Skip to content
Back to skills

Audit And Fix

BSecurity

'I''ll perform a comprehensive security audit and automatically fix vulnerabilities

  • 18 stars
  • 0 votes
  • 0 copies
  • 1 view
  • Added September 4, 2026
securitytypescriptgobashreactexpresstestingdebugginggitsecurityperformance

Security analysis

B84/100
  • criticalSends environment variables or credentials to an external URL
  • mediumInstalls packages at runtime which could introduce malicious dependencies

Pro shows the line behind each finding and how to fix it

Scanned September 4, 2026

npx -y skills add majiayu000/claude-skill-registry-data --skill audit-and-fix --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Audit And Fix?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Audit And Fix
[![Security: B โ€” Skills Directory](https://www.skillsdirectory.com/api/skills/majiayu000-audit-and-fix-claude-skill-registry-data/badge)](https://www.skillsdirectory.com/skills/majiayu000-audit-and-fix-claude-skill-registry-data)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: audit-and-fix
description: 'I''ll perform a comprehensive security audit and automatically fix vulnerabilities
  for: $ARGUMENTS'
---

---
skill: audit-and-fix
description: Security audit with automatic fixes: $ARGUMENTS (package names or '.')
location: project
---

# Security Audit and Fix: $ARGUMENTS

I'll perform a comprehensive security audit and automatically fix vulnerabilities for: **$ARGUMENTS**

This advanced workflow includes:
1. Creating an isolated git worktree for safety
2. Running `npm audit` to identify all vulnerabilities
3. Categorizing vulnerabilities by severity (critical, high, moderate, low)
4. Automatically updating vulnerable packages
5. Using parallel agents for efficient processing (when >3 packages)
6. Validating each update with full test suite
7. Generating comprehensive security report
8. Prompting for merge if all validations pass

This is a complex skill demonstrating parallel execution, conditional logic, and comprehensive error handling.

Let's begin!

---

## Process Steps

### 1. Create Isolated Git Worktree

Create an isolated environment for safe dependency updates:

```bash
# Generate unique timestamp
TIMESTAMP=$(date +%Y%m%d-%H%M%S)
WORKTREE_PATH="../audit-fix-worktree-$TIMESTAMP"
BRANCH_NAME="security-audit-$TIMESTAMP"

echo "๐Ÿ”’ Creating isolated worktree for security audit"
echo "๐Ÿ“ Worktree path: $WORKTREE_PATH"
echo "๐ŸŒฟ Branch name: $BRANCH_NAME"
echo ""

# Create worktree
git worktree add "$WORKTREE_PATH" -b "$BRANCH_NAME"

# Navigate into worktree
cd "$WORKTREE_PATH/expense-tracker-ai"

echo "โœ… Worktree created and ready"
echo "๐Ÿ“ Working in: $(pwd)"
echo ""
```

**Why isolated worktree is critical:**
- Package updates can break the application
- Dependencies may have incompatibilities
- Tests may fail after updates
- Need ability to discard if updates fail
- Main workspace remains functional during audit

### 2. Run Initial Security Audit

Scan for vulnerabilities using npm audit:

```bash
echo "๐Ÿ” Running security audit..."
echo ""

# Run npm audit and save results
npm audit --json > audit-report.json 2>&1

# Check if audit found any issues
AUDIT_EXIT_CODE=$?

if [ $AUDIT_EXIT_CODE -eq 0 ]; then
  echo "โœ… No vulnerabilities found!"
  echo ""
  echo "Your dependencies are secure."
  echo "No updates needed."

  # Clean up worktree
  cd /Users/greg/code/claude-code-coursera
  git worktree remove "$WORKTREE_PATH"
  git branch -d "$BRANCH_NAME"

  exit 0
fi

echo "โš ๏ธ  Vulnerabilities detected. Analyzing..."
echo ""
```

