Skip to content
Back to skills

Dependency Audit

ASecurity

Run npm/pip/etc audit, triage advisories, and apply the safest upgrades

  • 3 stars
  • 0 votes
  • 0 copies
  • 3 views
  • Added September 3, 2026
ai-agentsgosecurity

Security analysis

A100/100

Scanned September 3, 2026

npx -y skills add black141312/ada --skill dependency-audit --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Dependency Audit?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Dependency Audit
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/black141312-dependency-audit/badge)](https://www.skillsdirectory.com/skills/black141312-dependency-audit)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: dependency-audit
description: Run npm/pip/etc audit, triage advisories, and apply the safest upgrades
category: security
---

# Dependency Audit

Use this to find and triage known-vulnerable third-party packages in a project's dependency tree.

1. Run the ecosystem auditor: `npm audit --json`, `pip-audit`, `pnpm audit`, `cargo audit`, or `osv-scanner -r .`; capture the raw output.
2. For each advisory note severity, whether it is a direct or transitive dependency, and if a fixed version exists.
3. Confirm reachability: check whether the vulnerable code path is actually called by this project — a CVE in an unused code path is lower priority.
4. Fix direct deps by bumping to the patched version; for transitive ones use overrides/resolutions (`overrides` in package.json, constraints file for pip) or upgrade the parent.
5. Re-run the auditor and the test suite to confirm the advisory clears and nothing broke.
6. Record any advisory you intentionally accept (no fix available, not reachable) with a dated justification.

## Rules
- Prioritize by severity AND reachability/exploitability, not by raw count of advisories.
- Pin to the minimal version that fixes the issue; avoid sweeping major-version bumps in the same change.
- Lockfiles must be regenerated and committed so the fix is reproducible.
- Beware audit noise: dev-only/build-time deps rarely warrant a risky upgrade — judge by where the package runs.
- Add the audit to CI (failing on high/critical) so regressions are caught automatically.

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…