Agent skill

Dependency Scanning

by sickn33 in sickn33/agentic-awesome-skills

Scan package dependencies for known vulnerabilities using Snyk, Dependabot, and OWASP Dependency-Check.

MITAuto-check passedSecurity

Install Dependency Scanning

skills CLI
$ npx skills add sickn33/agentic-awesome-skills --skill dependency-scanning -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install sickn33/agentic-awesome-skills dependency-scanning --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/sickn33/agentic-awesome-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/dependency-scanning .claude/skills/dependency-scanning && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
dependency-scanning
GitHub stars
47k
Used in
1 other repo
Token cost
~2.4k tokens
SKILL.md length
266 words
Files
1
Skills in repo
1,394
Repo updated
First seen
Licence
MIT

At a glance

Scan package dependencies for known vulnerabilities using Snyk, Dependabot, and OWASP Dependency-Check.

  • Tasks that involve Dependency management
  • SKILL.md covers When to Use This Skill, Prerequisites, Tool Comparison and Snyk, plus 7 more sections
  • Calls npm, pip and go; reaches github.com and jeremylong.github.io; needs SNYK_TOKEN
  • Tasks that involve Web application vulnerabilities

What it does

Dependency Scanning is an agent skill from sickn33/agentic-awesome-skills. Scan package dependencies for known vulnerabilities using Snyk, Dependabot, and OWASP Dependency-Check.

Its SKILL.md is about 2.4k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts. Compatibility notes: Requires the relevant security tooling (scanners, vault CLIs) and an authorized scope for any active assessment. Docs-only; helper scripts and templates not…

It sits in Security, covering Dependency management and Web application vulnerabilities. It works with Snyk and Python. The repository describes itself as: AAS Core is the local, agent-first control plane for complete catalog discovery, agent-owned selection, stack validation, and planning, backed by 2,400+ agentic skills. Includes… The licence is MIT.

When your agent uses it

  • Tasks that involve Dependency management
  • Tasks that involve Web application vulnerabilities

Example prompts

  • “/dependency-scanning”

Requirements

  • Python 3
  • Node.js
  • Docker
  • A credential in SNYK_TOKEN
  • Compatibility (from SKILL.md): Requires the relevant security tooling (scanners, vault CLIs) and an authorized scope for any active assessment. Docs-only; helper scripts and templates not bundled.

What it can do on your machine

Read from SKILL.md and the folder at commit 1e53ce2. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • npm
    • pip
    • go
    • wget
    • brew
    • gem
    • npx
    • curl
    • sh

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • github.com
    • jeremylong.github.io
    • raw.githubusercontent.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • SNYK_TOKEN

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

  • Compatibility

    Requires the relevant security tooling (scanners, vault CLIs) and an authorized scope for any active assessment. Docs-only; helper scripts and templates not bundled.

    From compatibility in the SKILL.md frontmatter.

Context cost

Dependency Scanning loads about 2.4k tokens when it runs. Until then it costs about 31 tokens; SKILL.md has 266 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~31
When it runs · the whole SKILL.md, loaded when a task matches
~2.4k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from sickn33/agentic-awesome-skills at commit 1e53ce2, republished under its MIT licence (© sickn33). 266 words, ~2,421 tokens.

Download SKILL.mdSave it as .claude/skills/dependency-scanning/SKILL.md (or your agent's skills folder).
name
dependency-scanning
description
Scan package dependencies for known vulnerabilities using Snyk, Dependabot, and OWASP Dependency-Check.
compatibility
Requires the relevant security tooling (scanners, vault CLIs) and an authorized scope for any active assessment. Docs-only; helper scripts and templates not bundled.
category
security
risk
safe
source
https://github.com/BagelHole/DevOps-Security-Agent-Skills
source_repo
BagelHole/DevOps-Security-Agent-Skills
source_type
community
date_added
2026-09-20
license
MIT
license_source
https://github.com/BagelHole/DevOps-Security-Agent-Skills/blob/main/LICENSE
metadata.author
devops-skills
metadata.version
1.0

Dependency Scanning

Identify vulnerabilities in third-party dependencies and libraries.