### 3. Categorize Vulnerabilities by Severity

Parse audit results and categorize by severity:

```bash
echo "๐Ÿ“Š Vulnerability Analysis"
echo "โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”"

# Extract vulnerability counts by severity
if command -v jq >/dev/null 2>&1; then
  # Use jq if available
  CRITICAL=$(jq -r '.metadata.vulnerabilities.critical // 0' audit-report.json)
  HIGH=$(jq -r '.metadata.vulnerabilities.high // 0' audit-report.json)
  MODERATE=$(jq -r '.metadata.vulnerabilities.moderate // 0' audit-report.json)
  LOW=$(jq -r '.metadata.vulnerabilities.low // 0' audit-report.json)
  INFO=$(jq -r '.metadata.vulnerabilities.info // 0' audit-report.json)
else
  # Fallback: parse npm audit output directly
  npm audit | grep -E "Critical|High|Moderate|Low|Info" | while read -r line; do
    case "$line" in
      *Critical*) echo "$line" | awk '{print $2}' > /tmp/critical_count ;;
      *High*) echo "$line" | awk '{print $2}' > /tmp/high_count ;;
      *Moderate*) echo "$line" | awk '{print $2}' > /tmp/moderate_count ;;
      *Low*) echo "$line" | awk '{print $2}' > /tmp/low_count ;;
    esac
  done

  CRITICAL=$(cat /tmp/critical_count 2>/dev/null || echo 0)
  HIGH=$(cat /tmp/high_count 2>/dev/null || echo 0)
  MODERATE=$(cat /tmp/moderate_count 2>/dev/null || echo 0)
  LOW=$(cat /tmp/low_count 2>/dev/null || echo 0)
fi

TOTAL=$((CRITICAL + HIGH + MODERATE + LOW))

echo "๐Ÿ”ด Critical: $CRITICAL"
echo "๐ŸŸ  High: $HIGH"
echo "๐ŸŸก Moderate: $MODERATE"
echo "๐ŸŸข Low: $LOW"
echo "โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”"
echo "๐Ÿ“‹ Total vulnerabilities: $TOTAL"
echo ""
```

**Severity definitions:**
- **Critical**: Immediate action required, actively exploited
- **High**: Serious security risk, patch ASAP
- **Moderate**: Security concern, should fix soon
- **Low**: Minor issue, fix when convenient
- **Info**: Informational, no immediate action needed

### 4. Identify Vulnerable Packages

Extract the list of packages that need updating:

```bash
echo "๐Ÿ“ฆ Identifying vulnerable packages..."
echo ""

# Get list of vulnerable packages
if command -v jq >/dev/null 2>&1; then
  # Extract unique package names from audit report
  VULNERABLE_PACKAGES=$(jq -r '.vulnerabilities | keys[]' audit-report.json 2>/dev/null || echo "")
else
  # Fallback: parse npm audit output
  VULNERABLE_PACKAGES=$(npm audit | grep -E "^[a-z]" | awk '{print $1}' | sort -u)
fi

if [ -z "$VULNERABLE_PACKAGES" ]; then
  echo "โŒ Could not parse vulnerable packages"
  echo "Running npm audit fix instead..."

  npm audit fix

  if [ $? -eq 0 ]; then
    echo "โœ… npm audit fix completed"
  else
    echo "โŒ npm audit fix failed"
    echo "Manual intervention required"
  fi

  exit 0
fi

# Count packages
PACKAGE_COUNT=$(echo "$VULNERABLE_PACKAGES" | wc -l | tr -d ' ')

echo "Found $PACKAGE_COUNT vulnerable packages:"
echo "$VULNERABLE_PACKAGES" | while read -r pkg; do
  echo "  โ€ข $pkg"
done
echo ""
```

### 5. Determine Execution Strategy

Based on the number of packages, choose sequential or parallel execution:

```bash
echo "๐ŸŽฏ Determining execution strategy..."
echo ""

if [ "$ARGUMENTS" = "." ] || [ "$ARGUMENTS" = "all" ]; then
  # Process all vulnerable packages
  PACKAGES_TO_UPDATE="$VULNERABLE_PACKAGES"
  UPDATE_MODE="all"
elif echo "$ARGUMENTS" | grep -q '\*'; then
  # Glob pattern matching
  PACKAGES_TO_UPDATE=$(echo "$VULNERABLE_PACKAGES" | grep "$ARGUMENTS")
  UPDATE_MODE="pattern"
else
  # Specific packages
  PACKAGES_TO_UPDATE="$ARGUMENTS"
  UPDATE_MODE="specific"
fi

UPDATE_COUNT=$(echo "$PACKAGES_TO_UPDATE" | wc -l | tr -d ' ')

echo "Update mode: $UPDATE_MODE"
echo "Packages to update: $UPDATE_COUNT"
echo ""

# Choose execution strategy
if [ $UPDATE_COUNT -gt 3 ]; then
  echo "๐Ÿ“Š Multiple packages detected ($UPDATE_COUNT packages)"
  echo "๐Ÿš€ Using parallel execution for efficiency"
  echo ""
  echo "Strategy:"
  echo "  โ€ข Split into groups of 2 packages per agent"
  echo "  โ€ข Launch parallel Task agents"
  echo "  โ€ข Each agent updates and validates independently"
  echo "  โ€ข Collect and merge results"
  echo ""
  EXECUTION_MODE="parallel"
else
  echo "๐Ÿ“ Processing $UPDATE_COUNT packages sequentially"
  echo ""
  EXECUTION_MODE="sequential"
fi
```

