Skip to content
Back to skills

Dependency Audit

ASecurity

Audits project dependencies for known vulnerabilities, outdated packages, unused dependencies, and license compliance. Works with npm, pip, cargo, go modules, and more.

  • 7 stars
  • 0 votes
  • 0 copies
  • 1 view
  • Added May 28, 2026
ai-agentsrustgorubyphpbashsecurity

Works with

  • cli

Security analysis

A100/100

Scanned May 28, 2026

npx -y skills add viknesh20-20/claude-code-tool-kit --skill dependency-audit --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Dependency Audit?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Dependency Audit
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/viknesh20-20-dependency-audit/badge)](https://www.skillsdirectory.com/skills/viknesh20-20-dependency-audit)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: dependency-audit
description: "Audits project dependencies for known vulnerabilities, outdated packages, unused dependencies, and license compliance. Works with npm, pip, cargo, go modules, and more."
argument-hint: "[optional: 'security', 'outdated', 'unused', or 'all']"
allowed-tools: Read, Grep, Glob, Bash
---

# Dependency Audit

## Detect Package Manager
!`ls package.json package-lock.json yarn.lock pnpm-lock.yaml bun.lockb 2>/dev/null`
!`ls requirements.txt Pipfile Pipfile.lock pyproject.toml poetry.lock 2>/dev/null`
!`ls go.mod go.sum 2>/dev/null`
!`ls Cargo.toml Cargo.lock 2>/dev/null`
!`ls Gemfile Gemfile.lock 2>/dev/null`
!`ls *.csproj *.sln 2>/dev/null`
!`ls composer.json composer.lock 2>/dev/null`
!`ls mix.exs mix.lock 2>/dev/null`

---

## Audit Checks

### 1. Security Vulnerabilities
Run the appropriate audit command:

| Ecosystem | Command |
|-----------|---------|
| npm | `npm audit --json` |
| yarn | `yarn audit --json` |
| pnpm | `pnpm audit --json` |
| pip | `pip audit 2>/dev/null \|\| pip-audit 2>/dev/null` |
| Go | `govulncheck ./... 2>/dev/null` |
| Rust | `cargo audit 2>/dev/null` |
| Ruby | `bundle audit check 2>/dev/null` |
| .NET | `dotnet list package --vulnerable 2>/dev/null` |
| PHP | `composer audit 2>/dev/null` |

For each vulnerability found:
- Package name and version
- CVE ID or advisory ID
- Severity (Critical/High/Medium/Low)
- Fixed version (if available)
- Whether it's a direct or transitive dependency

### 2. Outdated Dependencies
Run the appropriate command:

| Ecosystem | Command |
|-----------|---------|
| npm | `npm outdated --json` |
| pip | `pip list --outdated 2>/dev/null` |
| Go | `go list -m -u all 2>/dev/null` |
| Rust | `cargo outdated 2>/dev/null` |
| Ruby | `bundle outdated 2>/dev/null` |

Classify updates:
- **Patch** (1.0.0 → 1.0.1): Usually safe, bug fixes
- **Minor** (1.0.0 → 1.1.0): New features, backward compatible
- **Major** (1.0.0 → 2.0.0): Breaking changes, needs review

### 3. Unused Dependencies
Look for dependencies that are imported in package manifest but never referenced in code:

1. Read the dependency list from the manifest
2. For each dependency, search the codebase for imports/requires
3. Flag any dependency with zero references as potentially unused

Note: Some dependencies are used via CLI, plugins, or config — verify before removing.

### 4. License Compliance
Check for problematic licenses:
- **Copyleft** (GPL, AGPL): May require releasing your code
- **Permissive** (MIT, Apache, BSD): Generally safe for commercial use
- **Unknown/No License**: Risk — treat as all rights reserved

---

## Output Format

### Vulnerability Summary
| Package | Version | Severity | CVE | Fix Available |
|---------|---------|----------|-----|---------------|

### Outdated Packages
| Package | Current | Latest | Update Type | Breaking? |
|---------|---------|--------|-------------|-----------|

### Potentially Unused
| Package | Last Import Found | Recommendation |
|---------|-------------------|----------------|

### License Concerns
| Package | License | Risk Level |
|---------|---------|------------|

### Recommendations
1. **Immediate**: Critical/High vulnerabilities with available fixes
2. **Short-term**: Major version updates for key dependencies
3. **Backlog**: Minor updates and cleanup of unused dependencies

### Health Score
Rate dependency health from **0 to 10** (10 = all up to date, no vulns).

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…