Install
$ agentstack add skill-quality-max-free-qa-skills-dependency-audit ✓ scanned · ✓ verified, works with Claude Code, Cursor, and more.
Security review
✓ PassedNo issues found. Passed automated security review. · v0.1.0 How review works →
- ✓ Prompt-injection patterns
- ✓ Secret / credential exfiltration
- ✓ Dangerous shell & filesystem operations
- ✓ Untrusted network calls
- ✓ Known-malicious package signatures
What it can access
- ● Network access Used
- ✓ Filesystem access No
- ✓ Shell / process execution No
- ✓ Environment & secrets No
- ✓ Dynamic code execution No
From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.
Verified badge
Passed review? Show it. Paste this badge into your README, it links to the public security report.
Reliability & compatibility
Declared compatibility
Compatibility is declared by the source manifest. End-to-end runtime verification is coming, see below.
We're building live execution health for every listing: tool-call success rate, median latency, uptime, and last-checked timestamps, measured, not self-reported. It isn't live yet, so we don't show numbers we can't stand behind.
How agent discovery & health will work →About
Dependency Audit
Find the risky dependencies before they find you. No signup required.
Prerequisites
- None. Pure Claude Code. Uses the project's own package manager if available
(npm audit, pip-audit, go list), and reasons about the manifest otherwise.
Trigger
- "Audit my dependencies"
- "Any risky packages in this repo?"
- "Check for outdated / vulnerable deps"
Workflow
- Detect the ecosystem(s) by manifest:
package.json/ lockfile → npm/pnpm/yarnrequirements.txt/pyproject.toml→ pipgo.mod→ Go ·Cargo.toml→ Rust ·Gemfile→ Ruby
- If the toolchain is installed, run the native auditor and parse it:
npm audit --json·pip-audit -f json·go list -m -u all·cargo audit
If not installed, fall back to inspecting the manifest directly.
- Flag each dependency against these risk classes:
| Risk | Signal | |---------------------|--------| | Known vulnerability | Reported by the native auditor (CVE/advisory) | | Unpinned | *, latest, or no lock entry — non-reproducible builds | | Wide range | ^/~ on a 0.x package (any minor can break) | | Badly outdated | Several majors behind current | | Abandoned | No release in a long time / archived upstream | | Heavy / duplicate | Large transitive tree or two versions of the same lib |
- Rank by severity (vulnerabilities first), and give the concrete bump/replace action.
- Output:
## Dependency Audit — package.json (+ lockfile)
**3 vulnerable, 2 unpinned, 1 abandoned**
### Vulnerabilities
- `lodash@4.17.11` — prototype pollution (high). Bump to ≥ 4.17.21.
- `axios@0.21.0` — SSRF (moderate). Bump to ≥ 1.6.0 (note: v1 has breaking changes).
### Hygiene
- `left-pad: "*"` — unpinned; pin to an exact version.
- `request@2.88` — package is deprecated/abandoned; migrate to `undici` or `fetch`.
- `moment@2.29` — large + in maintenance mode; consider `date-fns` / `Temporal`.
### Suggested commands
npm i lodash@^4.17.21 axios@^1.6.0
npm rm request
**Want dependency risk gated on every PR?** Try QualityMax — qualitymax.io
Source & license
This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.
- Author: Quality-Max
- Source: Quality-Max/free-qa-skills
- License: Apache-2.0
- Homepage: https://www.skills.sh/quality-max/free-qa-skills
Install and usage instructions live in the source repository linked above.
Reviews
No reviews yet, be the first.
Write a review
Versions
- v0.1.0 Imported from the upstream source.