**Execution strategies:**
- **1-3 packages**: Sequential (simpler, easier to debug)
- **4+ packages**: Parallel (faster, more efficient)

### 6. Execute Updates (Sequential Mode)

For โ‰ค3 packages, update one by one:

```bash
if [ "$EXECUTION_MODE" = "sequential" ]; then
  echo "โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”"
  echo "Starting sequential updates..."
  echo "โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”"
  echo ""

  SUCCESS_COUNT=0
  FAILURE_COUNT=0
  FAILED_PACKAGES=""

  echo "$PACKAGES_TO_UPDATE" | while read -r package; do
    if [ -z "$package" ]; then
      continue
    fi

    echo "๐Ÿ“ฆ Updating: $package"
    echo "โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”"

    # Get current version
    CURRENT_VERSION=$(npm list "$package" --depth=0 2>/dev/null | grep "$package" | awk -F@ '{print $NF}')
    echo "Current version: $CURRENT_VERSION"

    # Update package
    npm install "$package@latest" --save

    if [ $? -ne 0 ]; then
      echo "โŒ Failed to install $package@latest"
      FAILURE_COUNT=$((FAILURE_COUNT + 1))
      FAILED_PACKAGES="$FAILED_PACKAGES\n  โ€ข $package"
      continue
    fi

    # Get new version
    NEW_VERSION=$(npm list "$package" --depth=0 2>/dev/null | grep "$package" | awk -F@ '{print $NF}')
    echo "New version: $NEW_VERSION"

    # Validate the update
    echo ""
    echo "Running validation..."

    # Build
    echo "  1/4 Build..."
    npm run build >/dev/null 2>&1
    if [ $? -ne 0 ]; then
      echo "  โŒ Build failed after updating $package"
      FAILURE_COUNT=$((FAILURE_COUNT + 1))
      FAILED_PACKAGES="$FAILED_PACKAGES\n  โ€ข $package (build failed)"
      # Revert
      npm install "$package@$CURRENT_VERSION" --save
      continue
    fi
    echo "  โœ… Build passed"

    # Lint
    echo "  2/4 Lint..."
    npm run lint >/dev/null 2>&1
    if [ $? -ne 0 ]; then
      echo "  โŒ Lint failed after updating $package"
      FAILURE_COUNT=$((FAILURE_COUNT + 1))
      FAILED_PACKAGES="$FAILED_PACKAGES\n  โ€ข $package (lint failed)"
      npm install "$package@$CURRENT_VERSION" --save
      continue
    fi
    echo "  โœ… Lint passed"

    # Unit tests
    echo "  3/4 Unit tests..."
    npm test >/dev/null 2>&1
    if [ $? -ne 0 ]; then
      echo "  โŒ Tests failed after updating $package"
      FAILURE_COUNT=$((FAILURE_COUNT + 1))
      FAILED_PACKAGES="$FAILED_PACKAGES\n  โ€ข $package (tests failed)"
      npm install "$package@$CURRENT_VERSION" --save
      continue
    fi
    echo "  โœ… Tests passed"

    # E2E tests
    echo "  4/4 E2E tests..."
    npm run test:e2e >/dev/null 2>&1
    if [ $? -ne 0 ]; then
      echo "  โŒ E2E tests failed after updating $package"
      FAILURE_COUNT=$((FAILURE_COUNT + 1))
      FAILED_PACKAGES="$FAILED_PACKAGES\n  โ€ข $package (e2e failed)"
      npm install "$package@$CURRENT_VERSION" --save
      continue
    fi
    echo "  โœ… E2E tests passed"

    echo ""
    echo "โœ… Successfully updated: $package ($CURRENT_VERSION โ†’ $NEW_VERSION)"
    echo ""
    SUCCESS_COUNT=$((SUCCESS_COUNT + 1))
  done

  echo "โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”"
  echo "Sequential Update Summary"
  echo "โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”"
  echo "โœ… Successful: $SUCCESS_COUNT"
  echo "โŒ Failed: $FAILURE_COUNT"

  if [ $FAILURE_COUNT -gt 0 ]; then
    echo ""
    echo "Failed packages:"
    echo -e "$FAILED_PACKAGES"
  fi
  echo ""
fi
```

