Awesome Dependency Audit

Read-only audit of third-party dependencies — lockfile discipline, typosquats and hallucinated package names, dependency confusion, install-script exposure, provenance, licenses, CVE reachability — with a SHIP / FIX / BLOCK verdict. Use when asked to audit dependencies or the supply chain, judge whether a package is safe, review a manifest change, after a bot version bump, or 'проверь зависимости'. Do not use for vulnerabilities in your own code (awesome-security-audit) or to execute the upgrades (awesome-dependency-upgrade).

khasky 51807a2 14.4 KB Updated

File contents

khasky/awesome-agent-skills/tree/main/skills/awesome-dependency-audit commit 51807a236e

Frequently asked questions

npx skillmds@latest add khasky/awesome-dependency-audit