Oss Review
anthropics/claude-for-legal
Open source license compliance check for a dependency list, a single library, or outbound code.
Scan project dependencies for known vulnerabilities, generate software bills of materials, and enforce license compliance across the software supply chain.
$ npx skills add seb1n/awesome-ai-agent-skills --skill dependency-scanning -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install seb1n/awesome-ai-agent-skills dependency-scanning --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/seb1n/awesome-ai-agent-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/security/dependency-scanning .claude/skills/dependency-scanning && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "dependency-scanning" agent skill from https://github.com/seb1n/awesome-ai-agent-skills/tree/main/security/dependency-scanning into .claude/skills/dependency-scanning/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "dependency-scanning", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/seb1n/awesome-ai-agent-skills/tree/main/security/dependency-scanningType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add seb1n/awesome-ai-agent-skills --skill dependency-scanning -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install seb1n/awesome-ai-agent-skills dependency-scanning --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/seb1n/awesome-ai-agent-skills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/security/dependency-scanning .agents/skills/dependency-scanning && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "dependency-scanning" agent skill from https://github.com/seb1n/awesome-ai-agent-skills/tree/main/security/dependency-scanning into .agents/skills/dependency-scanning/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "dependency-scanning", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add seb1n/awesome-ai-agent-skills --skill dependency-scanning -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install seb1n/awesome-ai-agent-skills dependency-scanning --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/seb1n/awesome-ai-agent-skills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/security/dependency-scanning .cursor/skills/dependency-scanning && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "dependency-scanning" agent skill from https://github.com/seb1n/awesome-ai-agent-skills/tree/main/security/dependency-scanning into .cursor/skills/dependency-scanning/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "dependency-scanning", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/seb1n/awesome-ai-agent-skills.git --path security/dependency-scanning--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add seb1n/awesome-ai-agent-skills --skill dependency-scanning -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install seb1n/awesome-ai-agent-skills dependency-scanning --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/seb1n/awesome-ai-agent-skills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/security/dependency-scanning .gemini/skills/dependency-scanning && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "dependency-scanning" agent skill from https://github.com/seb1n/awesome-ai-agent-skills/tree/main/security/dependency-scanning into .gemini/skills/dependency-scanning/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "dependency-scanning", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install seb1n/awesome-ai-agent-skills dependency-scanningInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add seb1n/awesome-ai-agent-skills --skill dependency-scanning -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/seb1n/awesome-ai-agent-skills.git skills-src && mkdir -p .github/skills && cp -r skills-src/security/dependency-scanning .github/skills/dependency-scanning && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "dependency-scanning" agent skill from https://github.com/seb1n/awesome-ai-agent-skills/tree/main/security/dependency-scanning into .github/skills/dependency-scanning/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "dependency-scanning", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add seb1n/awesome-ai-agent-skills --skill dependency-scanning -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install seb1n/awesome-ai-agent-skills dependency-scanning --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/seb1n/awesome-ai-agent-skills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/security/dependency-scanning .opencode/skills/dependency-scanning && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "dependency-scanning" agent skill from https://github.com/seb1n/awesome-ai-agent-skills/tree/main/security/dependency-scanning into .opencode/skills/dependency-scanning/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "dependency-scanning", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
dependency-scanningScan project dependencies for known vulnerabilities, generate software bills of materials, and enforce license compliance across the software supply chain.
Dependency Scanning is an agent skill from seb1n/awesome-ai-agent-skills. Scan project dependencies for known vulnerabilities, generate software bills of materials, and enforce license compliance across the software supply chain. Use when the user requests dependency scanning or provides relevant inputs for this workflow.
Its SKILL.md is about 2.1k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Legal & Compliance, covering Regulatory compliance and Supply chain security. The repository describes itself as: 103 ready-to-use AI agent skills for Claude Code, OpenAI Codex, Gemini CLI, Cursor, GitHub Copilot, Windsurf, and other Agent Skills-compatible tools. Complete SKILL.md… The licence is MIT.
6 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit 75865a5. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
npmFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use npm, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Dependency Scanning loads about 2.1k tokens when it runs. Until then it costs about 67 tokens; SKILL.md has 915 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from seb1n/awesome-ai-agent-skills at commit 75865a5, republished under its MIT licence (© seb1n). 915 words, ~2,099 tokens.
.claude/skills/dependency-scanning/SKILL.md (or your agent's skills folder).This skill enables the agent to analyze a project's direct and transitive dependencies for known security vulnerabilities, outdated packages, and license compliance issues. The agent parses manifest and lock files, queries vulnerability databases (NVD, GitHub Advisory, OSV), produces structured reports with CVE identifiers and remediation guidance, and can generate a Software Bill of Materials (SBOM) in standard formats.