### 7. Execute Updates (Parallel Mode)

For >3 packages, use parallel agents:

```bash
if [ "$EXECUTION_MODE" = "parallel" ]; then
  echo "โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”"
  echo "Starting parallel updates..."
  echo "โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”"
  echo ""

  # Split packages into groups
  # Group size: 2 packages per agent
  GROUP_SIZE=2

  # Calculate number of groups needed
  NUM_GROUPS=$(( (UPDATE_COUNT + GROUP_SIZE - 1) / GROUP_SIZE ))

  echo "Parallel execution plan:"
  echo "  โ€ข Total packages: $UPDATE_COUNT"
  echo "  โ€ข Packages per agent: $GROUP_SIZE"
  echo "  โ€ข Number of agents: $NUM_GROUPS"
  echo ""

  # Claude will use Task tool with general-purpose subagents
  # Each subagent will receive a subset of packages to update
  #
  # Conceptual breakdown:
  # - Agent 1: packages 1-2
  # - Agent 2: packages 3-4
  # - Agent 3: packages 5-6
  # ...
  #
  # Each agent independently:
  # 1. Updates its assigned packages
  # 2. Runs full validation suite for each
  # 3. Reports success/failure
  # 4. Reverts on failure
  #
  # Main process waits for all agents to complete,
  # then collects and merges results

  echo "โณ Launching parallel agents..."
  echo ""

  # The actual Task tool usage will be handled by Claude
  # This is a placeholder showing the conceptual approach
  #
  # For each group:
  #   Task({
  #     subagent_type: 'general-purpose',
  #     description: `Update packages: ${group.join(', ')}`,
  #     prompt: `Update these packages with full validation: ${packages}
  #              For each package:
  #              1. npm install package@latest
  #              2. Run build, lint, test, e2e
  #              3. Revert if any validation fails
  #              4. Report results`,
  #     run_in_background: true
  #   })
  #
  # Wait for all agents
  # Collect results
  # Generate summary

  echo "โœ… All agents completed"
  echo ""
fi
```

**Parallel execution benefits:**
- **Speed**: 3-5x faster for large updates
- **Resource utilization**: Better use of available CPU
- **Scalability**: Handles dozens of packages efficiently

**Parallel execution challenges:**
- **Complexity**: More moving parts
- **Debugging**: Harder to trace failures
- **Coordination**: Need to merge results
- **Rate limits**: May hit npm registry limits

### 8. Run Post-Update Security Audit

After updates, verify vulnerabilities are fixed:

```bash
echo "โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”"
echo "Running post-update security audit..."
echo "โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”"
echo ""

npm audit --json > audit-report-after.json 2>&1
AUDIT_EXIT_CODE=$?

if [ $AUDIT_EXIT_CODE -eq 0 ]; then
  echo "โœ… No vulnerabilities remaining!"
  echo ""
  REMAINING_VULNS=0
else
  # Count remaining vulnerabilities
  if command -v jq >/dev/null 2>&1; then
    CRITICAL_AFTER=$(jq -r '.metadata.vulnerabilities.critical // 0' audit-report-after.json)
    HIGH_AFTER=$(jq -r '.metadata.vulnerabilities.high // 0' audit-report-after.json)
    MODERATE_AFTER=$(jq -r '.metadata.vulnerabilities.moderate // 0' audit-report-after.json)
    LOW_AFTER=$(jq -r '.metadata.vulnerabilities.low // 0' audit-report-after.json)
  else
    CRITICAL_AFTER=0
    HIGH_AFTER=0
    MODERATE_AFTER=0
    LOW_AFTER=0
  fi

  REMAINING_VULNS=$((CRITICAL_AFTER + HIGH_AFTER + MODERATE_AFTER + LOW_AFTER))

  echo "โš ๏ธ  Remaining vulnerabilities: $REMAINING_VULNS"
  echo ""
  echo "๐Ÿ”ด Critical: $CRITICAL_AFTER (was: $CRITICAL)"
  echo "๐ŸŸ  High: $HIGH_AFTER (was: $HIGH)"
  echo "๐ŸŸก Moderate: $MODERATE_AFTER (was: $MODERATE)"
  echo "๐ŸŸข Low: $LOW_AFTER (was: $LOW)"
  echo ""
fi

# Calculate fixed count
FIXED_COUNT=$((TOTAL - REMAINING_VULNS))

echo "๐Ÿ“Š Fix Summary:"
echo "  โ€ข Vulnerabilities fixed: $FIXED_COUNT"
echo "  โ€ข Vulnerabilities remaining: $REMAINING_VULNS"
echo ""
```

