Installs into .claude/skills of the current project.
Are you the author of Dependency Cve Audit?
Add the live security badge to your README. It updates with every re-scan.
[](https://www.skillsdirectory.com/skills/startmeupai-dependency-cve-audit)
---
name: dependency-cve-audit
description: Audit dependency advisories, lockfile integrity, lifecycle scripts, and parser risk.
---
# Dependency CVE Audit
## Trigger Conditions
Use before merging dependency changes or during a periodic supply-chain review.
## Required Inputs
- Package manifest, lockfile, dependency diff, audit availability, and risk-critical packages.
## Workflow
1. Confirm the lockfile exists and matches the manifest.
2. Run the package-manager audit when network access is authorized.
3. Map advisories to production/development reachability and dependency paths.
4. Inspect newly introduced install/prepare lifecycle scripts.
5. Flag wildcard or moving-tag direct dependencies.
6. Review unmaintained parsers that handle untrusted input.
## Deterministic Checks
- Frozen-lockfile check, manifest-range scan, lifecycle-script diff, and audit JSON parse.
## Safety and Permission Boundaries
- Do not install, upgrade, or contact registries unless authorized; report unavailable data.
## Required Evidence
- Package, installed version, advisory identifier, dependency path, fix version, and limitations.
## Completion Condition
- All local checks run and network-dependent checks are passed or explicitly unavailable.
## Example
`Audit ExampleApp dependencies before the release branch is cut.`