# Dependency Audit

> Audits a project's Python and JavaScript dependencies for known CVEs and version drift — pip-audit for the backend, pnpm audit for the frontend, plus lockfile and pinning hygiene. Use when checking dependencies for vulnerabilities, adding or upgrading a package, reviewing a Dependabot or renovate PR, wiring a supply-chain gate into CI, or triaging an audit finding. Not for reviewing application c…

- **Type:** Skill
- **Install:** `agentstack add skill-deadlymind-nanolama-dependency-audit`
- **Verified:** Yes — security-reviewed for prompt injection and unsafe behavior
- **Seller:** [Deadlymind](https://agentstack.voostack.com/s/deadlymind)
- **Installs:** 0
- **Category:** [Developer Tools](https://agentstack.voostack.com/c/developer-tools)
- **Latest version:** 0.1.0
- **License:** MIT
- **Upstream author:** [Deadlymind](https://github.com/Deadlymind)
- **Source:** https://github.com/Deadlymind/nanolama/tree/main/skills/dependency-audit

## Install

```sh
agentstack add skill-deadlymind-nanolama-dependency-audit
```

Requires the [AgentStack CLI](https://agentstack.voostack.com/docs/cli). Works with Claude Code, Cursor, and any MCP-compatible agent.

## About

# Dependency audit (supply-chain hygiene)

## When to use
Before adding or bumping a dependency, when a vulnerability scanner or bot flags one,
and on a schedule in CI. A CVE in a transitive package is as real as a bug in your own
code — treat the dependency tree as attack surface.

## Pattern
Scan **both** ecosystems against advisory databases, from the **committed lockfiles**
(so you audit exactly what ships), triage each finding (upgrade, or consciously accept
with a recorded reason), and run the scan as a CI gate so new CVEs surface on their own.

## Steps / idioms
1. Commit and audit from lockfiles — `uv.lock`/`poetry.lock`/pinned `requirements.txt`
   and `pnpm-lock.yaml`. Pin production deps; never audit a floating range.
2. Run both scanners; fail the build on the severity you care about:

   ```bash
   # Python — pip-audit reads installed pkgs or a requirements file (OSV/PyPI advisories)
   pip-audit -r requirements.txt --strict            # non-zero exit on any known CVE
   #   pip-audit --fix                                # auto-bump where a safe version exists

   # JavaScript — audit the pnpm workspace
   pnpm audit --prod --audit-level=high              # non-zero exit at >= high
   #   pnpm audit --fix                              # apply compatible upgrades

   # Triage a finding you cannot fix yet: upgrade, or record an explicit, expiring waiver
   #   (e.g. a pip-audit --ignore-vuln GHSA-xxxx with a comment + review date).
   ```

3. Automate the bumps: enable Dependabot or renovate, and review those PRs against this
   same checklist rather than merging blindly.
4. Vet **new** dependencies before adding: real project, active maintenance, sane
   transitive footprint, and the exact package name (guard against typosquats).

## Adapt to your repo
Swap the tools for your package managers (`npm audit`/`yarn npm audit`, `poetry`, `uv`,
`osv-scanner`, or `safety` as an alternative to pip-audit). Choose the `--audit-level`
threshold your team enforces, and point the commands at your real lockfile paths.

## Gotchas
- Auditing installed packages instead of the lockfile hides what actually deploys — scan the lock.
- `--audit-level=high` still lets moderate CVEs through; pick the threshold deliberately.
- A "fix" that jumps a major version can break you — read the changelog, don't just take `--fix`.
- Dev-only advisories still matter for your build/CI machines; scan dev deps too, separately.
- Accepting a finding without an expiry turns into a permanent silent risk — set a review date.

## See also
- `version-check`
- `security-review`
- `ci-cd`

## Source & license

This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.

- **Author:** [Deadlymind](https://github.com/Deadlymind)
- **Source:** [Deadlymind/nanolama](https://github.com/Deadlymind/nanolama)
- **License:** MIT

Install and usage instructions live in the source repository linked above.

## Pricing

- **Free** — Free

## Security capabilities

Automated source analysis of v0.1.0 — what this tool can access:

- **Network access:** no
- **Filesystem access:** no
- **Shell / process execution:** no
- **Environment & secrets:** no
- **Dynamic code execution:** no

*"Yes" means the capability is present in the source — more access means more to trust, not that it is unsafe.*


## Versions

- **0.1.0** — security scan: passed — Imported from the upstream source.

## Links

- Listing page: https://agentstack.voostack.com/l/skill-deadlymind-nanolama-dependency-audit
- Seller: https://agentstack.voostack.com/s/deadlymind
- Browse the marketplace: https://agentstack.voostack.com/browse

---
Listed on AgentStack — the marketplace for AI agent skills and MCP servers. Every listing is security-reviewed. Creators keep 70%.
