Skip to content
Back to skills

Dependency Audit

ASecurity

Run and triage dependency vulnerability audits across Node.js, Python, Rust, and Go using native tools (npm audit, pip-audit, cargo audit, govulncheck). Use when auditing dependencies for known CVEs or prioritizing remediation.

  • 2 stars
  • 0 votes
  • 0 copies
  • 0 views
  • Added October 1, 2026
ai-agentspythonrustgonodedatabase

Security analysis

A100/100

Pro scans all 3 files and shows the line behind each finding

Scanned October 1, 2026

npx -y skills add matthews-wong/claude-code-plugins --skill dependency-audit --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Dependency Audit?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Dependency Audit
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/matthews-wong-dependency-audit/badge)](https://www.skillsdirectory.com/skills/matthews-wong-dependency-audit)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: dependency-audit
description: Run and triage dependency vulnerability audits across Node.js, Python, Rust, and Go using native tools (npm audit, pip-audit, cargo audit, govulncheck). Use when auditing dependencies for known CVEs or prioritizing remediation.
---

# Dependency audit

Audit dependencies for known vulnerabilities using each ecosystem's native, authoritative tooling. Report only what the tools return — never fabricate CVE IDs, severities, or advisory text.

## Workflow

1. Identify the ecosystem from manifest/lock files.
2. Run the native audit tool (see `reference/tools.md` for exact commands and flags).
3. Triage each finding (see `reference/triage.md`).
4. Produce a prioritized remediation plan.
5. Recommend wiring the same tool into CI for continuous coverage.

## Quick command map

- **Node.js**: `npm audit` (or `npm audit --json`); `pnpm audit`; `yarn npm audit`.
- **Python**: `pip-audit` (uses PyPI + OSV advisory data).
- **Rust**: `cargo audit` (RustSec Advisory DB).
- **Go**: `govulncheck ./...` (Go vuln DB, with call-graph reachability).

See `reference/tools.md` for installation, JSON output, and options.

## Triage priorities (summary)

Rank by: severity → fix availability → reachability → direct vs transitive → exposure of the affected code path. A critical CVE in an unreachable transitive dev-dependency may rank below a high CVE in a reachable runtime path. Full rubric in `reference/triage.md`.

## Honesty rules

- Only report advisory IDs, severities, and fixed versions that the tool actually emitted.
- If unsure whether a finding applies, say so and point to the upstream advisory URL.
- Note the timestamp of the run; advisory databases update continuously.

## References (load on demand)

- `reference/tools.md` — per-ecosystem commands, install, JSON flags, gotchas.
- `reference/triage.md` — severity/reachability triage rubric and remediation patterns.

Files in this skill

  • SKILL.md1.9 KB
  • reference/tools.md2.1 KB
  • reference/triage.md2 KB

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…