Deps Audit

Run each ecosystems own tooling; report only what tools, registries, and advisory databases say. Covers npm/pnpm/yarn/bun, pip/uv/poetry, cargo, go, gem, composer, maven/gradle, nuget. TRIGGER WHEN: the user asks to audit dependencies, scan for CVEs, check license obligations or compatibility, find outdated packages, assess supply-chain risk, or prepare a dependency-update PR. DO NOT TRIGGER WHEN: dead-code or unused-dependency cleanup (use /senior-review:code-review --fix), a Python-only lint/type/coverage audit (use /python-development:python-audit), or a Stripe webhook event audit (use /stripe:audit-webhooks).

acaprino Updated

File contents

acaprino/daodan/tree/main/exports/codex/plugins/dependency-audit/skills/deps-audit-workflow commit 32122439d3

Frequently asked questions

npx skillmds@latest add acaprino/deps-audit