When to Use This Skill

Use this skill when:

  • Managing third-party dependencies
  • Implementing software composition analysis
  • Meeting compliance requirements
  • Securing the software supply chain
  • Automating vulnerability detection

Prerequisites

  • Package manifest files (package.json, requirements.txt, etc.)
  • CI/CD pipeline access
  • Dependency scanning tool

Tool Comparison

ToolTypeLanguagesBest For
SnykCommercial/FreeManyComprehensive SCA
DependabotFree (GitHub)ManyAutomated PRs
OWASP Dep-CheckOSSManyFree scanning
npm auditBuilt-inNode.jsQuick checks
pip-auditOSSPythonPython projects
TrivyOSSManyContainer deps

Snyk

CLI Usage
bash
# Install
npm install -g snyk

# Authenticate
snyk auth

# Test project
snyk test

# Monitor project (track over time)
snyk monitor

# Test specific manifest
snyk test --file=package.json
snyk test --file=requirements.txt

# Output formats
snyk test --json > snyk-results.json
snyk test --sarif > snyk-results.sarif

# Fix vulnerabilities
snyk fix

# Ignore vulnerability
snyk ignore --id=SNYK-JS-LODASH-567746 --expiry=2024-12-31 --reason="No exploit path"
CI Integration
yaml
# .github/workflows/snyk.yml
name: Snyk Security

on:
  push:
    branches: [main]
  pull_request:

jobs:
  snyk:
    runs-on: ubuntu-latest
    steps:
      - uses: actions/checkout@v4

      - name: Run Snyk to check for vulnerabilities
        uses: snyk/actions/node@master
        env:
          SNYK_TOKEN: ${{ secrets.SNYK_TOKEN }}
        with:
          args: --severity-threshold=high

      - name: Upload results to GitHub
        uses: github/codeql-action/upload-sarif@v3
        with:
          sarif_file: snyk.sarif
Policy File
yaml
# .snyk
version: v1.25.0
ignore:
  SNYK-JS-LODASH-567746:
    - '*':
        reason: No user input reaches this function
        expires: 2024-12-31
        created: 2024-01-15

  'snyk:lic:npm:gpl-3.0':
    - '*':
        reason: Internal use only
        
patch: {}

GitHub Dependabot

Configuration
yaml
# .github/dependabot.yml
version: 2
updates:
  # JavaScript/Node.js
  - package-ecosystem: "npm"
    directory: "/"
    schedule:
      interval: "weekly"
      day: "monday"
    open-pull-requests-limit: 10
    reviewers:
      - "security-team"
    labels:
      - "dependencies"
      - "security"
    ignore:
      - dependency-name: "aws-sdk"
        update-types: ["version-update:semver-major"]
    groups:
      development-dependencies:
        dependency-type: "development"
        update-types:
          - "minor"
          - "patch"

  # Python
  - package-ecosystem: "pip"
    directory: "/"
    schedule:
      interval: "daily"
    
  # Docker
  - package-ecosystem: "docker"
    directory: "/"
    schedule:
      interval: "weekly"
    
  # GitHub Actions
  - package-ecosystem: "github-actions"
    directory: "/"
    schedule:
      interval: "weekly"
Security Alerts
yaml
# Automated security updates
# Enable in repository Settings > Security > Dependabot

# Dependabot will automatically:
# - Create PRs for vulnerable dependencies
# - Update to patched versions
# - Provide CVE details in PR description

OWASP Dependency-Check

Installation
bash
# Download
wget https://github.com/jeremylong/DependencyCheck/releases/download/v9.0.0/dependency-check-9.0.0-release.zip
unzip dependency-check-9.0.0-release.zip

# Or via Homebrew
brew install dependency-check
Usage
bash
# Scan project
dependency-check --project "MyProject" \
  --scan /path/to/project \
  --out /path/to/reports \
  --format HTML \
  --format JSON

# With specific analyzers
dependency-check --project "MyProject" \
  --scan . \
  --enableExperimental \
  --disableRetireJS

# CI configuration
dependency-check --project "MyProject" \
  --scan . \
  --format JSON \
  --failOnCVSS 7 \
  --suppression suppression.xml
Suppression File
xml
<!-- suppression.xml -->
<?xml version="1.0" encoding="UTF-8"?>
<suppressions xmlns="https://jeremylong.github.io/DependencyCheck/dependency-suppression.1.3.xsd">
  <suppress>
    <notes>False positive - not using vulnerable function</notes>
    <packageUrl regex="true">^pkg:npm/lodash@.*$</packageUrl>
    <cve>CVE-2021-23337</cve>
  </suppress>
  
