Cross-repository dependency audit. An agent skill from thatrebeccarae/claude-marketing.

MITAuto-check passedMarketing & SEO

Install Dep Audit

skills CLI
$ npx skills add thatrebeccarae/claude-marketing --skill dep-audit -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install thatrebeccarae/claude-marketing dep-audit --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/thatrebeccarae/claude-marketing.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/dep-audit .claude/skills/dep-audit && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
dep-audit
GitHub stars
161
Token cost
~2k tokens
SKILL.md length
786 words
Files
4
Skills in repo
55
Repo updated
First seen
Licence
MIT

At a glance

Cross-repository dependency audit. An agent skill from thatrebeccarae/claude-marketing.

  • Works in 8 steps: Detect Package Managers → Parse Manifests and Lock Files → Check for Outdated Packages → …
  • Marketing & SEO work in your project
  • SKILL.md covers Install, When to Use, Usage and Procedure, plus 2 more sections
  • Calls cargo, npm and git

What it does

Dep Audit is an agent skill from thatrebeccarae/claude-marketing. Cross-repository dependency audit. Scans package manifests for outdated packages, security advisories, version conflicts, and license issues. Produces a prioritized update plan. Supports Node.js, Python, Rust, and Go projects.

Its SKILL.md is about 2k tokens, which your agent loads only when the skill is triggered. The skill folder holds 3 other files (for example `EXAMPLES.md` and `REFERENCE.md`).

It sits in Marketing & SEO. It works with Rust, Node.js, Python and npm. The repository describes itself as: A full marketing department for Claude Code. Skill packs for Klaviyo, Shopify, GA4, Looker Studio, paid media, and more. Audit, optimize, and report using natural language. The licence is MIT.

When your agent uses it

  • Marketing & SEO work in your project

Example prompts

  • “/dep-audit”

Requirements

  • Python 3
  • Node.js

Workflow steps

8 steps, taken from the step headings in SKILL.md.

  1. Detect Package Managers
  2. Parse Manifests and Lock Files
  3. Check for Outdated Packages
  4. Check for Security Advisories
  5. Cross-Repo Analysis (Multiple Repos)
  6. License Scan
  7. Generate Update Plan
  8. Report

What it can do on your machine

Read from SKILL.md and the folder at commit a8a63ec. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • cargo
    • npm
    • git
    • pip
    • poetry
    • go
    • npx

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use npm, git, pip and npx, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Dep Audit loads about 2k tokens when it runs. Until then it costs about 59 tokens; SKILL.md has 786 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~59
When it runs · the whole SKILL.md, loaded when a task matches
~2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from thatrebeccarae/claude-marketing at commit a8a63ec, republished under its MIT licence (© thatrebeccarae). 786 words, ~1,981 tokens.

Download SKILL.mdSave it as .claude/skills/dep-audit/SKILL.md (or your agent's skills folder). This skill also uses 3 other files; get the full folder from GitHub.
name
dep-audit
description
Cross-repository dependency audit. Scans package manifests for outdated packages, security advisories, version conflicts, and license issues. Produces a prioritized update plan. Supports Node.js, Python, Rust, and Go projects.
license
MIT
origin
custom
author
Rebecca Rae Barton
author_url
https://github.com/thatrebeccarae
metadata.version
1.0.0
metadata.category
devops
metadata.domain
dependencies
metadata.updated
2026-03-19
metadata.tested
2026-03-19
metadata.tested_with
Claude Code v2.1

Dependency Audit

Cross-repository dependency audit. Scans package manifests (package.json, pyproject.toml, Cargo.toml, go.mod) for outdated packages, security advisories, version conflicts between repos, and license compatibility issues. Produces a prioritized update plan.

