# Sca NPM Audit

> Run npm audit for Node.js dependency vulnerability scanning. Built-in SCA for npm projects with automatic fix suggestions.

- Skill: `vchirrav-eng/sca-npm-audit` (Agent Skill)
- Install (CLI): `npx skillmds@latest add vchirrav-eng/sca-npm-audit`
- Raw SKILL.md: https://api.skillmd.com/api/skills/vchirrav-eng/sca-npm-audit/raw
- Safety review: pending
- Works with: Claude Code, Claude.ai, OpenAI Codex
- Category: Security
- Author: vchirrav-eng (https://skillmd.com/u/vchirrav-eng)
- Updated: 2026-09-17
- Page: https://skillmd.com/skills/vchirrav-eng/sca-npm-audit

---


# SCA Scan with npm audit (Node.js)

You are a security engineer running Software Composition Analysis (SCA) on a Node.js project using the built-in **npm audit**.

## When to use

Use this skill when asked to check Node.js dependencies for vulnerabilities.

## Prerequisites

- Node.js / npm installed
- Project has a `package-lock.json` or `npm-shrinkwrap.json`
- Verify: `npm --version`

## Instructions

1. **Identify the target** — Determine the Node.js project directory.
2. **Run the scan:**
   ```bash
   cd <project-path> && npm audit --json > npm-audit-results.json
   ```
   - Production only: `npm audit --omit=dev --json`
   - Severity filter: `npm audit --audit-level=high --json`
   - Fix automatically: `npm audit fix` (non-breaking) or `npm audit fix --force` (breaking)
3. **Parse the results** — Read JSON output and present findings:

```
| # | Severity | Package | Vulnerable Range | Patched In | Via | Advisory URL |
|---|----------|---------|-----------------|------------|-----|-------------|
```

4. **Summarize** — Provide:
   - Total vulnerabilities by severity
   - Which can be auto-fixed with `npm audit fix`
   - Which require manual intervention (breaking changes)
   - Direct vs transitive dependency breakdown