  <suppress until="2024-12-31">
    <notes>Risk accepted - mitigated by WAF</notes>
    <cpe>cpe:/a:apache:struts:2.5.0</cpe>
    <vulnerabilityName>CVE-2023-12345</vulnerabilityName>
  </suppress>
</suppressions>
Maven Integration
xml
<!-- pom.xml -->
<plugin>
  <groupId>org.owasp</groupId>
  <artifactId>dependency-check-maven</artifactId>
  <version>9.0.0</version>
  <configuration>
    <failBuildOnCVSS>7</failBuildOnCVSS>
    <suppressionFiles>
      <suppressionFile>suppression.xml</suppressionFile>
    </suppressionFiles>
  </configuration>
  <executions>
    <execution>
      <goals>
        <goal>check</goal>
      </goals>
    </execution>
  </executions>
</plugin>

Language-Specific Tools

Node.js (npm audit)
bash
# Run audit
npm audit

# JSON output
npm audit --json

# Fix automatically
npm audit fix

# Fix with breaking changes
npm audit fix --force

# Production only
npm audit --production
Python (pip-audit)
bash
# Install
pip install pip-audit

# Scan installed packages
pip-audit

# Scan requirements file
pip-audit -r requirements.txt

# Output formats
pip-audit --format json
pip-audit --format cyclonedx-json

# Fix vulnerabilities
pip-audit --fix
Go (govulncheck)
bash
# Install
go install golang.org/x/vuln/cmd/govulncheck@latest

# Scan project
govulncheck ./...

# JSON output
govulncheck -json ./...
Ruby (bundler-audit)
bash
# Install
gem install bundler-audit

# Update database
bundle-audit update

# Run audit
bundle-audit check

# Output format
bundle-audit check --format json

SBOM Generation

CycloneDX
bash
# Node.js
npx @cyclonedx/cyclonedx-npm --output-file sbom.json

# Python
pip install cyclonedx-bom
cyclonedx-py -o sbom.json

# Go
go install github.com/CycloneDX/cyclonedx-gomod/cmd/cyclonedx-gomod@latest
cyclonedx-gomod mod -json > sbom.json
Syft
bash
# Install
curl -sSfL https://raw.githubusercontent.com/anchore/syft/main/install.sh -o /tmp/install-syft.sh && sh /tmp/install-syft.sh && rm /tmp/install-syft.sh -s

# Generate SBOM
syft dir:/path/to/project -o cyclonedx-json > sbom.json
syft dir:/path/to/project -o spdx-json > sbom-spdx.json

# From container
syft myimage:latest -o cyclonedx-json > sbom.json

CI/CD Pipeline

yaml
# Comprehensive dependency scanning
name: Dependency Security

on:
  push:
    branches: [main]
  pull_request:
  schedule:
    - cron: '0 8 * * *'

jobs:
  scan:
    runs-on: ubuntu-latest
    steps:
      - uses: actions/checkout@v4

      - name: npm audit
        run: npm audit --audit-level=high

      - name: Snyk scan
        uses: snyk/actions/node@master
        env:
          SNYK_TOKEN: ${{ secrets.SNYK_TOKEN }}
        with:
          args: --severity-threshold=high
          
      - name: Generate SBOM
        run: npx @cyclonedx/cyclonedx-npm --output-file sbom.json

      - name: Upload SBOM
        uses: actions/upload-artifact@v4
        with:
          name: sbom
          path: sbom.json

Common Issues

Issue: Too Many Alerts

Problem: Overwhelmed by vulnerability count Solution: Prioritize by exploitability, filter by severity

Issue: No Fix Available

Problem: Vulnerable dependency has no patch Solution: Consider alternatives, implement compensating controls

Issue: Breaking Updates

Problem: Security fix breaks functionality Solution: Review changelogs, test thoroughly, use lockfiles