### 9. Generate Comprehensive Security Report

Create detailed report with all findings:

```
โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”
๐Ÿ”’ SECURITY AUDIT REPORT
โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”

๐Ÿ“… Date: $(date '+%Y-%m-%d %H:%M:%S')
๐Ÿ“ Worktree: $WORKTREE_PATH
๐ŸŒฟ Branch: $BRANCH_NAME

โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”
๐Ÿ“Š VULNERABILITY SUMMARY
โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”

Initial Scan:
  ๐Ÿ”ด Critical: $CRITICAL
  ๐ŸŸ  High: $HIGH
  ๐ŸŸก Moderate: $MODERATE
  ๐ŸŸข Low: $LOW
  โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”
  ๐Ÿ“‹ Total: $TOTAL

After Updates:
  ๐Ÿ”ด Critical: $CRITICAL_AFTER
  ๐ŸŸ  High: $HIGH_AFTER
  ๐ŸŸก Moderate: $MODERATE_AFTER
  ๐ŸŸข Low: $LOW_AFTER
  โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”
  ๐Ÿ“‹ Total: $REMAINING_VULNS

Result:
  โœ… Fixed: $FIXED_COUNT vulnerabilities
  โš ๏ธ  Remaining: $REMAINING_VULNS vulnerabilities

โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”
๐Ÿ“ฆ PACKAGE UPDATES
โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”

Successful Updates ($SUCCESS_COUNT):
  [List each successful package update]
  โ€ข webpack: 5.88.0 โ†’ 5.89.0 (fixed CVE-2023-XXXX)
  โ€ข react-dom: 18.2.0 โ†’ 18.3.1 (fixed CVE-2023-YYYY)
  โ€ข express: 4.18.0 โ†’ 4.19.2 (fixed CVE-2024-ZZZZ)

Failed Updates ($FAILURE_COUNT):
  [List each failed package with reason]
  โ€ข typescript: 5.1.0 โ†’ 5.3.0 (build errors)
  โ€ข jest: 29.5.0 โ†’ 30.0.0 (breaking changes)

โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”
โœ… VALIDATION RESULTS
โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”

Build:       โœ“ Passed
Lint:        โœ“ Passed
Unit Tests:  โœ“ Passed (24/24)
E2E Tests:   โœ“ Passed (12/12)

โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”
๐Ÿ’ก RECOMMENDATIONS
โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”

[If remaining vulnerabilities]

๐Ÿ”ด Critical Priority:
  โ€ข Review remaining critical vulnerabilities
  โ€ข Consider manual updates for failed packages
  โ€ข Check for security patches or workarounds

๐ŸŸ  High Priority:
  โ€ข Address high severity issues within 7 days
  โ€ข Monitor security advisories

๐ŸŸก Medium Priority:
  โ€ข Plan updates for moderate severity issues
  โ€ข Include in next maintenance cycle

[If all fixed]

โœ… All Clear:
  โ€ข No vulnerabilities detected
  โ€ข All dependencies up to date
  โ€ข Maintain regular audit schedule

โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”
๐Ÿ”ง NEXT STEPS
โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”

[If successful]
  โœ… Review changes in worktree
  โœ… Test application manually
  โœ… Merge to main branch
  โœ… Deploy updated dependencies

[If failures]
  โš ๏ธ  Review failed package updates
  โš ๏ธ  Check breaking change documentation
  โš ๏ธ  Consider manual migration
  โš ๏ธ  Address remaining vulnerabilities

โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”
```

