Dependency Auditor

by Alireza Rezvani alirezarezvani/dependency-auditor multi-file Updated


Audit and manage dependencies across multi-language projects by scanning for vulnerabilities, license conflicts, and transitive dependency risks, with safe-upgrade planning.

SKILL.md

Related

  1. Security Review · github bundle
    Scans codebases for security vulnerabilities by reasoning about code context, data flow, and component interactions, covering injection flaws, secrets exposure, authentication issues, and weak cryptography across multiple languages.
    36.2k
    repo stars
  2. Performing Container Security Scanning With Trivy · mukul975 bundle
    Scan container images, filesystems, and Kubernetes manifests for vulnerabilities, misconfigurations, exposed secrets, and license compliance issues using Aqua Security Trivy with SBOM generation and CI/CD integration.
    24.6k
    repo stars
  3. Detecting Typosquatting Packages · mukul975 bundle
    Flag misspelled, brandjacked, and typosquatted package names across npm, PyPI, and crates.io before installation using edit-distance, keyboard-proximity, and known-target corpus matching with typomania, OSSGadget, and pypi-scan.
    24.6k
    repo stars
  4. Implementing Rapid7 Insightvm For Scanning · mukul975 bundle
    Deploy and configure Rapid7 InsightVM Security Console and Scan Engines for authenticated and unauthenticated vulnerability scanning across enterprise environments.
    24.6k
    repo stars
  5. Security Compliance Automation · chimeranext bundle
    Automates security and compliance checks using OPA policies, Trivy vulnerability scanning, AWS CIS benchmark verification, and Kubernetes remediation scripts.
    4
    repo stars
  6. Senior Secops · alirezarezvani bundle
    Run security audits, vulnerability scans, compliance checks, and incident response workflows for application security.
    20.4k
    repo stars

Frequently asked questions

How do I install the Dependency Auditor skill?

Run npx skillmds add alirezarezvani/dependency-auditor in your terminal (requires Node.js), paste this page's agent-chat prompt into Claude, Cursor, or any MCP-connected agent, or download the SKILL.md file and copy it into your agent's skills directory.

What does the Dependency Auditor skill do?

Audit and manage dependencies across multi-language projects by scanning for vulnerabilities, license conflicts, and transitive dependency risks, with safe-upgrade planning. It is listed under Security, DevOps & Infra, Web & Frontend, CI/CD, Compliance & Privacy, Vulnerability Scanning on SkillMD.

Is Dependency Auditor safe to use?

SkillMD's automated safety review verdict for this skill is PASS. Independent scanners report: SkillSpector: FAIL, Skill Scanner: PASS. Capability flags: executes scripts, makes network calls, reads secrets. SkillMD never runs a skill's scripts for you; review the SKILL.md before installing.

Which AI agents work with Dependency Auditor?

This skill is tagged as working with Claude Code, Claude.ai, OpenAI Codex. SKILL.md is an open format, so most agents that read a skills directory can load it too.

Is Dependency Auditor free to use?

Yes. Installing skills from SkillMD is free, and the skill stays under its author's original license.

Who published Dependency Auditor?

Alireza Rezvani (@alirezarezvani) published this skill. Their other Agent Skills are listed on their SkillMD profile.