Install

bash
git clone https://github.com/thatrebeccarae/claude-marketing.git && cp -r claude-marketing/skills/dep-audit ~/.claude/skills/

When to Use

  • Monthly hygiene: Run on a cadence to catch dependency drift before it compounds
  • Before releases: Verify no known vulnerabilities ship to production
  • Security incidents: When a CVE drops, quickly assess exposure across all repos
  • Onboarding new repos: Baseline the dependency health of a repo you're inheriting or adopting

Usage

  • /dep-audit [repo-path] — audit a single repository
  • /dep-audit [repo-path1] [repo-path2] ... — cross-repo audit (enables version conflict detection)

Procedure

1. Detect Package Managers

Scan the target repo(s) for manifest files:

ManagerManifestLock File
npmpackage.jsonpackage-lock.json
yarnpackage.jsonyarn.lock
pnpmpackage.jsonpnpm-lock.yaml
piprequirements.txt, setup.py, setup.cfgrequirements.txt (pinned)
poetrypyproject.toml (has [tool.poetry])poetry.lock
uvpyproject.toml (has [tool.uv])uv.lock
cargoCargo.tomlCargo.lock
go modgo.modgo.sum
bash
# Detect which manifests exist
ls package.json pyproject.toml Cargo.toml go.mod requirements.txt 2>/dev/null
# Detect lock files
ls package-lock.json yarn.lock pnpm-lock.yaml poetry.lock uv.lock Cargo.lock go.sum 2>/dev/null

If multiple ecosystems are present (e.g., a monorepo with Node.js frontend and Go backend), audit each independently and merge results.

2. Parse Manifests and Lock Files

Read the manifest to identify declared dependencies (direct) and the lock file for resolved versions (transitive). Distinguish between:

  • Production dependencies (dependencies, [dependencies], main requires)
  • Development dependencies (devDependencies, [dev-dependencies], extras)
3. Check for Outdated Packages

Query the registry for latest versions and categorize the delta:

bash
# Node.js
npm outdated --json

# Python (pip)
pip list --outdated --format=json

# Python (poetry)
poetry show --outdated

# Rust
cargo outdated --format json  # requires cargo-outdated

# Go
go list -m -u all

Categorize each outdated package:

  • Patch update (e.g., 2.3.1 -> 2.3.4): Safe, usually bug fixes
  • Minor update (e.g., 2.3.1 -> 2.5.0): New features, should be backward-compatible
  • Major update (e.g., 2.3.1 -> 3.0.0): Breaking changes likely, needs migration review
4. Check for Security Advisories

Run ecosystem-native audit tools:

bash
# Node.js
npm audit --json

# Python
pip-audit --format=json  # or: safety check

# Rust
cargo audit --json  # requires cargo-audit

# Go
govulncheck ./...

Parse severity from results:

  • Critical: Remote code execution, authentication bypass, data exfiltration
  • High: Privilege escalation, significant data exposure
  • Medium: DoS potential, limited data exposure
  • Low: Information disclosure, minor issues
5. Cross-Repo Analysis (Multiple Repos)

When auditing two or more repos, compare dependency versions:

  • Version conflicts: Same package at different versions across repos (e.g., axios@0.27.2 in repo A, axios@1.6.2 in repo B)
  • Shared dependencies: Packages used by multiple repos that could be aligned to a single version
  • Divergent major versions: Flag these as highest priority — they indicate repos drifting apart

Present a conflict table showing package, version per repo, and recommended target version.

6. License Scan

Check dependency licenses against compatibility rules:

bash
# Node.js
npx license-checker --json

# Python
pip-licenses --format=json

# Rust
cargo license --json  # requires cargo-license

# Go
go-licenses report ./...  # requires go-licenses

Flag issues:

  • Copyleft in permissive projects: GPL/AGPL dependencies in MIT/Apache-licensed projects
  • Unknown or missing licenses: Dependencies with no license metadata
  • Non-OSI-approved licenses: Custom or restrictive licenses
  • License conflicts: Incompatible license combinations (e.g., GPLv2-only with Apache-2.0)
7. Generate Update Plan

Prioritize all findings into a single ordered list:

  1. Critical security advisories — fix immediately
  2. High security advisories — fix this sprint
  3. License violations — assess and remediate
  4. Major outdated (with known issues) — plan migration
  5. Cross-repo version conflicts — align versions
  6. Minor outdated — batch update
  7. Patch outdated — batch update

Group related updates together:

  • All @types/* packages in one PR
  • All packages from the same org (e.g., @babel/*)
  • Peer dependency chains that must move together

Note breaking change risks for any major update. Link to migration guides where available.

