Install
$ agentstack add skill-davila7-claude-with-skills-well-documented-skill ✓ scanned · ✓ verified — works with Claude Code, Cursor, and more.
Security review
✓ PassedNo issues found. Passed automated security review. · v0.1.0 How review works →
- ✓ Prompt-injection patterns
- ✓ Secret / credential exfiltration
- ✓ Dangerous shell & filesystem operations
- ✓ Untrusted network calls
- ✓ Known-malicious package signatures
What it can access
- ✓ Network access No
- ✓ Filesystem access No
- ✓ Shell / process execution No
- ✓ Environment & secrets No
- ✓ Dynamic code execution No
From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.
About
Dependency audit
Run a dependency health check for the current project. If a specific package name was provided as an argument, focus the audit on that package. Otherwise audit all dependencies.
Step 1: Detect the package manager
Check whether this is a Node.js or Python project:
- If
package.jsonexists in the working directory, use npm. - If
requirements.txt,pyproject.toml, orsetup.pyexists, use pip. - If both exist, audit both.
Step 2: Check for outdated packages
For npm:
npm outdated
For pip:
pip list --outdated
If $ARGUMENTS is a specific package name, filter the output to that package. If $ARGUMENTS is empty or "all", show the full list.
Step 3: Check for known vulnerabilities
For npm:
npm audit
For pip (if pip-audit is available):
pip-audit
If pip-audit is not installed, note its absence and recommend installing it: pip install pip-audit.
Step 4: Summarize findings
Present a concise report:
- Total outdated packages (current version vs latest version for the top 10 most outdated)
- Any vulnerabilities found: severity level, affected package, advisory ID
- Recommended actions in priority order: fix critical vulnerabilities first, then high, then update packages with breaking changes separately from patch updates
- If
$ARGUMENTSnames a specific package: show its current version, latest version, changelog link if available fromnpm info homepageorpip show, and whether any known vulnerabilities affect this specific package
Notes
- Do not modify
package.json,requirements.txt, or any lock file. This skill audits only; it does not upgrade. - If the project has no dependencies file at all, report that and stop.
Source & license
This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.
- Author: davila7
- Source: davila7/claude-with-skills
- License: MIT
- Homepage: https://claude-with-skills.vercel.app
Install and usage instructions live in the source repository linked above.
Reviews
No reviews yet — be the first.
Write a review
Versions
- v0.1.0 Imported from the upstream source.