Agent skill

Dep Updates

by trufflesecurity in trufflesecurity/trufflehog

Plan and apply Go dependency updates, including advisory-driven bumps, Trivy/govulncheck validation, and supply-chain review.

AGPL-3.0Auto-check passedDevelopment

Install Dep Updates

skills CLI
$ npx skills add trufflesecurity/trufflehog --skill dep-updates -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install trufflesecurity/trufflehog dep-updates --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/trufflesecurity/trufflehog.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.cursor/skills/dep-updates .claude/skills/dep-updates && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
dep-updates
GitHub stars
28k
Token cost
~1.3k tokens
SKILL.md length
660 words
Files
1
Skills in repo
1
Repo updated
First seen
Licence
AGPL-3.0

At a glance

Plan and apply Go dependency updates, including advisory-driven bumps, Trivy/govulncheck validation, and supply-chain review.

  • Works in 4 steps: Run Trivy from the project root as a… → Optionally supplement with Go’s official… → Use gh against the upstream repo when… → …
  • The user asks to update dependencies
  • SKILL.md covers Quick Start, Triage notes, Go workflow and Validation, plus 1 more section
  • Calls go, make and docker

What it does

Dep Updates is an agent skill from trufflesecurity/trufflehog. Plan and apply Go dependency updates, including advisory-driven bumps, Trivy/govulncheck validation, and supply-chain review. Use when the user asks to update dependencies, refresh modules for security alerts, or run dependency vulnerability scans.

Its SKILL.md is about 1.3k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Development, covering Dependency management, Supply chain security and Secrets management. It works with Trivy. The repository describes itself as: Find, verify, and analyze leaked credentials. The licence is AGPL-3.0.

When your agent uses it

  • The user asks to update dependencies
  • Refresh modules for security alerts
  • Run dependency vulnerability scans

Example prompts

  • “/dep-updates”

Requirements

  • Docker

Workflow steps

4 steps, taken from the first numbered list in SKILL.md.

  1. Run Trivy from the project root as a container, not a locally installed binary
  2. Optionally supplement with Go’s official checker (reports module vulnerabilities from the Go vulnerability database)
  3. Use gh against the upstream repo when helpful, for example Dependabot security alerts
  4. Triage each finding as

What it can do on your machine

Read from SKILL.md and the folder at commit 0e42739. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • go
    • make
    • docker
    • gh

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use docker and gh, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Dep Updates loads about 1.3k tokens when it runs. Until then it costs about 65 tokens; SKILL.md has 660 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~65
When it runs · the whole SKILL.md, loaded when a task matches
~1.3k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from trufflesecurity/trufflehog at commit 0e42739, republished under its AGPL-3.0 licence (© trufflesecurity). 660 words, ~1,290 tokens.

Download SKILL.mdSave it as .claude/skills/dep-updates/SKILL.md (or your agent's skills folder).
name
dep-updates
description
Plan and apply Go dependency updates, including advisory-driven bumps, Trivy/govulncheck validation, and supply-chain review. Use when the user asks to update dependencies, refresh modules for security alerts, or run dependency vulnerability scans.

Dependency updates

Use this skill when the user wants to update dependencies in this repo—whether driven by security advisories, Dependabot, or general maintenance.

This repository is primarily Go (go.mod / go.sum). There is no root Node workspace; follow the Go workflow below.

Project convention: Do not create or maintain docs/vuln-residual-risk.md (or similar residual-risk documents) unless the user explicitly asks. Summarize anything still open in the PR description or chat instead.

Quick Start

  1. Run Trivy from the project root as a container, not a locally installed binary:
bash
docker run --rm -v "$PWD:/src" -w /src aquasec/trivy@sha256:bcc376de8d77cfe086a917230e818dc9f8528e3c852f7b1aff648949b6258d1c fs --scanners vuln .
  1. Optionally supplement with Go’s official checker (reports module vulnerabilities from the Go vulnerability database):
bash
go install golang.org/x/vuln/cmd/govulncheck@latest
govulncheck ./...
  1. Use gh against the upstream repo when helpful, for example Dependabot security alerts:
bash
gh api repos/trufflesecurity/trufflehog/dependabot/alerts --paginate
  1. Triage each finding as:
  • Actionable: a fixed version exists and the current constraint allows, or can be relaxed to allow, the update.
  • Blocked: a fix exists, but taking it would require a major-version bump in a sibling dependency or a broader refactor the user did not ask for.
  • No fix available: upstream has not published a patched release.
  1. Apply module updates, rerun the scans, and note remaining gaps in the PR or response (not in a standing residual-risk doc).