Show full SKILL.md (287 more words)Show less
8. Report

Produce a severity-coded summary table:

PriorityPackageCurrentLatestTypeSeverityRepos AffectedAction
1lodash4.17.194.17.21patchCRITICAL (CVE-2021-23337)repo-a, repo-bUpdate immediately
2express4.17.14.21.2minorHIGH (CVE-2024-29041)repo-aUpdate this sprint
3webpack4.46.05.94.0majorMEDIUM (outdated)repo-aPlan migration
...

Follow with:

  • Total dependency count (direct / transitive) per repo
  • Security summary: X critical, Y high, Z medium, W low
  • Outdated summary: X major, Y minor, Z patch
  • License summary: X flagged, Y clean
  • Cross-repo conflicts: X packages with version divergence

Key Principles

  1. Never auto-update. This skill audits and recommends. The human decides what to update and when. Automated updates can introduce breaking changes, especially for major versions.
  2. Security first. Critical and high-severity vulnerabilities always top the priority list, regardless of how old other dependencies are.
  3. Group related updates. Updating react without updating react-dom creates version mismatches. Always identify peer dependency chains.
  4. Context matters. A major version bump on a dev-only dependency (e.g., eslint) is lower risk than a patch on a production runtime dependency with a CVE.
  5. Lock files are truth. Always read the lock file for actual resolved versions, not just the range specifier in the manifest.
  6. Don't chase latest for its own sake. If a dependency is working, stable, and has no advisories, "outdated" is not the same as "broken."

How to Use This Skill

Ask:

  • "Audit the dependencies in ~/Repos/my-app"
  • "Compare dependency versions across these three repos"
  • "Are there any security vulnerabilities in this project?"
  • "Check for license issues before we open-source this repo"
  • "Build me an update plan for everything that's behind"

For command reference, license compatibility details, and false positive handling, see REFERENCE.md. For worked examples, see EXAMPLES.md.

© thatrebeccarae, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 3 other files in skills/dep-audit of thatrebeccarae/claude-marketing.

  • SKILL.md
  • EXAMPLES.md
  • LICENSE
  • REFERENCE.md

Open the folder on GitHubat commit a8a63ec

Compare with similar skills

Dep Audit next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Dep Audit compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Dep Audit this skillthatrebeccarae/claude-marketing161—~2kAutomated safety check: PassMIT
CI Pipeline Synthesizerkajisho5/ffmpeg-skill1.9k1 repos~1.1kAutomated safety check: PassMIT
Dep Auditorlaolaoshiren/claude-code-skills-zh880—~895Automated safety check: PassMIT
Dependency Scanjwynia/agent-skills170—~1.7kAutomated safety check: PassMIT
SDK ReleasePrismer-AI/PrismerCloud1.6k—~1.9kAutomated safety check: WarnMIT
Fory Releaseapache/fory4.6k—~2.9kAutomated safety check: PassApache-2.0

Similar skills

  • CI Pipeline Synthesizer

    kajisho5/ffmpeg-skill

    Generate GitHub Actions CI/CD pipeline configurations for automated building and testing of library and package projects.

    1.9k GitHub starsUsed in 1 repo~1.1k tokens
    DevOps & CloudAuto-check passed
  • Dep Auditor

    laolaoshiren/claude-code-skills-zh

    审计 Node.js、Python、Go、Rust、JVM、Ruby 项目的依赖漏洞、版本健康度与许可证事实;当用户要求检查 package.json、lockfile、requirements、go.mod、Cargo.toml、pom.xml、Gemfile.lock,或生成不改依赖的中文审计报告时使用

    880 GitHub stars~895 tokensUpdated 5 days ago
    DevelopmentAuto-check passed
  • Dependency Scan

    jwynia/agent-skills

    Detect CVEs and security issues in project dependencies. An agent skill from jwynia/agent-skills.

    170 GitHub stars~1.7k tokensUpdated 7 mo ago
    SecurityAuto-check passed
  • SDK Release

    Prismer-AI/PrismerCloud

    SDK build, test, version bump, and release to open source repo + registries.

    1.6k GitHub stars~1.9k tokensUpdated 10 days ago
    Agent WorkflowsAuto-check: warnings
  • Fory Release

    apache/fory

    Prepare an Apache Fory release candidate from a clean release branch, including the version bump, RC tag, JVM staging, ASF source artifacts, SVN upload, and vote email.

