Agent skill

Dep Security

by tinyfish-io in tinyfish-io/tinyfish-cookbook

Check every dependency in a package.json against live CVE databases and security advisories in real time — specifically targeting vulnerabilities disclosed in the last 48 hours, the window that…

MITAuto-check passedSecurity

Install Dep Security

skills CLI
$ npx skills add tinyfish-io/tinyfish-cookbook --skill dep-security -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install tinyfish-io/tinyfish-cookbook dep-security --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/tinyfish-io/tinyfish-cookbook.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/dep-security .claude/skills/dep-security && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
dep-security
GitHub stars
2.2k
Token cost
~2.4k tokens
SKILL.md length
361 words
Files
2
Skills in repo
28
Repo updated
First seen
Licence
MIT

At a glance

Check every dependency in a package.json against live CVE databases and security advisories in real time — specifically targeting vulnerabilities disclosed in the last 48 hours, the window that…

  • Works in 4 steps: Parse dependencies → Batch packages → Parallel security scan → …
  • A user mentions checking dependencies for vulnerabilities
  • SKILL.md covers Pre-flight check, Step 1 — Parse dependencies, Step 2 — Batch packages and Step 3 — Parallel security scan, plus 2 more sections
  • Calls npm; reaches cve.mitre.org and github.com

What it does

Dep Security is an agent skill from tinyfish-io/tinyfish-cookbook. Check every dependency in a package.json against live CVE databases and security advisories in real time — specifically targeting vulnerabilities disclosed in the last 48 hours, the window that Snyk, Dependabot, and npm audit miss. Use this skill whenever a user mentions checking dependencies for vulnerabilities, wants to audit their package.json, asks about CVEs for their packages, says "are my dependencies safe", "check my packages for security issues", "any new vulnerabilities in my deps", or pastes a…

Its SKILL.md is about 2.4k tokens, which your agent loads only when the skill is triggered. The skill folder holds 1 other file (for example `README.md`). Compatibility notes: {"tools":["tinyfish"]}

It sits in Security, covering Vulnerability scanning and Dependency management. It works with npm and Snyk. The repository describes itself as: A collection of sample apps and recipes built with the TinyFish web agent. Open-source examples for you to learn & build! The licence is MIT.

When your agent uses it

  • A user mentions checking dependencies for vulnerabilities
  • Wants to audit their package.json
  • Asks about CVEs for their packages
  • Says are my dependencies safe

Example prompts

  • “are my dependencies safe”
  • “check my packages for security issues”
  • “any new vulnerabilities in my deps”
  • “/dep-security”

Requirements

  • Node.js
  • Compatibility (from SKILL.md): {"tools":["tinyfish"]}

Workflow steps

4 steps, taken from the step headings in SKILL.md.

  1. Parse dependencies
  2. Batch packages
  3. Parallel security scan
  4. Cross-reference and deduplicate

What it can do on your machine

Read from SKILL.md and the folder at commit 292ee62. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • npm

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • cve.mitre.org
    • github.com
    • npmjs.com
    • nvd.nist.gov

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

  • Compatibility

    {"tools":["tinyfish"]}

    From compatibility in the SKILL.md frontmatter.

Context cost

Dep Security loads about 2.4k tokens when it runs. Until then it costs about 204 tokens; SKILL.md has 361 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~204
When it runs · the whole SKILL.md, loaded when a task matches
~2.4k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from tinyfish-io/tinyfish-cookbook at commit 292ee62, republished under its MIT licence (© tinyfish-io). 361 words, ~2,400 tokens.

