Dependency Auditor

    by Samuel Rose

    1

    Audit dependencies for security, licenses, and health while generating a phased, low-risk upgrade and migration plan.

    Secure checkout via Stripe

    1 installSecurity scanned

    Works with the AI tools you already use

    CClaude CodeCCursorCCodex CLIGGitHub CopilotGGemini CLIVVS CodeWWindsurfMManus+14 more

    See it in action

    You say

    Please audit my package.json for any security vulnerabilities, outdated libraries, or abandoned packages and provide a prioritized upgrade plan.

    Your agent does

    Audit Results:

    • express: 4.18.2 -> 4.19.1 (Low Risk)
    • moment: Abandoned. Migration: Replace with dayjs (+85% bundle savings)
    • lodash: CVE-2023-45133 (Critical). Fix: Upgrade to 4.17.21 Phased Plan: 1. Patch Criticals, 2. Minor Batches, 3. Major Migrations.

    What you get

    Identify and remediate high-risk security vulnerabilities in package treesEnsure legal compliance by flags for incompatible open-source licensesExecute phased dependency upgrades to minimize breaking changes and downtimeAssess library health metrics to replace unmaintained or deprecated packages

    About this skill

    Maintain a Healthier, More Secure Codebase

    Dependencies are the silent foundation of your application, but they can also be its greatest liability. Dependency Auditor is a specialized skill for senior engineers and DevOps professionals who need more than just a list of outdated packages. It provides a deep, multi-dimensional analysis of your project's ecosystem to identify risks before they reach production.

    Detailed Risk Assessment

    Unlike standard CLI tools, this skill analyzes five critical vectors:

    • Security: Identifies CVEs and provides specific fixed versions.
    • Maintenance Health: Flags abandoned packages, "bus factor" risks, and declining commit activity.
    • License Compliance: Audits for copyleft (GPL/AGPL) or missing licenses that pose legal risks.
    • Upgrade Risk: Categorizes updates by "Minor" (low risk) vs "Major" (migration required).
    • Bundle Impact: Identifies heavy JavaScript packages and suggests lighter alternatives (e.g., swapping Moment.js for Day.js).

    Actionable Migration Planning

    The output isn't just a report; it’s a phased execution strategy. You receive a prioritized upgrade order—securing vulnerabilities first, then batching minor updates, and finally providing detailed migration steps for major version jumps, including breaking change analysis and required peer-dependency updates.

    Supported Ecosystems

    Supports npm, yarn, pnpm (JavaScript/TypeScript), pip, poetry (Python), Cargo (Rust), Go modules, Composer (PHP), and Bundler (Ruby).

    How to install

    Drop the file into your AI Agent. Works with Claude, Cursor, ChatGPT, and 20+ more.

    Reviews

    No reviews yet

    Be one of the first to try it. Every listed skill passes our trust checks below.

    Security scanned

    Passed our 8-point scan before listing

    1 install

    Downloaded by developers to date

    30-day refund

    Not a fit? Get your money back

    Trust & safety

    Security scanned

    Verified clean 4 months ago

    Installs1
    Listed4 months ago

    Creator

    Founder of Agensi

    Frequently Asked Questions

    Popular in Security & Compliance