Detect Package Ecosystem and Manifest Files — Identify the project's language ecosystem by locating dependency manifests such as package.json and package-lock.json (Node.js), requirements.txt and Pipfile.lock (Python), pom.xml or build.gradle (Java), go.sum (Go), or Gemfile.lock (Ruby). Detect monorepo structures with multiple manifests.
Resolve the Full Dependency Tree — Parse lock files to build the complete dependency graph including transitive dependencies. Identify dependency depth, shared sub-dependencies, and version constraints. Flag phantom dependencies that are used in code but missing from the manifest.
Scan Against Vulnerability Databases — Query the National Vulnerability Database (NVD), GitHub Advisory Database, and OSV for each resolved package and version. Match results by CPE or PURL identifier. Record CVE IDs, CVSS scores, severity levels, affected version ranges, and fixed versions where available.
Assess License Compliance — Extract the declared license for each dependency and compare it against the project's license policy. Flag copyleft licenses (GPL, AGPL) in proprietary projects, identify packages with no declared license, and detect license conflicts between direct and transitive dependencies.
Generate SBOM and Vulnerability Report — Produce a Software Bill of Materials in CycloneDX or SPDX format. Generate a vulnerability report sorted by severity, including CVE identifiers, affected dependency paths, available fix versions, and whether the vulnerable code path is reachable.
Recommend and Apply Fixes — Suggest the minimum version upgrades required to resolve vulnerabilities without breaking changes. Where possible, generate updated manifest and lock files automatically. Flag cases where no fix is available and suggest alternative packages or workarounds.
Provide the agent with the path to a project directory or a specific manifest file. Optionally specify a license policy or target compliance standard. The agent will perform a full scan and deliver a prioritized vulnerability report.
Prompt example:
Scan the Node.js project in /app for dependency vulnerabilities. Generate a CycloneDX SBOM and flag any GPL-licensed transitive dependencies.Command:
npm audit --json > audit-report.jsonVulnerability Report (excerpt):
| # | Severity | Package | Installed | Fixed In | CVE | Dependency Path |
|---|---|---|---|---|---|---|
| 1 | Critical | jsonwebtoken | 8.5.1 | 9.0.0 | CVE-2022-23529 | direct |
| 2 | High | minimatch | 3.0.4 | 3.0.5 | CVE-2022-3517 | express > send > mime > minimatch |
| 3 | High | qs | 6.5.2 | 6.5.3 | CVE-2022-24999 | express > qs |
| 4 | Medium | semver | 5.7.1 | 5.7.2 | CVE-2022-25883 | nodemon > semver |
| 5 | Low | cookie | 0.4.1 | 0.4.2 | CVE-2024-47764 | express > cookie |
Auto-generated fix in package.json:
{
"dependencies": {
"jsonwebtoken": "^9.0.0",
"express": "^4.19.2"
},
"overrides": {
"minimatch": "3.0.5",
"semver": "5.7.2"
}
}Command:
pip-audit -r requirements.txt --format json --output audit.json --fix --dry-runVulnerability Report (excerpt):
| # | Severity | Package | Installed | Fixed In | CVE | Description |
|---|---|---|---|---|---|---|
| 1 | Critical | cryptography | 38.0.0 | 41.0.6 | CVE-2023-49083 | NULL pointer dereference when loading PKCS7 certificates |
| 2 | High | requests | 2.28.0 | 2.31.0 | CVE-2023-32681 | Leaking Proxy-Authorization header to redirected hosts |
| 3 | High | Jinja2 | 3.1.1 | 3.1.3 | CVE-2024-22195 | Cross-site scripting via xmlattr filter |
| 4 | Medium | setuptools | 65.0.0 | 70.0.0 | CVE-2024-6345 | Remote code execution via download functions |
Auto-generated requirements.txt (fixed):
cryptography==41.0.6 # was 38.0.0 — fixes CVE-2023-49083
requests==2.31.0 # was 2.28.0 — fixes CVE-2023-32681
Jinja2==3.1.3 # was 3.1.1 — fixes CVE-2024-22195
setuptools>=70.0.0 # was 65.0.0 — fixes CVE-2024-6345
Flask==3.0.0
gunicorn==21.2.0overrides or pip constraints can introduce runtime incompatibilities. Always run the test suite after applying automated fixes.© seb1n, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in security/dependency-scanning of seb1n/awesome-ai-agent-skills.
