Dependency Checker
This skill provides automated assistance for dependency checker tasks.
Overview
This skill empowers Claude to automatically analyze your project's dependencies for security vulnerabilities, outdated packages, and license compliance issues. It uses the dependency-checker plugin to identify potential risks and provides insights for remediation.
How It Works
- Detecting Package Manager: The skill identifies the relevant package manager (npm, pip, composer, gem, go modules) based on the presence of manifest files (e.g., package.json, requirements.txt, composer.json).
- Scanning Dependencies: The skill utilizes the dependency-checker plugin to scan the identified dependencies against known vulnerability databases (CVEs), outdated package lists, and license information.
- Generating Report: The skill presents a comprehensive report summarizing the findings, including vulnerability summaries, detailed vulnerability information, outdated packages with recommended updates, and license compliance issues.
When to Use This Skill
This skill activates when you need to:
- Check a project for known security vulnerabilities in its dependencies.
- Identify outdated packages that may contain security flaws or performance issues.
- Ensure that the project's dependencies comply with licensing requirements.
Examples
Example 1: Identifying Vulnerabilities Before Deployment
User request: "Check dependencies for vulnerabilities before deploying to production."
The skill will:
- Detect the relevant package manager (e.g., npm).
- Scan the project's dependencies for known vulnerabilities using the dependency-checker plugin.
- Generate a report highlighting any identified vulnerabilities, their severity, and recommended fixes.
Example 2: Updating Outdated Packages
User request: "Scan for outdated packages and suggest updates."
The skill will:
- Detect the relevant package manager (e.g., pip).
- Scan the project's dependencies for outdated packages.
- Generate a report listing the outdated packages and their available updates, including major, minor, and patch releases.
Best Practices
- Regular Scanning: Schedule dependency checks regularly (e.g., weekly or monthly) to stay informed about new vulnerabilities and updates.
- Pre-Deployment Checks: Always run a dependency check before deploying any code to production to prevent introducing vulnerable dependencies.
- Review and Remediation: Carefully review the generated reports and take appropriate action to remediate identified vulnerabilities and update outdated packages.
Integration
This skill seamlessly integrates with other Claude Code tools, allowing you to use the identified vulnerabilities to guide further actions, such as automatically creating pull requests to update dependencies or generating security reports for compliance purposes.
Prerequisites
- Access to codebase and configuration files in {baseDir}/
- Security scanning tools installed as needed
- Understanding of security standards and best practices
- Permissions for security analysis operations
Instructions
- Identify security scan scope and targets
- Configure scanning parameters and thresholds
- Execute security analysis systematically
- Analyze findings for vulnerabilities and compliance gaps
- Prioritize issues by severity and impact
- Generate detailed security report with remediation steps
Output
- Security scan results with vulnerability details
- Compliance status reports by standard
- Prioritized list of security issues by severity
- Remediation recommendations with code examples
- Executive summary for stakeholders
Error Handling
If security scanning fails:
- Verify tool installation and configuration
- Check file and directory permissions
- Validate scan target paths
- Review tool-specific error messages
- Ensure network access for dependency checks
Resources
- Security standard documentation (OWASP, CWE, CVE)
- Compliance framework guidelines (GDPR, HIPAA, PCI-DSS)
- Security scanning tool documentation
- Vulnerability remediation best practices
1---2name: analyzing-dependencies3description: Analyze dependencies for known security vulnerabilities and outdated versions. Use when auditing third-party libraries. Trigger with 'check dependencies', 'scan for vulnerabilities', or 'audit packages'.4license: MIT5---6# Dependency Checker78This skill provides automated assistance for dependency checker tasks.910## Overview1112This skill empowers Claude to automatically analyze your project's dependencies for security vulnerabilities, outdated packages, and license compliance issues. It uses the dependency-checker plugin to identify potential risks and provides insights for remediation.1314## How It Works15161. **Detecting Package Manager**: The skill identifies the relevant package manager (npm, pip, composer, gem, go modules) based on the presence of manifest files (e.g., package.json, requirements.txt, composer.json).172. **Scanning Dependencies**: The skill utilizes the dependency-checker plugin to scan the identified dependencies against known vulnerability databases (CVEs), outdated package lists, and license information.183. **Generating Report**: The skill presents a comprehensive report summarizing the findings, including vulnerability summaries, detailed vulnerability information, outdated packages with recommended updates, and license compliance issues.1920## When to Use This Skill2122This skill activates when you need to:23- Check a project for known security vulnerabilities in its dependencies.24- Identify outdated packages that may contain security flaws or performance issues.25- Ensure that the project's dependencies comply with licensing requirements.2627## Examples2829### Example 1: Identifying Vulnerabilities Before Deployment3031User request: "Check dependencies for vulnerabilities before deploying to production."3233The skill will:341. Detect the relevant package manager (e.g., npm).352. Scan the project's dependencies for known vulnerabilities using the dependency-checker plugin.363. Generate a report highlighting any identified vulnerabilities, their severity, and recommended fixes.3738### Example 2: Updating Outdated Packages3940User request: "Scan for outdated packages and suggest updates."4142The skill will:431. Detect the relevant package manager (e.g., pip).442. Scan the project's dependencies for outdated packages.453. Generate a report listing the outdated packages and their available updates, including major, minor, and patch releases.4647## Best Practices4849- **Regular Scanning**: Schedule dependency checks regularly (e.g., weekly or monthly) to stay informed about new vulnerabilities and updates.50- **Pre-Deployment Checks**: Always run a dependency check before deploying any code to production to prevent introducing vulnerable dependencies.51- **Review and Remediation**: Carefully review the generated reports and take appropriate action to remediate identified vulnerabilities and update outdated packages.5253## Integration5455This skill seamlessly integrates with other Claude Code tools, allowing you to use the identified vulnerabilities to guide further actions, such as automatically creating pull requests to update dependencies or generating security reports for compliance purposes.5657## Prerequisites5859- Access to codebase and configuration files in {baseDir}/60- Security scanning tools installed as needed61- Understanding of security standards and best practices62- Permissions for security analysis operations6364## Instructions65661. Identify security scan scope and targets672. Configure scanning parameters and thresholds683. Execute security analysis systematically694. Analyze findings for vulnerabilities and compliance gaps705. Prioritize issues by severity and impact716. Generate detailed security report with remediation steps7273## Output7475- Security scan results with vulnerability details76- Compliance status reports by standard77- Prioritized list of security issues by severity78- Remediation recommendations with code examples79- Executive summary for stakeholders8081## Error Handling8283If security scanning fails:84- Verify tool installation and configuration85- Check file and directory permissions86- Validate scan target paths87- Review tool-specific error messages88- Ensure network access for dependency checks8990## Resources9192- Security standard documentation (OWASP, CWE, CVE)93- Compliance framework guidelines (GDPR, HIPAA, PCI-DSS)94- Security scanning tool documentation95- Vulnerability remediation best practices