Install
$ agentstack add skill-leek-agent-skills-weekly-npm-dependency-audit ✓ scanned · ✓ verified — works with Claude Code, Cursor, and more.
Security review
✓ PassedNo issues found. Passed automated security review. · v0.1.0 How review works →
- ✓ Prompt-injection patterns
- ✓ Secret / credential exfiltration
- ✓ Dangerous shell & filesystem operations
- ✓ Untrusted network calls
- ✓ Known-malicious package signatures
What it can access
- ✓ Network access No
- ✓ Filesystem access No
- ✓ Shell / process execution No
- ✓ Environment & secrets No
- ✓ Dynamic code execution No
From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.
About
NPM Dependency Audit Weekly
Goal
Deliver a weekly npm dependency audit summary.
Loop
Kickoff prompt:
/loop 7d Start the "NPM Dependency Audit Weekly" loop.
Goal: deliver a weekly npm dependency audit summary.
Between iterations run: npm outdated || true
Exit when: summary is posted with recommended upgrades.
Step 1: Run npm outdated, categorize updates, and propose a safe upgrade plan.
Run this in the target project:
npm outdated || true
Also run a security audit when the project has a lockfile that makes the result meaningful:
npm audit || true
If there is no package.json, stop and report that the current directory is not an npm project.
Report
Summarize the result with:
- Current package manager evidence, such as
package-lock.json,npm-shrinkwrap.json, or npm scripts. - Outdated dependencies grouped by patch, minor, and major updates.
- Security advisories from
npm audit, grouped by severity, if audit output is available. - Recommended safe upgrade order, starting with low-risk patch and minor updates.
- Breaking-change risks, required code changes, or test coverage gaps for major updates.
- Exact verification commands the project should run after upgrades.
Keep the report direct. Do not apply upgrades unless the user asks you to do the upgrade work.
Guardrails
- Do not modify the check command or exit criteria to force success.
- Do not skip, disable, or bypass checks to make the audit look clean.
- If package metadata is missing, dependency resolution fails, or audit output is blocked by registry/authentication issues, stop and report the blocker.
Source & license
This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.
- Author: leek
- Source: leek/agent-skills
- License: MIT
- Homepage: https://skills.sh/leek/agent-skills
Install and usage instructions live in the source repository linked above.
Reviews
No reviews yet — be the first.
Write a review
Versions
- v0.1.0 Imported from the upstream source.