.

  5. Generate SBOM and Vulnerability Report — Produce a Software Bill of Materials in CycloneDX or SPDX format. Generate a vulnerability report sorted by severity, including CVE identifiers, affected dependency paths, available fix versions, and whether the vulnerable code path is reachable.

  6. Recommend and Apply Fixes — Suggest the minimum version upgrades required to resolve vulnerabilities without breaking changes. Where possible, generate updated manifest and lock files automatically. Flag cases where no fix is available and suggest alternative packages or workarounds.

Supported Technologies

  • Node.js: npm audit, yarn audit, Snyk, Dependabot
  • Python: pip-audit, Safety, Snyk, Dependabot
  • Java: OWASP Dependency-Check, Snyk, Maven Enforcer Plugin
  • Go: govulncheck, Nancy, Snyk
  • Containers: Trivy, Grype (scan OS packages and application dependencies inside images)
  • SBOM Formats: CycloneDX (JSON/XML), SPDX (JSON/Tag-Value)
  • CI/CD Integration: GitHub Actions, GitLab CI, Jenkins, CircleCI

Usage

Provide the agent with the path to a project directory or a specific manifest file. Optionally specify a license policy or target compliance standard. The agent will perform a full scan and deliver a prioritized vulnerability report.

Prompt example:

Scan the Node.js project in /app for dependency vulnerabilities. Generate a CycloneDX SBOM and flag any GPL-licensed transitive dependencies.

Examples

Example 1: Scanning a Node.js Project

Command:

bash
npm audit --json > audit-report.json

Vulnerability Report (excerpt):

#SeverityPackageInstalledFixed InCVEDependency Path
1Criticaljsonwebtoken8.5.19.0.0CVE-2022-23529direct
2Highminimatch3.0.43.0.5CVE-2022-3517express > send > mime > minimatch
3Highqs6.5.26.5.3CVE-2022-24999express > qs
4Mediumsemver5.7.15.7.2CVE-2022-25883nodemon > semver
5Lowcookie0.4.10.4.2CVE-2024-47764express > cookie

Auto-generated fix in package.json:

json
{
  "dependencies": {
    "jsonwebtoken": "^9.0.0",
    "express": "^4.19.2"
  },
  "overrides": {
    "minimatch": "3.0.5",
    "semver": "5.7.2"
  }
}
Example 2: Scanning a Python Project with pip-audit

Command:

bash
pip-audit -r requirements.txt --format json --output audit.json --fix --dry-run

Vulnerability Report (excerpt):

#SeverityPackageInstalledFixed InCVEDescription
1Criticalcryptography38.0.041.0.6CVE-2023-49083NULL pointer dereference when loading PKCS7 certificates
2Highrequests2.28.02.31.0CVE-2023-32681Leaking Proxy-Authorization header to redirected hosts
3HighJinja23.1.13.1.3CVE-2024-22195Cross-site scripting via xmlattr filter
4Mediumsetuptools65.0.070.0.0CVE-2024-6345Remote code execution via download functions

Auto-generated requirements.txt (fixed):

cryptography==41.0.6    # was 38.0.0 — fixes CVE-2023-49083
requests==2.31.0        # was 2.28.0 — fixes CVE-2023-32681
Jinja2==3.1.3           # was 3.1.1 — fixes CVE-2024-22195
setuptools>=70.0.0      # was 65.0.0 — fixes CVE-2024-6345
Flask==3.0.0
gunicorn==21.2.0
Show full SKILL.md (384 more words)Show less

Best Practices

  • Scan on every CI build — integrate dependency scanning into CI pipelines so that new vulnerabilities are caught before code is merged, not after deployment.
  • Pin dependencies and use lock files — reproducible builds with lock files ensure that the exact versions scanned in CI are the same versions deployed to production.
  • Monitor transitive dependencies — over 80% of vulnerabilities in typical projects come from transitive dependencies. Always resolve and scan the full dependency tree, not just direct dependencies.
  • Automate update PRs — use Dependabot, Renovate, or Snyk to automatically open pull requests when fix versions become available, reducing the window of exposure.
  • Maintain a license allow-list — define an approved license list (e.g., MIT, Apache-2.0, BSD) and block builds that introduce dependencies with disallowed licenses.
  • Generate SBOMs for every release — store CycloneDX or SPDX SBOMs alongside release artifacts to support supply chain transparency and incident response.

