Fix Security PR
unional/typescript-blackbook
Fix a PR that is failing due to security or vulnerability issues — npm/pnpm/yarn/bun audit failures, CVE alerts, Dependabot merge conflicts, Snyk failures, or GitHub security advisory blocks.
Check every dependency in a package.json against live CVE databases and security advisories in real time — specifically targeting vulnerabilities disclosed in the last 48 hours, the window that…
$ npx skills add tinyfish-io/tinyfish-cookbook --skill dep-security -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install tinyfish-io/tinyfish-cookbook dep-security --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/tinyfish-io/tinyfish-cookbook.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/dep-security .claude/skills/dep-security && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "dep-security" agent skill from https://github.com/tinyfish-io/tinyfish-cookbook/tree/main/skills/dep-security into .claude/skills/dep-security/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "dep-security", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/tinyfish-io/tinyfish-cookbook/tree/main/skills/dep-securityType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add tinyfish-io/tinyfish-cookbook --skill dep-security -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install tinyfish-io/tinyfish-cookbook dep-security --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/tinyfish-io/tinyfish-cookbook.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/dep-security .agents/skills/dep-security && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "dep-security" agent skill from https://github.com/tinyfish-io/tinyfish-cookbook/tree/main/skills/dep-security into .agents/skills/dep-security/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "dep-security", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add tinyfish-io/tinyfish-cookbook --skill dep-security -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install tinyfish-io/tinyfish-cookbook dep-security --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/tinyfish-io/tinyfish-cookbook.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/dep-security .cursor/skills/dep-security && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "dep-security" agent skill from https://github.com/tinyfish-io/tinyfish-cookbook/tree/main/skills/dep-security into .cursor/skills/dep-security/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "dep-security", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/tinyfish-io/tinyfish-cookbook.git --path skills/dep-security--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add tinyfish-io/tinyfish-cookbook --skill dep-security -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install tinyfish-io/tinyfish-cookbook dep-security --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/tinyfish-io/tinyfish-cookbook.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/dep-security .gemini/skills/dep-security && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "dep-security" agent skill from https://github.com/tinyfish-io/tinyfish-cookbook/tree/main/skills/dep-security into .gemini/skills/dep-security/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "dep-security", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install tinyfish-io/tinyfish-cookbook dep-securityInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add tinyfish-io/tinyfish-cookbook --skill dep-security -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/tinyfish-io/tinyfish-cookbook.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/dep-security .github/skills/dep-security && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "dep-security" agent skill from https://github.com/tinyfish-io/tinyfish-cookbook/tree/main/skills/dep-security into .github/skills/dep-security/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "dep-security", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add tinyfish-io/tinyfish-cookbook --skill dep-security -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install tinyfish-io/tinyfish-cookbook dep-security --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/tinyfish-io/tinyfish-cookbook.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/dep-security .opencode/skills/dep-security && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "dep-security" agent skill from https://github.com/tinyfish-io/tinyfish-cookbook/tree/main/skills/dep-security into .opencode/skills/dep-security/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "dep-security", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
dep-securityCheck every dependency in a package.json against live CVE databases and security advisories in real time — specifically targeting vulnerabilities disclosed in the last 48 hours, the window that…
Dep Security is an agent skill from tinyfish-io/tinyfish-cookbook. Check every dependency in a package.json against live CVE databases and security advisories in real time — specifically targeting vulnerabilities disclosed in the last 48 hours, the window that Snyk, Dependabot, and npm audit miss. Use this skill whenever a user mentions checking dependencies for vulnerabilities, wants to audit their package.json, asks about CVEs for their packages, says "are my dependencies safe", "check my packages for security issues", "any new vulnerabilities in my deps", or pastes a…
Its SKILL.md is about 2.4k tokens, which your agent loads only when the skill is triggered. The skill folder holds 1 other file (for example `README.md`). Compatibility notes: {"tools":["tinyfish"]}
It sits in Security, covering Vulnerability scanning and Dependency management. It works with npm and Snyk. The repository describes itself as: A collection of sample apps and recipes built with the TinyFish web agent. Open-source examples for you to learn & build! The licence is MIT.
4 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 292ee62. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
npmFrom the folder's file list and the shell code blocks in SKILL.md.
