Install
$ agentstack add skill-motao123-dev-workflow-kit-dependency-compliance-audit ✓ scanned · ✓ verified, works with Claude Code, Cursor, and more.
Security review
✓ PassedNo issues found. Passed automated security review. · v0.1.0 How review works →
- ✓ Prompt-injection patterns
- ✓ Secret / credential exfiltration
- ✓ Dangerous shell & filesystem operations
- ✓ Untrusted network calls
- ✓ Known-malicious package signatures
What it can access
- ✓ Network access No
- ✓ Filesystem access No
- ✓ Shell / process execution No
- ✓ Environment & secrets No
- ✓ Dynamic code execution No
From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.
Verified badge
Passed review? Show it. Paste this badge into your README, it links to the public security report.
Reliability & compatibility
Declared compatibility
Compatibility is declared by the source manifest. End-to-end runtime verification is coming, see below.
We're building live execution health for every listing: tool-call success rate, median latency, uptime, and last-checked timestamps, measured, not self-reported. It isn't live yet, so we don't show numbers we can't stand behind.
How agent discovery & health will work →About
Dependency Compliance Audit
Use this skill when package choice or package governance is the main blocker.
Trigger Conditions
Use this skill when:
- the user asks whether a new dependency is safe or acceptable to adopt
- license, policy, provenance, or supply-chain concerns are in scope
- a stale, risky, or vulnerable package needs to be evaluated
- package upgrade pressure is affecting release confidence
- the team needs a dependency-focused review before merge or release
Do not use this skill for general code security review, product design, or final release signoff across the whole change.
Workflow
- Identify the dependency or dependency set under review.
- Clarify whether the concern is security, license, policy, maintenance, provenance, or upgrade compatibility.
- Separate direct dependency concerns from broader code-path concerns.
- Classify risk and likely decision options.
- Recommend the smallest next action with the best tradeoff.
- Suggest any follow-up review or documentation needed.
Output
For non-trivial work, provide:
- dependency scope reviewed
- main risk categories
- likely policy or release concerns
- recommended decision path
- follow-up verification or documentation
Coordination
After audit:
- use
security-reviewif dependency concerns expand into runtime trust-boundary issues - use
docs-writerif policy or migration notes should be recorded - use
ship-readinessif package choice remains a release blocker
Invocation Examples
- "Use dependency-compliance-audit to review whether this new package is safe to adopt."
- "Use dependency-compliance-audit because the main concern is license and supply-chain fit."
- "Use dependency-compliance-audit to assess whether this outdated package is still acceptable for release."
Source & license
This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.
- Author: motao123
- Source: motao123/dev-workflow-kit
- License: MIT
- Homepage: https://motao123.github.io/dev-workflow-kit/
Install and usage instructions live in the source repository linked above.
Reviews
No reviews yet, be the first.
Write a review
Versions
- v0.1.0 Imported from the upstream source.