### 10. Prompt for Merge Decision

Ask user whether to merge the updates:

```bash
if [ $SUCCESS_COUNT -gt 0 ] && [ $FAILURE_COUNT -eq 0 ] && [ $REMAINING_VULNS -eq 0 ]; then
  # Perfect case: all updates successful, no remaining vulnerabilities
  echo "โœ… Security audit complete!"
  echo "โœ… All vulnerabilities fixed"
  echo "โœ… All validations passed"
  echo ""
  echo "Merge changes to main branch? (yes/no)"
  echo ""
  echo "Options:"
  echo "  yes - Merge updates and clean up worktree"
  echo "  no  - Keep worktree for manual review"

elif [ $SUCCESS_COUNT -gt 0 ] && [ $REMAINING_VULNS -gt 0 ]; then
  # Partial success: some fixed, some remaining
  echo "โš ๏ธ  Partial success"
  echo "โœ… Fixed: $FIXED_COUNT vulnerabilities"
  echo "โš ๏ธ  Remaining: $REMAINING_VULNS vulnerabilities"
  echo ""
  echo "Merge partial fixes to main branch? (yes/no/review)"
  echo ""
  echo "Options:"
  echo "  yes    - Merge successful updates (progress made)"
  echo "  no     - Discard all changes (address all issues first)"
  echo "  review - Keep worktree for manual inspection"

else
  # Failure: no progress or major issues
  echo "โŒ Security audit completed with issues"
  echo "โŒ Failed updates: $FAILURE_COUNT"
  echo "โš ๏ธ  Remaining vulnerabilities: $REMAINING_VULNS"
  echo ""
  echo "What would you like to do? (keep/cleanup/retry)"
  echo ""
  echo "Options:"
  echo "  keep    - Preserve worktree for debugging"
  echo "  cleanup - Discard changes and remove worktree"
  echo "  retry   - Try npm audit fix --force (may break)"
fi
```

### 11. Handle Merge (If Yes)

If user chooses to merge successful updates:

```bash
echo "Merging security updates to main branch..."
echo ""

# Navigate back to original repo
cd /Users/greg/code/claude-code-coursera

# Show what will be merged
echo "Changes to merge:"
git diff main..$BRANCH_NAME --stat

echo ""
echo "Proceed with merge? (yes/no)"
# Wait for confirmation

# Merge
git merge "$BRANCH_NAME"

if [ $? -ne 0 ]; then
  echo "โŒ Merge conflict detected"
  echo ""
  echo "This is unusual for dependency updates."
  echo "Likely causes:"
  echo "  โ€ข package.json modified in main"
  echo "  โ€ข package-lock.json conflicts"
  echo ""
  echo "Resolve manually:"
  echo "  1. git status"
  echo "  2. Edit conflicting files"
  echo "  3. git add <files>"
  echo "  4. git merge --continue"
  exit 1
fi

echo "โœ… Merge successful"
echo ""

# Offer to push
echo "Push to remote? (yes/no)"
# Wait for response

# Clean up
git worktree remove "$WORKTREE_PATH"
git branch -d "$BRANCH_NAME"

echo ""
echo "โœ… Security updates merged successfully"
echo "โœ… Worktree cleaned up"
echo ""
echo "Don't forget to:"
echo "  โ€ข Test application in production environment"
echo "  โ€ข Monitor for any runtime issues"
echo "  โ€ข Update deployment pipelines if needed"
```

### 12. Handle Manual Review (If No/Review)

If user wants to review manually:

```bash
echo "Worktree preserved for review"
echo ""
echo "โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”"
echo "๐Ÿ“ Worktree Location"
echo "โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”"
echo ""
echo "Path: $WORKTREE_PATH"
echo "Branch: $BRANCH_NAME"
echo ""
echo "โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”"
echo "๐Ÿ” Review Changes"
echo "โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”"
echo ""
echo "Review package updates:"
echo "  cd $WORKTREE_PATH/expense-tracker-ai"
echo "  git diff HEAD package.json"
echo "  git diff HEAD package-lock.json"
echo ""
echo "Test application:"
echo "  npm run dev"
echo "  # Test functionality in browser"
echo ""
echo "Check dependencies:"
echo "  npm list --depth=0"
echo "  npm audit"
echo ""
echo "โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”"
echo "๐Ÿ”„ Merge When Ready"
echo "โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”"
echo ""
echo "Merge to main:"
echo "  cd /Users/greg/code/claude-code-coursera"
echo "  git merge $BRANCH_NAME"
echo "  git push origin main"
echo ""
echo "Clean up:"
echo "  git worktree remove $WORKTREE_PATH"
echo "  git branch -d $BRANCH_NAME"
echo ""
```