Safety Boundaries

  • Work only on systems the user owns or is explicitly authorized to assess, and record the approved scope before testing.
  • Start with passive or read-only inspection. Obtain explicit approval before active scanning, exploitation, load generation, or disruptive remediation.
  • Never expose secrets, extract unrelated data, weaken production controls, or expand beyond the approved targets.
  • Preserve evidence, minimize impact, stop on instability, and provide rollback or containment steps for every material change.

Edge Cases

  • Vulnerabilities with no available fix — when a CVE exists but no patched version is released, assess whether the vulnerable code path is reachable in your application. If it is, consider replacing the dependency or applying a local patch.
  • Monorepos with mixed ecosystems — a single repository may contain Node.js, Python, and Go services with separate manifests. Scan each ecosystem independently and produce a unified report.
  • Private registries and internal packages — packages hosted on private npm registries or internal PyPI servers will not appear in public vulnerability databases. Maintain a private advisory feed or scan internal packages with tools like Trivy that support custom data sources.
  • Version conflicts from overrides — forcing a transitive dependency to a newer version via npm overrides or pip constraints can introduce runtime incompatibilities. Always run the test suite after applying automated fixes.
  • Archived or unmaintained dependencies — a package may have no known CVEs but also no active maintainer. Treat unmaintained packages as a supply chain risk and plan migration to actively maintained alternatives.

© seb1n, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in security/dependency-scanning of seb1n/awesome-ai-agent-skills.

Open the folder on GitHubat commit 75865a5

Compare with similar skills

Dependency Scanning next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Dependency Scanning compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Dependency Scanning this skillseb1n/awesome-ai-agent-skills206—~2.1kAutomated safety check: PassMIT
Oss Reviewanthropics/claude-for-legal9.6k3 repos~5kAutomated safety check: PassApache-2.0
Bom Convert Validatecdxgen/cdxgen1.1k—~1.5kAutomated safety check: WarnApache-2.0
Sbom Generate686f6c61/alfred-dev117—~780Automated safety check: PassMIT
Codebase Cleanup Deps Auditaiskillstore/marketplace4307 repos~490Automated safety check: PassNone
Open Source PolicyHack23/cia239—~4.6kAutomated safety check: PassApache-2.0

Similar skills

  • Oss Review

    anthropics/claude-for-legal

    Official

    Open source license compliance check for a dependency list, a single library, or outbound code.

    9.6k GitHub starsUsed in 3 repos~5k tokens
    Legal & ComplianceAuto-check passed
  • Converts CycloneDX BOMs to SPDX 3.0.1 JSON-LD or between CycloneDX spec versions with cdx-convert, and validates BOMs against JSON schema, deep consistency checks, and OWASP SCVS and EU Cyber…

    1.1k GitHub stars~1.5k tokensUpdated yesterday
    SecurityAuto-check: warnings
  • Sbom Generate

    686f6c61/alfred-dev

    Usar para generar Software Bill of Materials para cumplimiento del CRA.

    117 GitHub stars~780 tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Codebase Cleanup Deps Audit

    aiskillstore/marketplace

    You are a dependency security expert specializing in vulnerability scanning, license compliance, and supply chain security.

    430 GitHub starsUsed in 7 repos~490 tokens
    SecurityAuto-check passed
  • Open source governance, security posture badges, license compliance, SBOM generation, and vulnerability management for transparency-driven development

    239 GitHub stars~4.6k tokensUpdated yesterday
    SecurityAuto-check passed
  • Dependency Audit

    Mathews-Tom/armory

    Audits direct and transitive dependencies for license compliance, maintenance health, CVEs, abandoned packages, and bloat.

    328 GitHub stars~2.7k tokensUpdated 2 days ago
    SecurityAuto-check passed

More from seb1n/awesome-ai-agent-skills

All 91 skills in this repo
  • Agent Red Teaming

    seb1n/awesome-ai-agent-skills

    Plan, execute, document, and retest authorized security assessments of AI agents and multi-agent workflows using safe adversarial cases, synthetic identities, canaries, and evidence-based findings.

