Agent skill

Security Scanning Security Dependencies

by aiskillstore in aiskillstore/marketplace

You are a security expert specializing in dependency vulnerability analysis, SBOM generation, and supply chain security.

No licenceAuto-check passedSecurity

Install Security Scanning Security Dependencies

skills CLI
$ npx skills add aiskillstore/marketplace --skill security-scanning-security-dependencies -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install aiskillstore/marketplace security-scanning-security-dependencies --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/aiskillstore/marketplace.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/sickn33/security-scanning-security-dependencies .claude/skills/security-scanning-security-dependencies && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
security-scanning-security-dependencies
GitHub stars
430
Used in
7 other repos
Token cost
~563 tokens
SKILL.md length
222 words
Files
3
Skills in repo
1,108
Repo updated
First seen
Licence
None found

At a glance

You are a security expert specializing in dependency vulnerability analysis, SBOM generation, and supply chain security.

  • Tasks that involve Supply chain security
  • SKILL.md covers Use this skill when, Do not use this skill when, Context and Requirements, plus 4 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md
  • Tasks that involve Vulnerability scanning

What it does

Security Scanning Security Dependencies is an agent skill from aiskillstore/marketplace. You are a security expert specializing in dependency vulnerability analysis, SBOM generation, and supply chain security. Scan project dependencies across multiple ecosystems to identify vulnerabilities, assess risks, and provide automated remediation strategies.

Its SKILL.md is about 560 tokens, which your agent loads only when the skill is triggered. The skill folder holds 3 other files (for example `resources/implementation-playbook.md` and `skill-report.json`).

It sits in Security, covering Supply chain security and Vulnerability scanning. The repository describes itself as: Security-audited skills for Claude, Codex & Claude Code. One-click install, quality verified.

When your agent uses it

  • Tasks that involve Supply chain security
  • Tasks that involve Vulnerability scanning

Example prompts

  • “/security-scanning-security-dependencies”

What it can do on your machine

Read from SKILL.md and the folder at commit ad8daf7. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Security Scanning Security Dependencies loads about 563 tokens when it runs. Until then it costs about 76 tokens; SKILL.md has 222 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~76
When it runs · the whole SKILL.md, loaded when a task matches
~563

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

Without a licence we can't republish the file, so here is its outline and opening line. It has 222 words (~563 tokens).

“You are a security expert specializing in dependency vulnerability analysis, SBOM generation, and supply chain security. Scan project dependencies across multiple ecosystems to identify vulnerabilities, assess risks, and provide automated remediation strategies.”

— opening of SKILL.md by aiskillstore
name
security-scanning-security-dependencies
risk
safe
source
community
date_added
2026-02-27

Read the full SKILL.md on GitHub

Files

SKILL.md and 2 other files in skills/sickn33/security-scanning-security-dependencies of aiskillstore/marketplace.

  • SKILL.md
  • resources/implementation-playbook.md
  • skill-report.json

Open the folder on GitHubat commit ad8daf7

Used in 7 other repositories

We found 16 copies of this SKILL.md (exact, near-identical or edited) in other folders, from 7 other GitHub owners. This page covers the copy in aiskillstore/marketplace, which our catalogue first saw on October 7, 2026.

Compare with similar skills

Security Scanning Security Dependencies next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Security Scanning Security Dependencies compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Security Scanning Security Dependencies this skillaiskillstore/marketplace4307 repos~563Automated safety check: PassNone
Warp Vulnerability Triagewarpdotdev/warp65k1 repos~2.1kAutomated safety check: PassAGPL-3.0
Container Scanning with GrypeAgentSecOps/SecOpsAgentKit2201 repos~2.5kAutomated safety check: PassCustom licence
Kesekit Startcdppcorp/KESE-KIT361—~2.3kAutomated safety check: PassMIT
Snapshotboostsecurityio/poutine523—~214Automated safety check: PassApache-2.0
Dependency Triagecobusgreyling/loop-engineering11k—~300Automated safety check: PassMIT

Similar skills

  • Gathers security findings from Dependabot, GCP container scanning, Docker Scout and Linear security issues, then triages and remediates them across Warp's repos and images.

    65k GitHub starsUsed in 1 repo~2.1k tokens
    SecurityAuto-check passed
  • Container Scanning with Grype

    AgentSecOps/SecOpsAgentKit

    Scans container images, filesystems and SBOMs with Grype for known vulnerabilities, ranks them by CVSS, EPSS and CISA KEV, and wires scans into CI/CD thresholds.

    220 GitHub starsUsed in 1 repo~2.5k tokens
    SecurityAuto-check passed
  • Kesekit Start

    cdppcorp/KESE-KIT

    Run a security vulnerability assessment based on KISA guidelines.

    361 GitHub stars~2.3k tokensUpdated 6 mo ago
    SecurityAuto-check passed
  • Snapshot

    boostsecurityio/poutine

    Run snapshot regression tests after changes to OPA rules, scanners, analyzers, or formatters to detect output regressions.