Triage notes

  • For Dependabot or advisory-driven work, note the affected module, vulnerable version range, fixed version, and exploit conditions called out in the advisory.
  • Check whether this repo is actually affected: look for imports, direct usage of the vulnerable APIs or code paths, and any required configuration, input shape, or runtime exposure described in the alert.
  • Verify that any advisory-listed "fixed version" actually exists upstream before planning around it; scanners can report versions that are not yet published.
  • For each incoming dependency update, spawn a sub-agent to inspect the new version for malicious or suspicious supply-chain changes before you adopt it.
  • Have the sub-agent review release notes and the module diff for typosquat signals, maintainer churn, unexpected build tags or generated code, obfuscated code, unexpected network or process behavior, credential or filesystem access, and unexplained new transitive dependencies.
  • Use sub-agents for per-package advisory and diff review, but keep go.mod / go.sum edits in a single coordinating agent.
  • Even if the alert appears non-exploitable here, still take the patch when the upgrade is reasonable and low risk.
  • If something cannot be upgraded yet, explain why in the PR or chat (upstream tag missing, incompatible API, etc.); do not create standing residual-risk documentation files unless the user asks.
Show full SKILL.md (259 more words)Show less

Go workflow

Use this path for findings in go.mod or go.sum.

  • Prefer targeted upgrades: go get example.com/module@vX.Y.Z (or a compatible minor/patch as appropriate).
  • After changes, run go mod tidy from the project root.
  • Never edit go.sum manually; it is generated.
  • Run make lint (or ./scripts/lint.sh) to match CI’s golangci-lint configuration.
  • Run tests appropriate to what changed. Broad checks often use:
    • make test for the default unit test sweep, or
    • go test -timeout 30s -tags "integration detectors" ./... when exercising integration and detector-tagged packages (narrow the path when only specific packages changed).
  • Use make test-integration or make test-detectors when the change touches integration-only or detector code paths.

Validation

After making updates:

  1. Re-run the same Trivy container command from the project root and confirm the vulnerability count decreased or the actionable findings were removed.
  2. Re-run govulncheck ./... if you use it in this pass.
  3. Run make lint and the relevant go test / make test* targets for the areas you touched.

Execution notes

  • Do not install Trivy locally as part of this workflow; use the containerized command.
  • Never edit go.sum manually; regenerate with go mod tidy after go get / go mod changes.
  • Do not create commits unless the user explicitly asks for them.
  • Use sub-agents wherever practical for read-only research and independent validation; keep go.mod and go.sum edits under one coordinating agent.
  • Include the analysis in the PR description: what the alert or upgrade was, how you checked impact, what the supply-chain review found, and what you changed.
  • Follow nearby project conventions and add tests when dependency updates require behavioral changes.

© trufflesecurity, AGPL-3.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .cursor/skills/dep-updates of trufflesecurity/trufflehog.

Open the folder on GitHubat commit 0e42739

Compare with similar skills

Dep Updates next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Dep Updates compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Dep Updates this skilltrufflesecurity/trufflehog28k—~1.3kAutomated safety check: PassAGPL-3.0
Performing Container Security Scanning With Trivymukul975/Anthropic-Cybersecurity-Skills34k—~818Automated safety check: PassApache-2.0
Vulnerability Scanningsecondsky/claude-skills227—~799Automated safety check: PassMIT
Security Vulnerabilities Patcheraxelixlabs/axelix148—~4.2kAutomated safety check: PassLGPL-3.0
npm Supply Chain Checkmajiayu000/spellbook287—~1.5kAutomated safety check: PassMIT
Secleak Checkinstructa/agent-skills139—~557Automated safety check: PassNone

Similar skills

  • Performing Container Security Scanning With Trivy

    mukul975/Anthropic-Cybersecurity-Skills

    Runs Trivy across every target type it supports - container images, filesystems, Git repositories, and Kubernetes clusters - for OS and dependency vulnerabilities, IaC misconfiguration, exposed…

    34k GitHub stars~818 tokensUpdated 1 mo ago
    DevOps & CloudAuto-check passed
  • Vulnerability Scanning

    secondsky/claude-skills

    Automated security scanning for dependencies, code, containers with Trivy, Snyk, npm audit.

