Dependency Auditor

SkillSecurity

This skill lets your AI check the outside packages your project relies on for known security vulnerabilities, license conflicts, and risky upgrades. It works across more than eight programming languages, so you can catch problems before a release, investigate a reported vulnerability, or plan a major version update.

Available today. Use it from your connected AI after setup.

After adding it, point your AI at a project and ask it to audit the dependencies, or ask it to look into a specific vulnerability you have heard about. It is especially useful before a release or when planning a major version bump.

Then ask your AI: use the Dependency Auditor skill

What your AI can do with it

  • Find known vulnerabilities in the packages your project uses
  • Flag license conflicts before they become compliance issues
  • Spot risks that come in through indirect dependencies
  • Recommend safe upgrade paths for outdated packages
  • Check projects written in more than eight languages
  • Investigate a specific reported vulnerability

What this skill tells your AI

The instructions your AI receives, as published by borghei/claude-skills in engineering/dependency-auditor/SKILL.md and read by ahel’s review.

Skill Type: POWERFUL · Category: Engineering · Domain: Dependency Management & Security

Offline, deterministic dependency auditing across 8+ package ecosystems. The three scripts are pattern-matchers over manifests/lockfiles — they do not call live advisory APIs; pair their findings with npm audit / pip-audit / cargo audit for current CVE coverage.

Quick Start

# 1. Scan for vulnerabilities (built-in offline CVE pattern set; exit non-zero on high severity)
python3 scripts/dep_scanner.py /path/to/project --format json --fail-on-high -o scan.json

# 2. Check license compliance and conflicts
python3 scripts/license_checker.py /path/to/project --policy strict --format json -o licenses.json

# 3. Plan upgrades from the scanner's inventory
python3 scripts/upgrade_planner.py scan.json --risk-threshold medium --timeline 90 --format json -o plan.json

Consume the outputs: scan.json findings drive which packages to pin/patch now; licenses.json conflicts go to the user as a legal-risk list; plan.json orders upgrades by risk with rollback notes. --quick-scan skips transitive deps; --security-only limits the plan to security fixes.

Verification loop: after applying upgrades, re-run step 1 and assert 0 high-severity findings before closing the audit.

Supported Ecosystems

LanguageManifests parsed
JavaScript/Nodepackage.json, package-lock.json, yarn.lock
Pythonrequirements.txt, pyproject.toml, Pipfile.lock, poetry.lock
Gogo.mod, go.sum
RustCargo.toml, Cargo.lock
RubyGemfile, Gemfile.lock
Javapom.xml, gradle.lockfile
PHPcomposer.json, composer.lock
C#/.NETpackages.config, project.assets.json

License Classification

  • Permissive: MIT, Apache 2.0, BSD (2/3-clause), ISC
  • Copyleft (strong): GPL v2/v3, AGPL v3 — flags contamination risk in permissive projects
  • Copyleft (weak): LGPL v2.1/v3, MPL 2.0
  • Proprietary / Dual / Unknown — unknown licenses are surfaced for manual review

The checker analyzes license inheritance through dependency chains and emits conflict pairs with remediation suggestions.

Upgrade Risk Matrix

RiskUpdate typeHandling
LowPatch, security fixesApply immediately
MediumMinor with new featuresBatch into scheduled update
HighMajor version, API changesDedicated migration task + tests
CriticalKnown breaking changesPlanned migration with rollback procedure

Prioritization: security patches > bug fixes > feature updates > major rewrites; deprecated features get immediate attention.

Scripts (accurate capability claims)

  • scripts/dep_scanner.py — multi-format parser; built-in offline vulnerability pattern set (~16 CVE patterns — a smoke layer, not a replacement for live advisories); transitive resolution from lockfiles; JSON + text output.
  • scripts/license_checker.py — license detection from package metadata; compatibility matrix across 20+ license types; --policy permissive|strict; conflict detection with remediation.
  • scripts/upgrade_planner.py — semver-based breaking-change prediction; risk-ordered migration plan with testing checklist and timeline estimation.

Sample fixtures: test-project/ and test-inventory.json in this folder; expected shapes in expected_outputs/.

CI Integration

# Security gate in CI
python3 scripts/dep_scanner.py . --format json --fail-on-high
python3 scripts/license_checker.py . --policy strict --format json

Best Practices

  1. Prioritize security: address high/critical findings immediately; license compliance before functionality.
  2. Gradual updates: incremental upgrades with thorough testing; feature flags for risky bumps.
  3. Cadence: security scans per commit; license audits monthly; full audit quarterly.
  4. False positives: whitelist with documentation; contact maintainers for license ambiguity.

See README.md for detailed usage and references/ for the vulnerability/license knowledge bases.

Signals

GitHub stars
740
Forks
135
Last commit
Aug 2026
Advanced
Catalog kind
skill
Gateway key
dependency-auditor
Source
github.com/borghei/claude-skills