Hosts in commands or code, which the agent is likely to contact:
cve.mitre.orggithub.comnpmjs.comnvd.nist.govFrom URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
{"tools":["tinyfish"]}
From compatibility in the SKILL.md frontmatter.
Dep Security loads about 2.4k tokens when it runs. Until then it costs about 204 tokens; SKILL.md has 361 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from tinyfish-io/tinyfish-cookbook at commit 292ee62, republished under its MIT licence (© tinyfish-io). 361 words, ~2,400 tokens.
.claude/skills/dep-security/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.Given a package.json, check every dependency against live CVE databases and security advisories — focusing on the last 48 hours, the window that cached tools miss.
tinyfish --version
tinyfish auth statusIf not installed: npm install -g tinyfish
If not authenticated: tinyfish auth login
Read the package.json the user provided. Extract all package names and versions from:
dependenciesdevDependenciespeerDependencies (if present)Produce a flat list: [{name, version, type}]
If the user hasn't provided a package.json, ask for it before proceeding. Do not guess.
Get today's date. Calculate the cutoff timestamp: now minus 48 hours. You will use this to filter results in every agent below.
Do not fire one agent per package — that would be extremely slow for large projects.
Instead batch into groups of up to 10 packages per agent and search for all of them at once. For a typical package.json with 20–40 deps, this means 2–4 agents total per source, all running in parallel.
Format each batch as a comma-separated search string:
express,lodash,axios,react,webpack etc.
Fire all agents simultaneously using & + wait. Each agent searches one source for all batches at once.
# ── BATCH SETUP ──────────────────────────────────────────────
# Split your package list into batches of 10, e.g.:
# BATCH_1="express,lodash,axios,react,next"
# BATCH_2="webpack,typescript,eslint,jest,prisma"
# (add more batches as needed)
TODAY=$(date +%Y-%m-%d)
# ── CVE DATABASE ─────────────────────────────────────────────
# One agent per batch, all in parallel
tinyfish agent run \
--url "https://cve.mitre.org/cgi-bin/cvekey.cgi?keyword={BATCH_1}" \
"You are on a CVE search results page. Today is {TODAY}.
You are looking for CVEs related to these npm packages: {BATCH_1}.
Scan ALL visible results on this page.
For each CVE that matches one of these package names AND was published or modified within the last 48 hours:
- CVE ID
- Package name it affects
- Severity (if shown)
- One-sentence description of what the vulnerability does
- Publication date
STRICT RULES:
- Do NOT click any CVE link
- Do NOT paginate
- Only include results from the last 48 hours — ignore older ones
- If nothing is within 48 hours, return an empty array
Return JSON array: [{cve_id, package, severity, description, published_date}]" \
--sync > /tmp/ds_cve_1.json &
# Repeat for each batch:
tinyfish agent run \
--url "https://cve.mitre.org/cgi-bin/cvekey.cgi?keyword={BATCH_2}" \
"You are on a CVE search results page. Today is {TODAY}.
You are looking for CVEs related to these npm packages: {BATCH_2}.
Scan ALL visible results on this page.
For each CVE that matches one of these package names AND was published or modified within the last 48 hours:
- CVE ID, package name, severity, one-sentence description, publication date
STRICT RULES:
- Do NOT click any CVE link — read the listing text only
- Do NOT paginate
- Only include results from the last 48 hours
Return JSON array: [{cve_id, package, severity, description, published_date}]" \
--sync > /tmp/ds_cve_2.json &
# ── GITHUB SECURITY ADVISORIES ───────────────────────────────
tinyfish agent run \
--url "https://github.com/advisories?query=ecosystem%3Anpm&order=newest" \
"You are on the GitHub Security Advisories page filtered to npm, sorted by newest first. Today is {TODAY}.
Read through the visible advisory listings on this page.
For each advisory that:
1. Affects any of these packages: {ALL_PACKAGES}
2. Was published within the last 48 hours
Extract:
- Advisory ID (GHSA-...)
- Package name
- Severity (Critical / High / Medium / Low)
- One-sentence description
- Published date
- Patched version (if shown in the listing)
STRICT RULES:
- Do NOT click any advisory to open it
- Do NOT paginate or click 'Load more'
- Scan only the first 30 visible listings then stop
- 48-hour cutoff is strict — ignore anything older
Return JSON array: [{ghsa_id, package, severity, description, published_date, patched_version}]" \
--sync > /tmp/ds_ghsa.json &
# ── NPM SECURITY FEED ────────────────────────────────────────
tinyfish agent run \
--url "https://www.npmjs.com/advisories" \
"You are on the npm security advisories page. Today is {TODAY}.