Open the folder on GitHubat commit 75865a5
Dependency Scanning next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Dependency Scanning this skillseb1n/awesome-ai-agent-skills | 206 | — | ~2.1k | Automated safety check: Pass | MIT | |
| Oss Reviewanthropics/claude-for-legal | 9.6k | 3 repos | ~5k | Automated safety check: Pass | Apache-2.0 | |
| Bom Convert Validatecdxgen/cdxgen | 1.1k | — | ~1.5k | Automated safety check: Warn | Apache-2.0 | |
| Sbom Generate686f6c61/alfred-dev | 117 | — | ~780 | Automated safety check: Pass | MIT | |
| Codebase Cleanup Deps Auditaiskillstore/marketplace | 430 | 7 repos | ~490 | Automated safety check: Pass | None | |
| Open Source PolicyHack23/cia | 239 | — | ~4.6k | Automated safety check: Pass | Apache-2.0 |
anthropics/claude-for-legal
Open source license compliance check for a dependency list, a single library, or outbound code.
cdxgen/cdxgen
Converts CycloneDX BOMs to SPDX 3.0.1 JSON-LD or between CycloneDX spec versions with cdx-convert, and validates BOMs against JSON schema, deep consistency checks, and OWASP SCVS and EU Cyber…
686f6c61/alfred-dev
Usar para generar Software Bill of Materials para cumplimiento del CRA.
aiskillstore/marketplace
You are a dependency security expert specializing in vulnerability scanning, license compliance, and supply chain security.
Hack23/cia
Open source governance, security posture badges, license compliance, SBOM generation, and vulnerability management for transparency-driven development
Mathews-Tom/armory
Audits direct and transitive dependencies for license compliance, maintenance health, CVEs, abandoned packages, and bloat.
seb1n/awesome-ai-agent-skills
Plan, execute, document, and retest authorized security assessments of AI agents and multi-agent workflows using safe adversarial cases, synthetic identities, canaries, and evidence-based findings.
seb1n/awesome-ai-agent-skills
Build a preliminary, evidence-based EU AI Act readiness assessment across AI-system inventory, territorial scope, operator roles, prohibited-practice screening, risk classification, transparency…
seb1n/awesome-ai-agent-skills
Design and verify auditable human oversight, approval gates, escalation paths, and safe state transitions for AI agent workflows.
seb1n/awesome-ai-agent-skills
Design, implement, harden, and verify Model Context Protocol (MCP) servers with precise tool contracts, least-privilege authorization, safe transports, structured errors, and interoperability tests.
seb1n/awesome-ai-agent-skills
Audit agent skills, plugins, prompts, manifests, scripts, dependencies, and bundled assets for provenance, prompt-injection, permission, execution, exfiltration, persistence, and update risk.
seb1n/awesome-ai-agent-skills
Inspect, profile, clean, reconcile, analyze, visualize, and verify spreadsheet data while preserving formulas, formatting, types, and source files.
Categories
Scan project dependencies for known vulnerabilities, generate software bills of materials, and enforce license compliance across the software supply chain. Dependency Scanning is an agent skill from seb1n/awesome-ai-agent-skills. Scan project dependencies for known vulnerabilities, generate software bills of materials, and enforce license compliance across the software supply chain.
Dependency Scanning fits situations like: the user requests dependency scanning; provides relevant inputs for this workflow.
Run `npx skills add seb1n/awesome-ai-agent-skills --skill dependency-scanning -a claude-code`. Or copy the skill folder (security/dependency-scanning in seb1n/awesome-ai-agent-skills) into .claude/skills/dependency-scanning in your project. Claude Code loads it when a task matches its description.
Run `npx skills add seb1n/awesome-ai-agent-skills --skill dependency-scanning -a codex`. Or copy the skill folder (security/dependency-scanning in seb1n/awesome-ai-agent-skills) into .agents/skills/dependency-scanning in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add seb1n/awesome-ai-agent-skills --skill dependency-scanning -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/dependency-scanning, .gemini/skills/dependency-scanning, .github/skills/dependency-scanning and .opencode/skills/dependency-scanning in your project.
Going by SKILL.md and its folder, Dependency Scanning needs the command-line tools its instructions call (npm). Our summary lists: Python 3; Node.js.
SKILL.md contains no URLs. Its commands use npm, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Dependency Scanning is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.
About 2.1k tokens (SKILL.md is roughly 8.4k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Dependency Scanning: Oss Review (anthropics/claude-for-legal, 9.6k stars), Bom Convert Validate (cdxgen/cdxgen, 1.1k stars), Sbom Generate (686f6c61/alfred-dev, 117 stars) and Codebase Cleanup Deps Audit (aiskillstore/marketplace, 430 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
seb1n (a GitHub user) maintains it in seb1n/awesome-ai-agent-skills, which has 206 GitHub stars. The repository holds 91 skills in this directory. The repository was last updated on August 9, 2026.
Source: seb1n/awesome-ai-agent-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.