    227 GitHub stars~799 tokensUpdated 11 days ago
    SecurityAuto-check passed
  • Create batched Dependabot-style pull requests for GitHub security findings in axelixlabs/axelix, grouped by dependency surface such as master/front-end, master/build.gradle.kts, or starter Gradle…

    148 GitHub stars~4.2k tokensUpdated today
    SecurityAuto-check passed
  • npm Supply Chain Check

    majiayu000/spellbook

    Scans a repository, its lockfiles and node_modules for known malicious npm package versions and install-time indicators, using a read-only Python scanner.

    287 GitHub stars~1.5k tokensUpdated today
    SecurityAuto-check passed
  • Secleak Check

    instructa/agent-skills

    Run or install repo security leak checks with BetterLeaks and Trivy.

    139 GitHub stars~557 tokensUpdated 10 days ago
    AI & LLM EngineeringAuto-check passed
  • Security Reviewer

    Jeffallan/claude-skills

    Audits code and infrastructure for vulnerabilities and produces a severity-rated report with locations and remediation, using SAST, dependency and secrets scans plus manual review.

    12k GitHub stars~1.3k tokensUpdated 5 days ago
    SecurityAuto-check passed

Works with

Categories

Questions about Dep Updates

What does Dep Updates do?

Plan and apply Go dependency updates, including advisory-driven bumps, Trivy/govulncheck validation, and supply-chain review. Dep Updates is an agent skill from trufflesecurity/trufflehog. Plan and apply Go dependency updates, including advisory-driven bumps, Trivy/govulncheck validation, and supply-chain review.

When should I use Dep Updates?

Dep Updates fits situations like: the user asks to update dependencies; refresh modules for security alerts; run dependency vulnerability scans.

How do I install Dep Updates in Claude Code?

Run `npx skills add trufflesecurity/trufflehog --skill dep-updates -a claude-code`. Or copy the skill folder (.cursor/skills/dep-updates in trufflesecurity/trufflehog) into .claude/skills/dep-updates in your project. Claude Code loads it when a task matches its description.

How do I install Dep Updates in Codex?

Run `npx skills add trufflesecurity/trufflehog --skill dep-updates -a codex`. Or copy the skill folder (.cursor/skills/dep-updates in trufflesecurity/trufflehog) into .agents/skills/dep-updates in your project. Codex loads it when a task matches its description.

Can I use Dep Updates in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add trufflesecurity/trufflehog --skill dep-updates -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/dep-updates, .gemini/skills/dep-updates, .github/skills/dep-updates and .opencode/skills/dep-updates in your project.

What does Dep Updates need to run?

Going by SKILL.md and its folder, Dep Updates needs the command-line tools its instructions call (go, make, docker and gh). Our summary lists: Docker.

Does Dep Updates access the network?

SKILL.md contains no URLs. Its commands use docker and gh, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Dep Updates safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Dep Updates use?

Dep Updates is published under the AGPL-3.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Dep Updates use?

About 1.3k tokens (SKILL.md is roughly 5.2k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Dep Updates?

Skills that share tags, products or a category with Dep Updates: Performing Container Security Scanning With Trivy (mukul975/Anthropic-Cybersecurity-Skills, 34k stars), Vulnerability Scanning (secondsky/claude-skills, 227 stars), Security Vulnerabilities Patcher (axelixlabs/axelix, 148 stars) and npm Supply Chain Check (majiayu000/spellbook, 287 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Dep Updates?

trufflesecurity (a GitHub organization) maintains it in trufflesecurity/trufflehog, which has 28,375 GitHub stars. The repository was last updated on October 8, 2026.

Source: trufflesecurity/trufflehog on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.