Dependency Risk Audit

Audits third-party dependencies for exploitable CVEs, abandonment, license exposure, and supply-chain hygiene, and delivers a ranked findings report with a remediation order. Use when someone asks "is this package safe to add", "audit our dependencies", "npm audit is screaming, what actually matters", "can we use this GPL library", or is preparing a security review or vendor questionnaire. Do NOT use for triaging vulnerabilities in first-party code or a full CVE queue - use vulnerability-triage instead; for reviewing the code you wrote for security flaws - use secure-code-review instead; for how secrets are stored and rotated - use secrets-hygiene instead; for assembling compliance evidence - use soc2-evidence-helper instead.

SkillMedev b56bc39 7.2 KB Updated

File contents

SkillMedev/security-compliance-hardening/tree/main/skills/dependency-risk-audit commit b56bc39a60

Frequently asked questions

npx skillmds@latest add skillmedev/dependency-risk-audit