    523 GitHub stars~214 tokensUpdated 2 days ago
    SecurityAuto-check passed
  • Dependency Triage

    cobusgreyling/loop-engineering

    Scans package manifests and lockfiles for outdated packages and known CVEs, then classifies each possible update as patch, minor, major or escalate-human for a dependency sweeper loop.

    11k GitHub stars~300 tokensUpdated today
    SecurityAuto-check passed
  • Container Security

    hardw00t/ai-security-arsenal

    Container and Kubernetes security assessment — image vulnerability scanning, SBOM diff analysis, K8s cluster auditing, RBAC privilege mapping, NetworkPolicy review, container escape testing, and…

    104 GitHub stars~2.8k tokensUpdated 5 mo ago
    SecurityAuto-check passed

More from aiskillstore/marketplace

All 1,108 skills in this repo
  • Code Stats

    aiskillstore/marketplace

    Analyze codebase with tokei (fast line counts by language) and difft (semantic AST-aware diffs).

    430 GitHub starsUsed in 2 repos~697 tokens
    Auto-check: notes
  • File Search

    aiskillstore/marketplace

    Modern file and content search using fd, ripgrep (rg), and fzf.

    430 GitHub starsUsed in 2 repos~598 tokens
    Auto-check: notes
  • Data Processing

    aiskillstore/marketplace

    Process JSON with jq and YAML/TOML with yq. An agent skill from aiskillstore/marketplace.

    430 GitHub starsUsed in 1 repo~720 tokens
    Auto-check: notes
  • Doc Scanner

    aiskillstore/marketplace

    Scans for project documentation files (AGENTS.md, CLAUDE.md, GEMINI.md, COPILOT.md, CURSOR.md, WARP.md, and 15+ other formats) and synthesizes guidance.

    430 GitHub starsUsed in 1 repo~644 tokens
    Auto-check: notes
  • Find Replace

    aiskillstore/marketplace

    Modern find-and-replace using sd (simpler than sed) and batch replacement patterns.

    430 GitHub starsUsed in 1 repo~527 tokens
    Auto-check: notes
  • Investigating Codebases

    aiskillstore/marketplace

    Automatically activated when user asks how something works, wants to understand unfamiliar code, needs to explore a new codebase, or asks questions like "where is X implemented?", "how does Y…

    430 GitHub starsUsed in 1 repo~2.7k tokens
    Auto-check: notes

Categories

Questions about Security Scanning Security Dependencies

What does Security Scanning Security Dependencies do?

You are a security expert specializing in dependency vulnerability analysis, SBOM generation, and supply chain security. Security Scanning Security Dependencies is an agent skill from aiskillstore/marketplace. You are a security expert specializing in dependency vulnerability analysis, SBOM generation, and supply chain security.

When should I use Security Scanning Security Dependencies?

Security Scanning Security Dependencies fits situations like: tasks that involve Supply chain security; tasks that involve Vulnerability scanning.

How do I install Security Scanning Security Dependencies in Claude Code?

Run `npx skills add aiskillstore/marketplace --skill security-scanning-security-dependencies -a claude-code`. Or copy the skill folder (skills/sickn33/security-scanning-security-dependencies in aiskillstore/marketplace) into .claude/skills/security-scanning-security-dependencies in your project. Claude Code loads it when a task matches its description.

How do I install Security Scanning Security Dependencies in Codex?

Run `npx skills add aiskillstore/marketplace --skill security-scanning-security-dependencies -a codex`. Or copy the skill folder (skills/sickn33/security-scanning-security-dependencies in aiskillstore/marketplace) into .agents/skills/security-scanning-security-dependencies in your project. Codex loads it when a task matches its description.

Can I use Security Scanning Security Dependencies in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add aiskillstore/marketplace --skill security-scanning-security-dependencies -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/security-scanning-security-dependencies, .gemini/skills/security-scanning-security-dependencies, .github/skills/security-scanning-security-dependencies and .opencode/skills/security-scanning-security-dependencies in your project.

What does Security Scanning Security Dependencies need to run?

SKILL.md names no scripts, command-line tools or credentials: Security Scanning Security Dependencies is instructions for the agent only.

Does Security Scanning Security Dependencies access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Security Scanning Security Dependencies safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Security Scanning Security Dependencies use?

No licence was found for Security Scanning Security Dependencies or its repository. Without one, default copyright applies: ask the author before reusing or redistributing it.

How many tokens does Security Scanning Security Dependencies use?

About 563 tokens (SKILL.md is roughly 2.3k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Security Scanning Security Dependencies?

Skills that share tags, products or a category with Security Scanning Security Dependencies: Warp Vulnerability Triage (warpdotdev/warp, 65k stars), Container Scanning with Grype (AgentSecOps/SecOpsAgentKit, 220 stars), Kesekit Start (cdppcorp/KESE-KIT, 361 stars) and Snapshot (boostsecurityio/poutine, 523 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Security Scanning Security Dependencies?

aiskillstore (a GitHub organization) maintains it in aiskillstore/marketplace, which has 430 GitHub stars. The repository holds 1,108 skills in this directory. The repository was last updated on October 7, 2026.

Source: aiskillstore/marketplace on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.