Skip to content
Back to skills

Dependency Management

ASecurity

Vet packages before adoption, audit for vulnerabilities, pin versions, and prevent dependency bloat.

  • 7 stars
  • 0 votes
  • 0 copies
  • 2 views
  • Added May 27, 2026
developmentrustgitfrontendsecurity

Security analysis

A92/100
  • mediumInstalls packages at runtime which could introduce malicious dependencies

Pro shows the line behind each finding and how to fix it

Scanned May 27, 2026

npx -y skills add Vimalk0703/shipworthy --skill dependency-management --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Dependency Management?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Dependency Management
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/vimalk0703-dependency-management/badge)](https://www.skillsdirectory.com/skills/vimalk0703-dependency-management)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: dependency-management
description: Vet packages before adoption, audit for vulnerabilities, pin versions, and prevent dependency bloat.
invoke_when: Use when adding a new dependency, reviewing package.json/requirements.txt, auditing for vulnerabilities, or when the post-tool-use hook detects a package installation.
---

# Dependency Management

## Before Adding a Dependency

### 1. Is it necessary?
- Can this be done in <50 lines without the dependency?
- Does the standard library already provide this?

### 2. Is it trustworthy?
- Downloads: >10K weekly (npm) or >1K stars (GitHub)
- Maintenance: updated within last 6 months
- License: MIT, Apache 2.0, BSD are safe
- Security: no open critical/high CVEs

### 3. What's the cost?
- Bundle size impact (for frontend)
- Transitive dependency count
- Lock-in risk

## When Adding
1. Install with exact version: `npm install package@1.2.3 --save-exact`
2. Run `npm audit` immediately after
3. Review lock file diff
4. Document WHY this dependency was chosen

## Red Flags
- Package with <100 weekly downloads
- Single maintainer with no org backing (for critical deps)
- No test suite in the package source
- Excessive transitive dependencies for a simple task
- Not updated in 2+ years (unless genuinely complete)
- Copyleft license (GPL) when your project isn't

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…