AgentStack
SKILL verified MIT Self-run

Dependency Audit

skill-davila7-claude-with-skills-well-documented-skill · by davila7

Audit npm or pip dependencies for outdated packages and known vulnerabilities. Use when checking package health, preparing for a release, reviewing dependencies before merging a PR, or when asked about outdated packages or security advisories.

No reviews yet
0 installs
18 views
0.0% view→install

Install

$ agentstack add skill-davila7-claude-with-skills-well-documented-skill

✓ scanned · ✓ verified — works with Claude Code, Cursor, and more.

Security review

✓ Passed

No issues found. Passed automated security review. · v0.1.0 How review works →

  • Prompt-injection patterns
  • Secret / credential exfiltration
  • Dangerous shell & filesystem operations
  • Untrusted network calls
  • Known-malicious package signatures

What it can access

  • Network access No
  • Filesystem access No
  • Shell / process execution No
  • Environment & secrets No
  • Dynamic code execution No

From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.

Are you the author of Dependency Audit? Claim this listing to set pricing, connect Stripe payouts, and keep 70% of every sale.
Sign up to claim

About

Dependency audit

Run a dependency health check for the current project. If a specific package name was provided as an argument, focus the audit on that package. Otherwise audit all dependencies.

Step 1: Detect the package manager

Check whether this is a Node.js or Python project:

  • If package.json exists in the working directory, use npm.
  • If requirements.txt, pyproject.toml, or setup.py exists, use pip.
  • If both exist, audit both.

Step 2: Check for outdated packages

For npm:

npm outdated

For pip:

pip list --outdated

If $ARGUMENTS is a specific package name, filter the output to that package. If $ARGUMENTS is empty or "all", show the full list.

Step 3: Check for known vulnerabilities

For npm:

npm audit

For pip (if pip-audit is available):

pip-audit

If pip-audit is not installed, note its absence and recommend installing it: pip install pip-audit.

Step 4: Summarize findings

Present a concise report:

  1. Total outdated packages (current version vs latest version for the top 10 most outdated)
  2. Any vulnerabilities found: severity level, affected package, advisory ID
  3. Recommended actions in priority order: fix critical vulnerabilities first, then high, then update packages with breaking changes separately from patch updates
  4. If $ARGUMENTS names a specific package: show its current version, latest version, changelog link if available from npm info homepage or pip show , and whether any known vulnerabilities affect this specific package

Notes

  • Do not modify package.json, requirements.txt, or any lock file. This skill audits only; it does not upgrade.
  • If the project has no dependencies file at all, report that and stop.

Source & license

This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.

Install and usage instructions live in the source repository linked above.

Reviews

No reviews yet — be the first.

Versions

  • v0.1.0 Imported from the upstream source.