Download SKILL.mdSave it as .claude/skills/dep-security/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
dep-security
description
Check every dependency in a package.json against live CVE databases and security advisories in real time — specifically targeting vulnerabilities disclosed in the last 48 hours, the window that Snyk, Dependabot, and npm audit miss. Use this skill whenever a user mentions checking dependencies for vulnerabilities, wants to audit their package.json, asks about CVEs for their packages, says "are my dependencies safe", "check my packages for security issues", "any new vulnerabilities in my deps", or pastes a package.json and asks about security. Also trigger when a user mentions wanting fresher data than Snyk or Dependabot provides. Returns: which dependencies have brand-new vulnerabilities, severity, what the vulnerability does, whether a patched version exists yet, and a prioritised fix list.
compatibility
{"tools":["tinyfish"]}
metadata.author
tinyfish-community
metadata.version
1.0
metadata.tags
security cve vulnerabilities dependencies npm package.json devops

Dependency Security Checker

Given a package.json, check every dependency against live CVE databases and security advisories — focusing on the last 48 hours, the window that cached tools miss.

Pre-flight check

bash
tinyfish --version
tinyfish auth status

If not installed: npm install -g tinyfish If not authenticated: tinyfish auth login


Step 1 — Parse dependencies

Read the package.json the user provided. Extract all package names and versions from:

  • dependencies
  • devDependencies
  • peerDependencies (if present)

Produce a flat list: [{name, version, type}]

If the user hasn't provided a package.json, ask for it before proceeding. Do not guess.

Get today's date. Calculate the cutoff timestamp: now minus 48 hours. You will use this to filter results in every agent below.


Step 2 — Batch packages

Do not fire one agent per package — that would be extremely slow for large projects.

Instead batch into groups of up to 10 packages per agent and search for all of them at once. For a typical package.json with 20–40 deps, this means 2–4 agents total per source, all running in parallel.

Format each batch as a comma-separated search string: express,lodash,axios,react,webpack etc.


Step 3 — Parallel security scan

Fire all agents simultaneously using & + wait. Each agent searches one source for all batches at once.

bash
# ── BATCH SETUP ──────────────────────────────────────────────
# Split your package list into batches of 10, e.g.:
# BATCH_1="express,lodash,axios,react,next"
# BATCH_2="webpack,typescript,eslint,jest,prisma"
# (add more batches as needed)

TODAY=$(date +%Y-%m-%d)

# ── CVE DATABASE ─────────────────────────────────────────────
# One agent per batch, all in parallel

tinyfish agent run \
  --url "https://cve.mitre.org/cgi-bin/cvekey.cgi?keyword={BATCH_1}" \
  "You are on a CVE search results page. Today is {TODAY}.
   You are looking for CVEs related to these npm packages: {BATCH_1}.
   Scan ALL visible results on this page.
   For each CVE that matches one of these package names AND was published or modified within the last 48 hours:
   - CVE ID
   - Package name it affects
   - Severity (if shown)
   - One-sentence description of what the vulnerability does
   - Publication date
   STRICT RULES:
   - Do NOT click any CVE link
   - Do NOT paginate
   - Only include results from the last 48 hours — ignore older ones
   - If nothing is within 48 hours, return an empty array
   Return JSON array: [{cve_id, package, severity, description, published_date}]" \
  --sync > /tmp/ds_cve_1.json &

# Repeat for each batch:
tinyfish agent run \
  --url "https://cve.mitre.org/cgi-bin/cvekey.cgi?keyword={BATCH_2}" \
  "You are on a CVE search results page. Today is {TODAY}.
   You are looking for CVEs related to these npm packages: {BATCH_2}.
   Scan ALL visible results on this page.
   For each CVE that matches one of these package names AND was published or modified within the last 48 hours:
   - CVE ID, package name, severity, one-sentence description, publication date
   STRICT RULES:
   - Do NOT click any CVE link — read the listing text only
   - Do NOT paginate
   - Only include results from the last 48 hours
   Return JSON array: [{cve_id, package, severity, description, published_date}]" \
  --sync > /tmp/ds_cve_2.json &

