Depaudit

Forensic dependency & supply-chain audit v1 (Gestalt-Popper). 18-phase deep analysis of everything the project TRUSTS from third parties: dependency CVE exposure (direct + transitive), outdated and abandoned packages, license compliance and contamination, lockfile integrity and reproducible builds, transitive dependency bloat and duplication, typosquatting / dependency-confusion / namespace-takeover risk, postinstall and lifecycle script auditing, pinned vs floating version policy, SBOM generation and completeness, registry trust and provenance, bundle exposure (server deps leaking to client), monorepo workspace hygiene, plus verdict, fix plan, fix execution, re-audit, and build-integrity safety gate. Answers "Is the supply chain SAFE?" Score /360. Preamble v1.0 compliant. Complements /secaudit (which owns RUNTIME exploitation of CVEs) — depaudit owns STATIC supply-chain hygiene, provenance, licensing, and reproducibility. Audit -> Plan -> Fix -> Re-audit. Use when user says "/depaudit", "dependency audit", "

agentik-os 0b5e0b3 40.9 KB Updated

File contents

agentik-os/omegaos/tree/main/skills/audits/depaudit commit 0b5e0b3b99

Frequently asked questions

npx skillmds@latest add agentik-os/depaudit