Skip to content
Back to skills

Dependency Cve Audit

ASecurity

Audit dependency advisories, lockfile integrity, lifecycle scripts, and parser risk.

  • 11 stars
  • 0 votes
  • 0 copies
  • 3 views
  • Added September 23, 2026
ai-agentsrust

Security analysis

A100/100

Scanned September 23, 2026

npx -y skills add startmeupai/swe-agents --skill dependency-cve-audit --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Dependency Cve Audit?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Dependency Cve Audit
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/startmeupai-dependency-cve-audit/badge)](https://www.skillsdirectory.com/skills/startmeupai-dependency-cve-audit)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: dependency-cve-audit
description: Audit dependency advisories, lockfile integrity, lifecycle scripts, and parser risk.
---

# Dependency CVE Audit

## Trigger Conditions

Use before merging dependency changes or during a periodic supply-chain review.

## Required Inputs

- Package manifest, lockfile, dependency diff, audit availability, and risk-critical packages.

## Workflow

1. Confirm the lockfile exists and matches the manifest.
2. Run the package-manager audit when network access is authorized.
3. Map advisories to production/development reachability and dependency paths.
4. Inspect newly introduced install/prepare lifecycle scripts.
5. Flag wildcard or moving-tag direct dependencies.
6. Review unmaintained parsers that handle untrusted input.

## Deterministic Checks

- Frozen-lockfile check, manifest-range scan, lifecycle-script diff, and audit JSON parse.

## Safety and Permission Boundaries

- Do not install, upgrade, or contact registries unless authorized; report unavailable data.

## Required Evidence

- Package, installed version, advisory identifier, dependency path, fix version, and limitations.

## Completion Condition

- All local checks run and network-dependent checks are passed or explicitly unavailable.

## Example

`Audit ExampleApp dependencies before the release branch is cut.`

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…