Best Practices

  • Scan on every build
  • Use lockfiles for reproducibility
  • Set severity thresholds
  • Generate and track SBOMs
  • Document exceptions properly
  • Update dependencies regularly
  • Monitor for new vulnerabilities
  • Automate PR creation for updates
  • sast-scanning (sast-scanning) - Code vulnerabilities
  • container-scanning (container-scanning) - Container dependencies
  • github-actions (github-actions) - CI integration

Limitations

  • Apply guidance only within authorized scope; test destructive steps in non-production first.
  • Docs-only import: upstream scripts and templates not bundled.
Example
bash
# Read-only first: inventory before any active step.
which <tool> && <tool> --help | head -n 20

Adapted from BagelHole/DevOps-Security-Agent-Skills (MIT); frontmatter, When to Use/Limitations, and safety boundaries added for upstream compliance. Docs-only import: helper scripts and templates not bundled.

© sickn33, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/dependency-scanning of sickn33/agentic-awesome-skills.

Open the folder on GitHubat commit 1e53ce2

Used in 1 other repository

We found 5 copies of this SKILL.md (exact, near-identical or edited) in other folders, from 1 other GitHub owner. This page covers the copy in sickn33/agentic-awesome-skills, which our catalogue first saw on October 7, 2026.

Compare with similar skills

Dependency Scanning next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Dependency Scanning compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Dependency Scanning this skillsickn33/agentic-awesome-skills47k1 repos~2.4kAutomated safety check: PassMIT
Code Safety Auditrongxinzy/RongxinAI154—~868Automated safety check: PassMIT
Security Auditoreigent-ai/eigent15k—~1.8kAutomated safety check: NotesApache-2.0
Security Verification Gatefengshao1227/ccg-workflow5.9k—~621Automated safety check: NotesMIT
Code Review Securitynicepkg/auto-company1921 repos~3.9kAutomated safety check: PassMIT
Cyber NeoHainrixz/cyber-neo281—~5.9kAutomated safety check: WarnMIT

Similar skills

  • Code Safety Audit

    rongxinzy/RongxinAI

    扫描代码安全漏洞,检测依赖漏洞、密钥泄露和OWASP安全模式。当用户提到安全扫描、漏洞检测、依赖审计、密钥泄露、API key、OWASP、npm audit、pip-audit或SQL注入/XSS等关键词时触发。

    154 GitHub stars~868 tokensUpdated today
    SecurityAuto-check passed
  • Security Auditor

    eigent-ai/eigent

    Audits source code, dependencies and config files for vulnerabilities and hardcoded secrets, using two bundled Python scanners and an OWASP Top 10 checklist.

    15k GitHub stars~1.8k tokensUpdated today
    SecurityAuto-check: notes
  • Security Verification Gate

    fengshao1227/ccg-workflow

    Scans code with a bundled Node script for injection, secrets, XSS and other risky patterns, ranks findings by severity and checks that security decisions are documented.

    5.9k GitHub stars~621 tokensUpdated 22 days ago
    SecurityAuto-check: notes
  • Code Review Security

    nicepkg/auto-company

    Security-focused code review checklist and automated scanning patterns.

    192 GitHub starsUsed in 1 repo~3.9k tokens
    SecurityAuto-check passed
  • Cyber Neo

    Hainrixz/cyber-neo

    Comprehensive cybersecurity analysis for any local project. An agent skill from Hainrixz/cyber-neo.

    281 GitHub stars~5.9k tokensUpdated 2 mo ago
    SecurityAuto-check: warnings
  • Kesekit Guide Ko

    cdppcorp/KESE-KIT

    AI 도구(Claude, ChatGPT, Cursor, Copilot)용 시큐어 코딩 프롬프트와 가이드를 생성합니다.

    359 GitHub stars~1.3k tokensUpdated 6 mo ago
    SecurityAuto-check passed

More from sickn33/agentic-awesome-skills

All 1,394 skills in this repo
  • Liuguang Banlan UI

    sickn33/agentic-awesome-skills

    Implements an interface in one of two named color modes, iridescent white or colorful black, from a parameterized starter that reports measured color intensity.

    47k GitHub starsUsed in 1 repo~2.5k tokens
    Auto-check passed
  • User Thoughts Memory

    sickn33/agentic-awesome-skills

    Saves a user's project decisions, rules and preferences into a project-local mdbase so later sessions and other agents can recover the intent.