    4.6k GitHub stars~2.9k tokensUpdated today
    Auto-check passed
  • Release Skills

    nexmoe/eve

    Universal release workflow. An agent skill from nexmoe/eve.

    421 GitHub starsUsed in 3 repos~3.3k tokens
    DevelopmentAuto-check passed

More from thatrebeccarae/claude-marketing

All 55 skills in this repo
  • Google Analytics

    thatrebeccarae/claude-marketing

    Analyze Google Analytics data, review website performance metrics, identify traffic patterns, and suggest data-driven improvements.

    161 GitHub starsUsed in 3 repos~1.3k tokens
    Auto-check: notes
  • Content Creator

    thatrebeccarae/claude-marketing

    Comprehensive content marketing toolkit with brand voice analysis, SEO optimization scripts, content frameworks, social media strategy, and content calendar planning.

    161 GitHub stars~1.1k tokensUpdated 4 mo ago
    Auto-check passed
  • Klaviyo Analyst

    thatrebeccarae/claude-marketing

    Klaviyo marketing operations and analyst expertise. An agent skill from thatrebeccarae/claude-marketing.

    161 GitHub stars~5k tokensUpdated 4 mo ago
    Auto-check: notes
  • Klaviyo Developer

    thatrebeccarae/claude-marketing

    Klaviyo API and developer integration expertise. An agent skill from thatrebeccarae/claude-marketing.

    161 GitHub stars~4.9k tokensUpdated 4 mo ago
    Auto-check: notes
  • Looker Studio

    thatrebeccarae/claude-marketing

    Looker Studio (formerly Google Data Studio) expertise. An agent skill from thatrebeccarae/claude-marketing.

    161 GitHub stars~3.6k tokensUpdated 4 mo ago
    Auto-check: notes
  • Shopify

    thatrebeccarae/claude-marketing

    Shopify e-commerce platform marketing expertise. An agent skill from thatrebeccarae/claude-marketing.

    161 GitHub stars~2.4k tokensUpdated 4 mo ago
    Auto-check: notes

Categories

Questions about Dep Audit

What does Dep Audit do?

Cross-repository dependency audit. An agent skill from thatrebeccarae/claude-marketing. Dep Audit is an agent skill from thatrebeccarae/claude-marketing. Cross-repository dependency audit.

When should I use Dep Audit?

Dep Audit fits situations like: marketing & SEO work in your project.

How do I install Dep Audit in Claude Code?

Run `npx skills add thatrebeccarae/claude-marketing --skill dep-audit -a claude-code`. Or copy the skill folder (skills/dep-audit in thatrebeccarae/claude-marketing) into .claude/skills/dep-audit in your project. Claude Code loads it when a task matches its description.

How do I install Dep Audit in Codex?

Run `npx skills add thatrebeccarae/claude-marketing --skill dep-audit -a codex`. Or copy the skill folder (skills/dep-audit in thatrebeccarae/claude-marketing) into .agents/skills/dep-audit in your project. Codex loads it when a task matches its description.

Can I use Dep Audit in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add thatrebeccarae/claude-marketing --skill dep-audit -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/dep-audit, .gemini/skills/dep-audit, .github/skills/dep-audit and .opencode/skills/dep-audit in your project.

What does Dep Audit need to run?

Going by SKILL.md and its folder, Dep Audit needs the command-line tools its instructions call (cargo, npm, git, pip, poetry and go). Our summary lists: Python 3; Node.js.

Does Dep Audit access the network?

SKILL.md contains no URLs. Its commands use npm, git, pip and npx, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Dep Audit safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Dep Audit use?

Dep Audit is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Dep Audit use?

About 2k tokens (SKILL.md is roughly 7.9k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Dep Audit?

Skills that share tags, products or a category with Dep Audit: CI Pipeline Synthesizer (kajisho5/ffmpeg-skill, 1.9k stars), Dep Auditor (laolaoshiren/claude-code-skills-zh, 880 stars), Dependency Scan (jwynia/agent-skills, 170 stars) and SDK Release (Prismer-AI/PrismerCloud, 1.6k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Dep Audit?

thatrebeccarae (a GitHub user) maintains it in thatrebeccarae/claude-marketing, which has 161 GitHub stars. The repository holds 55 skills in this directory. The repository was last updated on May 14, 2026.

Source: thatrebeccarae/claude-marketing on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.