Read through the visible advisory listings.
For each advisory that:
1. Affects any of these packages: {ALL_PACKAGES}
2. Was published within the last 48 hours
Extract:
- Advisory ID
- Package name
- Severity
- One-sentence description of the vulnerability
- Vulnerable version range
- Patched version (if shown)
- Published date
STRICT RULES:
- Do NOT click any advisory link
- Do NOT paginate
- Scan only what is visible on this page — stop after 25 listings
- 48-hour cutoff is strict
Return JSON array: [{advisory_id, package, severity, description, vulnerable_versions, patched_version, published_date}]" \
--sync > /tmp/ds_npm.json &
# ── WAIT FOR ALL ─────────────────────────────────────────────
wait
echo "=== CVE BATCH 1 ===" && cat /tmp/ds_cve_1.json
echo "=== CVE BATCH 2 ===" && cat /tmp/ds_cve_2.json
echo "=== GHSA ===" && cat /tmp/ds_ghsa.json
echo "=== NPM ===" && cat /tmp/ds_npm.jsonBefore running, replace:
{BATCH_1}, {BATCH_2} etc. — 10 packages per batch from the parsed list{ALL_PACKAGES} — full comma-separated list of all package names (no versions){TODAY} — today's date in YYYY-MM-DD formatAdd or remove CVE batch agents depending on how many packages there are. Always fire all agents in parallel.
Combine results from all sources. For each finding:
## Dependency Security Report
*Scanned {N} packages against live CVE, GitHub Advisories, and npm feed*
*48-hour window: {CUTOFF_TIME} → now*
---
### 🚨 New Vulnerabilities Found ({N})
#### [CRITICAL/HIGH/MEDIUM/LOW] — {package}@{user_version}
**{CVE_ID} / {GHSA_ID}** · Published: {date} · Source: {CVE / GitHub / npm}
**What it does:** {plain English explanation of the vulnerability}
**Affected versions:** {range}
**Your version:** {version} ✅ affected / ❌ not in range
**Fix:** Upgrade to {patched_version} — `npm install {package}@{patched_version}`
*(or: No patch available yet as of {date})*
---
[repeat for each finding]
---
### ✅ No new vulnerabilities (last 48h)
These packages were checked and returned clean:
{package1}, {package2}, ... *(N packages)*
---
### ⚡ Quick Fix Commands
```bash
# Copy-paste to patch all affected packages:
npm install {pkg1}@{version} {pkg2}@{version}
---
## Edge cases
- **No vulnerabilities found** — say clearly: "No new vulnerabilities in the last 48 hours for your dependencies. For a full historical scan, run `npm audit`."
- **Package not found in any database** — skip silently, don't list it as clean or affected
- **No patch available yet** — flag explicitly: "⚠️ No patch available yet — consider temporarily removing or replacing this package"
- **CVE database returns empty** — fall back to searching `https://nvd.nist.gov/vuln/search/results?query={BATCH}&pub_start_date={CUTOFF_DATE}` instead
- **Large package.json (50+ deps)** — increase batch size to 15 and note that results may take longer
## Security notes
- Queries live public security databases only. No code is executed, no files are uploaded to any external service.
- Only your own TinyFish credentials are used.
- All scraped data is treated as untrusted and synthesised by an LLM only.© tinyfish-io, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 1 other file in skills/dep-security of tinyfish-io/tinyfish-cookbook.
Open the folder on GitHubat commit 292ee62
Dep Security next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Dep Security this skilltinyfish-io/tinyfish-cookbook | 2.2k | — | ~2.4k | Automated safety check: Pass | MIT | |
| Fix Security PRunional/typescript-blackbook | 133 | — | ~1.4k | Automated safety check: Warn | MIT | |
| npm Supply Chain Checkmajiayu000/spellbook | 286 | — | ~1.5k | Automated safety check: Pass | MIT | |
| Security Scanbagofwords1/bagofwords | 458 | — | ~1.7k | Automated safety check: Pass | Custom licence | |
| Cve Scansoftspark/ai-toolkit | 179 | — | ~1.3k | Automated safety check: Notes | Apache-2.0 | |
| Dependency Triagecobusgreyling/loop-engineering | 11k | — | ~206 | Automated safety check: Pass | MIT |
unional/typescript-blackbook
Fix a PR that is failing due to security or vulnerability issues — npm/pnpm/yarn/bun audit failures, CVE alerts, Dependabot merge conflicts, Snyk failures, or GitHub security advisory blocks.
