Dependency Audit

SkillDev tools

Decide whether to add, keep, or remove a dependency. Use before adding any package.

Available today. Use it from your connected AI after setup.

Connect ahel once, and every AI you use reads what you have installed.

Then ask your AI: use the Dependency Audit skill

What this skill tells your AI

The instructions your AI receives, as published by archive228/loopkit in skills/dependency-audit/SKILL.md and read by ahel’s review.

Before adding a package, ask:

  1. Can the stdlib do it? No lodash for Array.map. No left-pad-tier packages.
  2. Is it already in the tree? Don't add axios if the project uses fetch.
  3. Is it alive? Last commit, open issues, maintainer responsiveness.
  4. Cost? A 500KB dep to format a date isn't worth it. Check the install size and transitive deps.
  5. Security? Known CVEs? Postinstall scripts? When you do add one, justify it in the PR body. Never silently grow package.json. For existing deps: anything unused or one-function gets removed.

Signals

GitHub stars
755
Forks
125
Last commit
Jul 2026
Advanced
Catalog kind
skill
Gateway key
dependency-audit
Source
github.com/archive228/loopkit