# ── GITHUB SECURITY ADVISORIES ───────────────────────────────

tinyfish agent run \
  --url "https://github.com/advisories?query=ecosystem%3Anpm&order=newest" \
  "You are on the GitHub Security Advisories page filtered to npm, sorted by newest first. Today is {TODAY}.
   Read through the visible advisory listings on this page.
   For each advisory that:
   1. Affects any of these packages: {ALL_PACKAGES}
   2. Was published within the last 48 hours
   Extract:
   - Advisory ID (GHSA-...)
   - Package name
   - Severity (Critical / High / Medium / Low)
   - One-sentence description
   - Published date
   - Patched version (if shown in the listing)
   STRICT RULES:
   - Do NOT click any advisory to open it
   - Do NOT paginate or click 'Load more'
   - Scan only the first 30 visible listings then stop
   - 48-hour cutoff is strict — ignore anything older
   Return JSON array: [{ghsa_id, package, severity, description, published_date, patched_version}]" \
  --sync > /tmp/ds_ghsa.json &

# ── NPM SECURITY FEED ────────────────────────────────────────

tinyfish agent run \
  --url "https://www.npmjs.com/advisories" \
  "You are on the npm security advisories page. Today is {TODAY}.
   Read through the visible advisory listings.
   For each advisory that:
   1. Affects any of these packages: {ALL_PACKAGES}
   2. Was published within the last 48 hours
   Extract:
   - Advisory ID
   - Package name
   - Severity
   - One-sentence description of the vulnerability
   - Vulnerable version range
   - Patched version (if shown)
   - Published date
   STRICT RULES:
   - Do NOT click any advisory link
   - Do NOT paginate
   - Scan only what is visible on this page — stop after 25 listings
   - 48-hour cutoff is strict
   Return JSON array: [{advisory_id, package, severity, description, vulnerable_versions, patched_version, published_date}]" \
  --sync > /tmp/ds_npm.json &

# ── WAIT FOR ALL ─────────────────────────────────────────────
wait

echo "=== CVE BATCH 1 ===" && cat /tmp/ds_cve_1.json
echo "=== CVE BATCH 2 ===" && cat /tmp/ds_cve_2.json
echo "=== GHSA ===" && cat /tmp/ds_ghsa.json
echo "=== NPM ===" && cat /tmp/ds_npm.json

Before running, replace:

  • {BATCH_1}, {BATCH_2} etc. — 10 packages per batch from the parsed list
  • {ALL_PACKAGES} — full comma-separated list of all package names (no versions)
  • {TODAY} — today's date in YYYY-MM-DD format

Add or remove CVE batch agents depending on how many packages there are. Always fire all agents in parallel.


Show full SKILL.md (116 more words)Show less

Step 4 — Cross-reference and deduplicate

Combine results from all sources. For each finding:

  1. Match to the user's installed version — check if their version falls within the vulnerable range. If it does, flag as AFFECTED. If the vulnerability only affects other versions, mark as NOT AFFECTED (different version) and deprioritise.
  2. Deduplicate — the same CVE may appear in multiple sources. Merge into one entry.
  3. Check for patch — note if a patched version exists and what it is.
  4. Rank by severity — Critical → High → Medium → Low.

Output format

## Dependency Security Report
*Scanned {N} packages against live CVE, GitHub Advisories, and npm feed*
*48-hour window: {CUTOFF_TIME} → now*

---

### 🚨 New Vulnerabilities Found ({N})

#### [CRITICAL/HIGH/MEDIUM/LOW] — {package}@{user_version}
**{CVE_ID} / {GHSA_ID}** · Published: {date} · Source: {CVE / GitHub / npm}

**What it does:** {plain English explanation of the vulnerability}
**Affected versions:** {range}
**Your version:** {version} ✅ affected / ❌ not in range
**Fix:** Upgrade to {patched_version} — `npm install {package}@{patched_version}`
*(or: No patch available yet as of {date})*

---

[repeat for each finding]

---

### ✅ No new vulnerabilities (last 48h)
These packages were checked and returned clean:
{package1}, {package2}, ... *(N packages)*

