Skip to main content
Back to registry

dependency-audit

jezweb/claude-skills

Status : Production Ready Last Updated : 2026-02-03 Scope : npm, pnpm, yarn projects

Installs159
Install command
npx skills add https://github.com/jezweb/claude-skills --skill dependency-audit
About this skill
Status : Production Ready Last Updated : 2026-02-03 Scope : npm, pnpm, yarn projects Categories: Checks for: The dep-auditor agent can: Version : 1.0.0 Last Updated : 2026-02-03 - Critical (CVSS 9.0-10.0): Remote code execution, auth bypass - High (CVSS 7.0-8.9): Data exposure, privilege escalation - Moderate (CVSS 4.0-6.9): DoS, info disclosure - Low (CVSS 0.1-3.9): Minor issues - Major updates : Breaking changes likely (review changelog) - Minor updates : New features, backwards compatible - Patch updates : Bug fixes, safe to update - GPL licenses in commercial projects (copyleft risk) - Unknown/missing licenses - License conflicts - Deprecated packages - Abandoned packages (no updates in 2+ years) - Packages with open security issues - Parse npm/pnpm audit JSON output - Cross-reference CVE databases - Generate detailed fix recommendations - Auto-fix safe updates (with confirmation) - npm audit fix --force : May introduce breaking changes (major version bumps) - Transitive dependencies : Some vulnerabilities require updating parent packages - False positives : Some advisories may not apply to your usage - Private registries : May need auth configuration for auditing - cloudflare-worker-base : For Workers projects - testing-patterns : Run tests after updates - developer-toolbox : For commit-helper after fixes

Source description provided by the upstream skill listing. Community reviews and install context appear in the sections below.

Community Reviews

Latest reviews

Sign in to review

No community reviews yet. Be the first to review.

Browse this skill in context
FAQ
What does dependency-audit do?

Status : Production Ready Last Updated : 2026-02-03 Scope : npm, pnpm, yarn projects

Is dependency-audit good?

dependency-audit does not have approved reviews yet, so SkillJury cannot publish a community verdict.

What agent does dependency-audit work with?

dependency-audit currently lists compatibility with codex, gemini-cli, opencode, cursor, replit, claude-code.

What are alternatives to dependency-audit?

Skills in the same category include telegram-bot-builder, flutter-app-size, sharp-edges, iterative-retrieval.

How do I install dependency-audit?

npx skills add https://github.com/jezweb/claude-skills --skill dependency-audit

Related skills

More from jezweb/claude-skills

Related skills

Alternatives in Software Engineering