    47k GitHub starsUsed in 1 repo~2.5k tokens
    Auto-check passed
  • Using LWC Memory and Graphs

    sickn33/agentic-awesome-skills

    Keeps project decisions, research and verified results available across coding-agent sessions through LWC memory, a document Wiki graph and a CodeGraph code index.

    47k GitHub starsUsed in 1 repo~2k tokens
    Auto-check passed
  • Find Complementary Founders

    sickn33/agentic-awesome-skills

    Guides an agent through assessing its own owner for cofounder fit, publishing an approved profile, and ranking complementary profiles other agents published for their owners.

    47k GitHub starsUsed in 1 repo~4.8k tokens
    Auto-check passed
  • Whatsapp Cloud API

    sickn33/agentic-awesome-skills

    Integracao com WhatsApp Business Cloud API (Meta). An agent skill from sickn33/agentic-awesome-skills.

    47k GitHub starsUsed in 2 repos~4.5k tokens
    Auto-check passed
  • Cline Pilot

    sickn33/agentic-awesome-skills

    Acts as a proxy for the Cline CLI, dispatching coding tasks one at a time, monitoring runs by hard evidence, relaying decisions to you and learning per-project preferences.

    47k GitHub starsUsed in 1 repo~4.6k tokens
    Auto-check passed

Works with

Categories

Questions about Dependency Scanning

What does Dependency Scanning do?

Scan package dependencies for known vulnerabilities using Snyk, Dependabot, and OWASP Dependency-Check. Dependency Scanning is an agent skill from sickn33/agentic-awesome-skills. Scan package dependencies for known vulnerabilities using Snyk, Dependabot, and OWASP Dependency-Check.

When should I use Dependency Scanning?

Dependency Scanning fits situations like: tasks that involve Dependency management; tasks that involve Web application vulnerabilities.

How do I install Dependency Scanning in Claude Code?

Run `npx skills add sickn33/agentic-awesome-skills --skill dependency-scanning -a claude-code`. Or copy the skill folder (skills/dependency-scanning in sickn33/agentic-awesome-skills) into .claude/skills/dependency-scanning in your project. Claude Code loads it when a task matches its description.

How do I install Dependency Scanning in Codex?

Run `npx skills add sickn33/agentic-awesome-skills --skill dependency-scanning -a codex`. Or copy the skill folder (skills/dependency-scanning in sickn33/agentic-awesome-skills) into .agents/skills/dependency-scanning in your project. Codex loads it when a task matches its description.

Can I use Dependency Scanning in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add sickn33/agentic-awesome-skills --skill dependency-scanning -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/dependency-scanning, .gemini/skills/dependency-scanning, .github/skills/dependency-scanning and .opencode/skills/dependency-scanning in your project.

What does Dependency Scanning need to run?

Going by SKILL.md and its folder, Dependency Scanning needs the command-line tools its instructions call (npm, pip, go, wget, brew and gem) and credentials named SNYK_TOKEN. Our summary lists: Python 3; Node.js; Docker; A credential in SNYK_TOKEN. Compatibility (from SKILL.md): Requires the relevant security tooling (scanners, vault CLIs) and an authorized scope for any active assessment. Docs-only; helper scripts and templates not bundled..

Does Dependency Scanning access the network?

SKILL.md names 3 domains. In commands or code: github.com, jeremylong.github.io and raw.githubusercontent.com; the agent is likely to contact these when it follows the instructions. This is read from the text; nothing was executed.

Is Dependency Scanning safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Dependency Scanning use?

Dependency Scanning is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Dependency Scanning use?

About 2.4k tokens (SKILL.md is roughly 9.7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Dependency Scanning?

Skills that share tags, products or a category with Dependency Scanning: Code Safety Audit (rongxinzy/RongxinAI, 154 stars), Security Auditor (eigent-ai/eigent, 15k stars), Security Verification Gate (fengshao1227/ccg-workflow, 5.9k stars) and Code Review Security (nicepkg/auto-company, 192 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Dependency Scanning?

sickn33 (a GitHub user) maintains it in sickn33/agentic-awesome-skills, which has 47,304 GitHub stars. The repository holds 1,394 skills in this directory. The repository was last updated on October 6, 2026.

Source: sickn33/agentic-awesome-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.