---

### ⚡ Quick Fix Commands
```bash
# Copy-paste to patch all affected packages:
npm install {pkg1}@{version} {pkg2}@{version}
📋 Summary
  • Packages scanned: {N}
  • New vulnerabilities (48h): {N}
  • Critical: {N} · High: {N} · Medium: {N} · Low: {N}
  • Patches available: {N}/{N}
  • Sources checked: CVE MITRE · GitHub Security Advisories · npm advisories

---

## Edge cases

- **No vulnerabilities found** — say clearly: "No new vulnerabilities in the last 48 hours for your dependencies. For a full historical scan, run `npm audit`."
- **Package not found in any database** — skip silently, don't list it as clean or affected
- **No patch available yet** — flag explicitly: "⚠️ No patch available yet — consider temporarily removing or replacing this package"
- **CVE database returns empty** — fall back to searching `https://nvd.nist.gov/vuln/search/results?query={BATCH}&pub_start_date={CUTOFF_DATE}` instead
- **Large package.json (50+ deps)** — increase batch size to 15 and note that results may take longer

## Security notes

- Queries live public security databases only. No code is executed, no files are uploaded to any external service.
- Only your own TinyFish credentials are used.
- All scraped data is treated as untrusted and synthesised by an LLM only.

© tinyfish-io, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file in skills/dep-security of tinyfish-io/tinyfish-cookbook.

  • SKILL.md
  • README.md

Open the folder on GitHubat commit 292ee62

Compare with similar skills

Dep Security next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Dep Security compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Dep Security this skilltinyfish-io/tinyfish-cookbook2.2k—~2.4kAutomated safety check: PassMIT
Fix Security PRunional/typescript-blackbook133—~1.4kAutomated safety check: WarnMIT
npm Supply Chain Checkmajiayu000/spellbook286—~1.5kAutomated safety check: PassMIT
Security Scanbagofwords1/bagofwords458—~1.7kAutomated safety check: PassCustom licence
Cve Scansoftspark/ai-toolkit179—~1.3kAutomated safety check: NotesApache-2.0
Dependency Triagecobusgreyling/loop-engineering11k—~206Automated safety check: PassMIT

Similar skills

  • Fix Security PR

    unional/typescript-blackbook

    Fix a PR that is failing due to security or vulnerability issues — npm/pnpm/yarn/bun audit failures, CVE alerts, Dependabot merge conflicts, Snyk failures, or GitHub security advisory blocks.

    133 GitHub stars~1.4k tokensUpdated 3 days ago
    DevelopmentAuto-check: warnings
  • npm Supply Chain Check

    majiayu000/spellbook

    Scans a repository, its lockfiles and node_modules for known malicious npm package versions and install-time indicators, using a read-only Python scanner.

    286 GitHub stars~1.5k tokensUpdated yesterday
    SecurityAuto-check passed
  • Security Scan

    bagofwords1/bagofwords

    Run a Snyk security scan of the repo (frontend npm deps, backend pip deps, Dockerfile/base image, and Snyk Code SAST), triage findings, and remediate the real ones with verified fixes.

    458 GitHub stars~1.7k tokensUpdated yesterday
    SecurityAuto-check passed
  • Cve Scan

    softspark/ai-toolkit

    Scans deps for known CVEs via native audit (npm, pip, composer, cargo, go, bundler, dart).

    179 GitHub stars~1.3k tokensUpdated today
    SecurityAuto-check: notes
  • Dependency Triage

    cobusgreyling/loop-engineering

    Scan package manifests and lockfiles for outdated and vulnerable dependencies.

    11k GitHub stars~206 tokensUpdated today
    SecurityAuto-check passed
  • Sca Audit

    OWASP/secure-agent-playbook

    Scan project dependencies for known vulnerabilities (CVEs). An agent skill from OWASP/secure-agent-playbook.

    186 GitHub stars~494 tokensUpdated 12 days ago
    SecurityAuto-check passed

More from tinyfish-io/tinyfish-cookbook

All 28 skills in this repo
  • Tinyfish Social Listening

    tinyfish-io/tinyfish-cookbook

    Monitor brand mentions, sentiment, and industry chatter across the web using TinyFish Search and Fetch.

    2.2k GitHub stars~5.4k tokensUpdated 6 days ago
    Auto-check passed
  • Academic Research Mapper

    tinyfish-io/tinyfish-cookbook

    Map the research landscape for any technical or academic topic by searching arXiv, Semantic Scholar, and Google Scholar in parallel.

    2.2k GitHub stars~3.5k tokensUpdated 6 days ago