---

## Error Handling

### Common Error Scenarios

#### Build Failure After Update

```
โŒ Build failed after updating webpack

Error: Module not found: '@types/webpack'

Resolution:
1. Install missing types: npm install --save-dev @types/webpack
2. Re-run build: npm run build
3. If still failing, check breaking changes in webpack docs
```

#### Dependency Conflict

```
โŒ npm ERR! ERESOLVE unable to resolve dependency tree

Conflict:
  react@18.3.0 requires webpack@^5.90.0
  Current webpack: 5.88.0

Resolution:
1. Update react first: npm install react@latest
2. Then update webpack: npm install webpack@latest
3. Or use --force (may cause issues):
   npm install webpack@latest --force
```

#### Test Failures After Update

```
โŒ Tests failed after updating jest

Error: Unknown option 'testEnvironment'

Cause: Breaking change in jest 30.x

Resolution:
1. Review migration guide:
   https://jestjs.io/docs/upgrading-to-jest30
2. Update jest.config.js
3. Update test files if needed
```

#### No Fix Available

```
โš ๏ธ  Vulnerability in transitive dependency

Package: some-deep-dependency
Severity: High
Fixable: No

Your package โ†’ intermediate-package โ†’ some-deep-dependency

Resolution:
1. Check if intermediate-package has update
2. Contact maintainer of intermediate-package
3. Consider alternative package
4. Monitor for security patch
```

---

## Advanced Usage

### Audit Specific Packages

```bash
# Audit and fix only React-related packages
audit-and-fix react*

# Audit and fix webpack and babel
audit-and-fix webpack babel

# Audit and fix all testing libraries
audit-and-fix @testing-library/*
```

### Audit by Severity

```bash
# Fix only critical vulnerabilities
# (requires custom filtering logic)
audit-and-fix . --severity=critical

# Fix critical and high severity
audit-and-fix . --severity=critical,high
```

### Dry Run Mode

```bash
# Show what would be updated without actually updating
audit-and-fix . --dry-run

# Expected output:
# Would update:
#   โ€ข webpack: 5.88.0 โ†’ 5.89.0
#   โ€ข react-dom: 18.2.0 โ†’ 18.3.1
#   โ€ข express: 4.18.0 โ†’ 4.19.2
```

---

## Performance Metrics

### Sequential vs Parallel Comparison

**Sequential (3 packages):**
- Time: ~15 minutes
- Memory: Low
- Debuggability: Easy

**Parallel (12 packages):**
- Time: ~5 minutes (3x faster)
- Memory: Medium
- Debuggability: Moderate

**Recommendation:**
- Use sequential for โ‰ค3 packages
- Use parallel for 4+ packages
- Consider sequential if debugging issues

---

## Related Skills and Commands

- **Simple Audit:** Use existing [.claude/skills/security-audit.md](.claude/skills/security-audit.md)
- **Package Updates:** Use existing [.claude/commands/npm-latest.md](../commands/npm-latest.md)
- **E2E Testing:** Use existing [.claude/commands/e2e-test.md](../commands/e2e-test.md)
- **Skills Guide:** See [skills.md](../../skills.md) for more patterns

---

## Summary

This skill demonstrates:

โœ… **Complex conditional logic** - Different strategies based on package count
โœ… **Parallel execution** - Using Task tool with subagents for scale
โœ… **Comprehensive validation** - Build, lint, unit tests, e2e tests
โœ… **Error categorization** - Grouping failures by type
โœ… **Rollback on failure** - Reverting packages that break validation
โœ… **Detailed reporting** - Security report with before/after comparison
โœ… **User decision points** - Multiple prompts for user control
โœ… **Cleanup handling** - Proper worktree and branch cleanup

This is the most complex skill example, showcasing advanced patterns for production-grade automation.

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading commentsโ€ฆ