Dependency Vetting

Vet an npm (or other) package for supply-chain risk before it's added to a project. Use when asked whether a package is safe, trustworthy, or worth adding, when about to install an unfamiliar dependency, or when something about a package feels off. Runs isolated and read-only, reports an evidence-backed risk verdict, does not install anything.

TheDecipherist ee18642 3.4 KB Updated

File contents

thedecipherist/claude-code-mastery-project-starter-kit/tree/main/.claude/skills/dependency-vetting commit ee186423ff

Frequently asked questions

npx skillmds@latest add thedecipherist/dependency-vetting