Works with the AI tools you already use

    Claude CodeClaude CodeCursorCursorCodex CLICodex CLIMuseMuseDotsDots+22 more

    Dependency Vuln Audit Skill

    1

    Audits dependencies for CVEs and supply-chain risks like typosquatting across Node, Python, Rust, and Go.

    $9.99

    Secure checkout via Stripe

    30-day refund guarantee

    Converts to your local currency at checkout

    Security scanned
    Dependency Vuln Audit Skill

    Dependency Vuln Audit Skill

    Example session with this skill installed

    Run a full dependency audit on this directory. I'm worried about the new packages added in the last commit and any transitive vulnerabilities in our existing stack.

    • Read your context and instructions
    • Compiled the dependency vuln audit
    • Generated the document

    I have completed a dependency and supply-chain audit for the detected Node.js and Python environments. I ran npm audit and pip-audit, then analyzed the manifests for supply-chain red flags.

    Dependency Security Audit Report

    Vulnerability Summary

    PackageVersionSeverityTypeFixed InRisk
    axios0.21.1HighDirect0.21.4SSRF Vulnerability
    glob-parent5.1.1MediumTransitive5.1.2Regular Expression Denial of Service
    requests2.25.0LowDirect2.25.1Information Leak via Proxy
    poython-dateutil2.8.1CriticalHeuristic-Typosquatting Risk (impersonating python-dateutil)

    Recommended Remediation Commands

    Run these commands to resolve the high-priority findings:

    
    # Update direct Node.js dependency
    npm install axios@0.21.4
    
    # Update direct Python dependency
    pip install --upgrade requests==2.25.1
    
    # ACTION REQUIRED: Remove potential malicious package
    pip uninstall poython-dateutil && pip install python-dateutil
    

    Supply-Chain Heuristics

    Typosquatting Alert: poython-dateutil was found in requirements.txt. This is a known high-risk naming pattern targeting python-dateutil.

    Install Scripts: preinstall script detected in node-sass-builder. Ensure this package is from a trusted internal or verified source.

    Abandoned Package: old-promise-poly has not been updated in 5 years. Consider replacing with native Promise or a maintained library.

    Next steps

    1. Immediately uninstall poython-dateutil and inspect the environment for unauthorized outbound traffic.
    2. Execute the npm install and pip install commands provided above to patch known CVEs.
    3. Review the node-sass-builder install script for any curl or bash execution.

    dependency-vuln-audit-skill.pdf

    PDF · document

    Generated

    Example file from a real run - the skill writes it into your workspace.

    Connects securely to your tools. The creator never sees your data.

    What you get

    Identify known CVEs using native ecosystem audit tools.Detect typosquatting and malicious naming patterns in manifests.Differentiate between direct and transitive dependency risks.Generate exact shell commands for patching identified vulnerabilities.

    About this skill

    The problem

    Native audit tools like npm audit or cargo audit only report known CVEs, leaving you blind to supply-chain risks like typosquatting or abandoned packages. Manually checking every transitive dependency in a deep tree for these red flags is impossible during a standard PR review.

    What it does

    • Detects project ecosystems and runs native audit tools (npm, pip, cargo, go, etc.) to fetch known CVEs.
    • Analyzes manifest files for supply-chain risks including install scripts, abandoned packages, and typosquatting.
    • Normalizes varying severity scales into a unified Critical/High/Medium/Low report.
    • Categorizes findings into direct vs. transitive dependencies to clarify the remediation path.
    • Generates exact CLI commands for every required version bump or override.

    Frameworks & tools

    Supports Node.js (npm, yarn, pnpm), Python (pip-audit), Rust (cargo audit), Go (govulncheck), Ruby (bundle audit), and PHP (composer audit).

    Why this beats prompting it yourself

    General LLMs often hallucinate version numbers or fail to differentiate between a direct dependency you control and a transitive one you don't. This skill executes real environment-aware tools and applies a specific supply-chain heuristic layer that standard prompts miss.

    Use cases

    • Pre-merge security checks on PRs that modify package-lock.json or requirements.txt.
    • Vetting a new package's supply-chain health before adding it to your production stack.
    • Generating a unified security report for polyglot repositories with multiple languages.

    Known limitations

    Requires native audit tools to be installed in the environment. It does not automatically modify lockfiles or run fix commands.

    How to install

    Works the same in every agent - Claude, Cursor, Codex, Copilot and 20+ more.

    ~30 seconds
    1. 1

      Download the ZIP

      Free skills download straight away. Paid skills unlock right after purchase.

    2. 2

      Unzip into your skills folder

      Every agent reads skills from one folder on your machine. Drop the unzipped folder in there.

    3. 3

      Ask your agent to use it

      Restart the agent if it was already running. It picks the skill up automatically - no config needed.

    Skills folder by agent

    Click the path to copy it. Create the folder if it does not exist yet.

    Reviews

    No reviews yet

    Be one of the first to try it. Every listed skill passes our trust checks below.

    Security scanned

    Passed our 8-point scan before listing

    Fresh listing

    Recently published to Agensi

    30-day refund

    Not a fit? Get your money back

    Trust & safety

    Security scanned

    Verified clean 15 days ago

    • Passed all security checks, Safe to install

    Listed15 days ago

    What's inside

    Frequently Asked Questions