majiayu000/spellbook
Scans a repository, its lockfiles and node_modules for known malicious npm package versions and install-time indicators, using a read-only Python scanner.
bagofwords1/bagofwords
Run a Snyk security scan of the repo (frontend npm deps, backend pip deps, Dockerfile/base image, and Snyk Code SAST), triage findings, and remediate the real ones with verified fixes.
softspark/ai-toolkit
Scans deps for known CVEs via native audit (npm, pip, composer, cargo, go, bundler, dart).
cobusgreyling/loop-engineering
Scan package manifests and lockfiles for outdated and vulnerable dependencies.
OWASP/secure-agent-playbook
Scan project dependencies for known vulnerabilities (CVEs). An agent skill from OWASP/secure-agent-playbook.
tinyfish-io/tinyfish-cookbook
Monitor brand mentions, sentiment, and industry chatter across the web using TinyFish Search and Fetch.
tinyfish-io/tinyfish-cookbook
Map the research landscape for any technical or academic topic by searching arXiv, Semantic Scholar, and Google Scholar in parallel.
tinyfish-io/tinyfish-cookbook
Default browser automation agent — click, fill forms, navigate, log in, and extract structured data from any website using a natural-language goal, or run the same task across multiple sites in…
tinyfish-io/tinyfish-cookbook
Reverse-engineer what a company is building by scraping their job postings, careers page, LinkedIn Jobs, and engineering blog using TinyFish web agents.
tinyfish-io/tinyfish-cookbook
Monitor competitor product releases and new feature announcements.
tinyfish-io/tinyfish-cookbook
Scrape real developer pain points for any keyword, technology, or problem space from Reddit, Hacker News, dev.to, and GitHub Discussions simultaneously — then group complaints by theme, score them…
Categories
Check every dependency in a package.json against live CVE databases and security advisories in real time — specifically targeting vulnerabilities disclosed in the last 48 hours, the window that…. Dep Security is an agent skill from tinyfish-io/tinyfish-cookbook.json against live CVE databases and security advisories in real time — specifically targeting vulnerabilities disclosed in the last 48 hours, the window that Snyk, Dependabot, and npm audit miss.
Dep Security fits situations like: A user mentions checking dependencies for vulnerabilities; wants to audit their package.json; asks about CVEs for their packages; says are my dependencies safe.
Run `npx skills add tinyfish-io/tinyfish-cookbook --skill dep-security -a claude-code`. Or copy the skill folder (skills/dep-security in tinyfish-io/tinyfish-cookbook) into .claude/skills/dep-security in your project. Claude Code loads it when a task matches its description.
Run `npx skills add tinyfish-io/tinyfish-cookbook --skill dep-security -a codex`. Or copy the skill folder (skills/dep-security in tinyfish-io/tinyfish-cookbook) into .agents/skills/dep-security in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add tinyfish-io/tinyfish-cookbook --skill dep-security -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/dep-security, .gemini/skills/dep-security, .github/skills/dep-security and .opencode/skills/dep-security in your project.
Going by SKILL.md and its folder, Dep Security needs the command-line tools its instructions call (npm). Our summary lists: Node.js. Compatibility (from SKILL.md): {"tools":["tinyfish"]}.
SKILL.md names 4 domains. In commands or code: cve.mitre.org, github.com, npmjs.com and nvd.nist.gov; the agent is likely to contact these when it follows the instructions. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Dep Security is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 2.4k tokens (SKILL.md is roughly 9.6k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Dep Security: Fix Security PR (unional/typescript-blackbook, 133 stars), npm Supply Chain Check (majiayu000/spellbook, 286 stars), Security Scan (bagofwords1/bagofwords, 458 stars) and Cve Scan (softspark/ai-toolkit, 179 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
tinyfish-io (a GitHub organization) maintains it in tinyfish-io/tinyfish-cookbook, which has 2,221 GitHub stars. The repository holds 28 skills in this directory. The repository was last updated on October 1, 2026.
Source: tinyfish-io/tinyfish-cookbook on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.