    206 GitHub stars~2.8k tokensUpdated 2 mo ago
    Auto-check passed
  • Eu AI Act Readiness

    seb1n/awesome-ai-agent-skills

    Build a preliminary, evidence-based EU AI Act readiness assessment across AI-system inventory, territorial scope, operator roles, prohibited-practice screening, risk classification, transparency…

    206 GitHub stars~3.3k tokensUpdated 2 mo ago
    Auto-check passed
  • Human In The Loop

    seb1n/awesome-ai-agent-skills

    Design and verify auditable human oversight, approval gates, escalation paths, and safe state transitions for AI agent workflows.

    206 GitHub stars~2.5k tokensUpdated 2 mo ago
    Auto-check passed
  • MCP Server Building

    seb1n/awesome-ai-agent-skills

    Design, implement, harden, and verify Model Context Protocol (MCP) servers with precise tool contracts, least-privilege authorization, safe transports, structured errors, and interoperability tests.

    206 GitHub stars~2.5k tokensUpdated 2 mo ago
    Auto-check passed
  • Skill Supply Chain Audit

    seb1n/awesome-ai-agent-skills

    Audit agent skills, plugins, prompts, manifests, scripts, dependencies, and bundled assets for provenance, prompt-injection, permission, execution, exfiltration, persistence, and update risk.

    206 GitHub stars~2.4k tokensUpdated 2 mo ago
    Auto-check passed
  • Spreadsheet Analysis

    seb1n/awesome-ai-agent-skills

    Inspect, profile, clean, reconcile, analyze, visualize, and verify spreadsheet data while preserving formulas, formatting, types, and source files.

    206 GitHub stars~2.5k tokensUpdated 2 mo ago
    Auto-check passed

Questions about Dependency Scanning

What does Dependency Scanning do?

Scan project dependencies for known vulnerabilities, generate software bills of materials, and enforce license compliance across the software supply chain. Dependency Scanning is an agent skill from seb1n/awesome-ai-agent-skills. Scan project dependencies for known vulnerabilities, generate software bills of materials, and enforce license compliance across the software supply chain.

When should I use Dependency Scanning?

Dependency Scanning fits situations like: the user requests dependency scanning; provides relevant inputs for this workflow.

How do I install Dependency Scanning in Claude Code?

Run `npx skills add seb1n/awesome-ai-agent-skills --skill dependency-scanning -a claude-code`. Or copy the skill folder (security/dependency-scanning in seb1n/awesome-ai-agent-skills) into .claude/skills/dependency-scanning in your project. Claude Code loads it when a task matches its description.

How do I install Dependency Scanning in Codex?

Run `npx skills add seb1n/awesome-ai-agent-skills --skill dependency-scanning -a codex`. Or copy the skill folder (security/dependency-scanning in seb1n/awesome-ai-agent-skills) into .agents/skills/dependency-scanning in your project. Codex loads it when a task matches its description.

Can I use Dependency Scanning in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add seb1n/awesome-ai-agent-skills --skill dependency-scanning -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/dependency-scanning, .gemini/skills/dependency-scanning, .github/skills/dependency-scanning and .opencode/skills/dependency-scanning in your project.

What does Dependency Scanning need to run?

Going by SKILL.md and its folder, Dependency Scanning needs the command-line tools its instructions call (npm). Our summary lists: Python 3; Node.js.

Does Dependency Scanning access the network?

SKILL.md contains no URLs. Its commands use npm, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Dependency Scanning safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Dependency Scanning use?

Dependency Scanning is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Dependency Scanning use?

About 2.1k tokens (SKILL.md is roughly 8.4k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Dependency Scanning?

Skills that share tags, products or a category with Dependency Scanning: Oss Review (anthropics/claude-for-legal, 9.6k stars), Bom Convert Validate (cdxgen/cdxgen, 1.1k stars), Sbom Generate (686f6c61/alfred-dev, 117 stars) and Codebase Cleanup Deps Audit (aiskillstore/marketplace, 430 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Dependency Scanning?

seb1n (a GitHub user) maintains it in seb1n/awesome-ai-agent-skills, which has 206 GitHub stars. The repository holds 91 skills in this directory. The repository was last updated on August 9, 2026.

Source: seb1n/awesome-ai-agent-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.