    Auto-check passed
  • Agent

    tinyfish-io/tinyfish-cookbook

    Default browser automation agent — click, fill forms, navigate, log in, and extract structured data from any website using a natural-language goal, or run the same task across multiple sites in…

    2.2k GitHub stars~1.1k tokensUpdated 6 days ago
    Auto-check passed
  • Company Hiring Intelligence

    tinyfish-io/tinyfish-cookbook

    Reverse-engineer what a company is building by scraping their job postings, careers page, LinkedIn Jobs, and engineering blog using TinyFish web agents.

    2.2k GitHub stars~3.6k tokensUpdated 6 days ago
    Auto-check passed
  • Competitor Product Monitor

    tinyfish-io/tinyfish-cookbook

    Monitor competitor product releases and new feature announcements.

    2.2k GitHub stars~1.7k tokensUpdated 6 days ago
    Auto-check passed
  • Dev Pain Finder

    tinyfish-io/tinyfish-cookbook

    Scrape real developer pain points for any keyword, technology, or problem space from Reddit, Hacker News, dev.to, and GitHub Discussions simultaneously — then group complaints by theme, score them…

    2.2k GitHub stars~2.6k tokensUpdated 6 days ago
    Auto-check passed

Works with

Categories

Questions about Dep Security

What does Dep Security do?

Check every dependency in a package.json against live CVE databases and security advisories in real time — specifically targeting vulnerabilities disclosed in the last 48 hours, the window that…. Dep Security is an agent skill from tinyfish-io/tinyfish-cookbook.json against live CVE databases and security advisories in real time — specifically targeting vulnerabilities disclosed in the last 48 hours, the window that Snyk, Dependabot, and npm audit miss.

When should I use Dep Security?

Dep Security fits situations like: A user mentions checking dependencies for vulnerabilities; wants to audit their package.json; asks about CVEs for their packages; says are my dependencies safe.

How do I install Dep Security in Claude Code?

Run `npx skills add tinyfish-io/tinyfish-cookbook --skill dep-security -a claude-code`. Or copy the skill folder (skills/dep-security in tinyfish-io/tinyfish-cookbook) into .claude/skills/dep-security in your project. Claude Code loads it when a task matches its description.

How do I install Dep Security in Codex?

Run `npx skills add tinyfish-io/tinyfish-cookbook --skill dep-security -a codex`. Or copy the skill folder (skills/dep-security in tinyfish-io/tinyfish-cookbook) into .agents/skills/dep-security in your project. Codex loads it when a task matches its description.

Can I use Dep Security in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add tinyfish-io/tinyfish-cookbook --skill dep-security -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/dep-security, .gemini/skills/dep-security, .github/skills/dep-security and .opencode/skills/dep-security in your project.

What does Dep Security need to run?

Going by SKILL.md and its folder, Dep Security needs the command-line tools its instructions call (npm). Our summary lists: Node.js. Compatibility (from SKILL.md): {"tools":["tinyfish"]}.

Does Dep Security access the network?

SKILL.md names 4 domains. In commands or code: cve.mitre.org, github.com, npmjs.com and nvd.nist.gov; the agent is likely to contact these when it follows the instructions. This is read from the text; nothing was executed.

Is Dep Security safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Dep Security use?

Dep Security is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Dep Security use?

About 2.4k tokens (SKILL.md is roughly 9.6k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Dep Security?

Skills that share tags, products or a category with Dep Security: Fix Security PR (unional/typescript-blackbook, 133 stars), npm Supply Chain Check (majiayu000/spellbook, 286 stars), Security Scan (bagofwords1/bagofwords, 458 stars) and Cve Scan (softspark/ai-toolkit, 179 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Dep Security?

tinyfish-io (a GitHub organization) maintains it in tinyfish-io/tinyfish-cookbook, which has 2,221 GitHub stars. The repository holds 28 skills in this directory. The repository was last updated on October 1, 2026.

Source: tinyfish-io/tinyfish-cookbook on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.