More screenshots
Works with the AI tools you already use
Dependency Health Check
Your Go project's `go.mod` references `golang.org/x/crypto v0.17.0`. The current version is `v0.31.0`.
Free
dependency-health-check
Example session with this skill installed
"Audit dependency health for this monorepo — it's Node.js + Python + Go"
- Read your context and instructions
- Compiled the dependency-health-check
- Generated the document
DEPENDENCY HEALTH REPORT
════════════════════════
Manifests detected: 3 ecosystems, 5 manifests
Scan date: 2026-09-21
CRITICAL (2)
────────────
Package Ecosystem Current Latest Notes
─────────────────── ───────── ─────── ─────── ─────────────────────────────────────────────
golang.org/x/crypto Go v0.17.0 v0.31.0 CVE-2024-45337 (CVSS 9.1) — auth bypass
requests pip 2.28.1 2.32.3 CVE-2024-35195 (CVSS 7.5) — cert verification
bypass
WARNING (4)
───────────
Package Ecosystem Current Latest Notes
───────────── ───────── ─────── ────── ──────────────────────
express npm 4.18.2 5.0.1 1 major version behind
pydantic poetry 1.10.12 2.9.2 1 major version behind
gin-gonic/gin Go 1.9.0 1.10.0 1 minor version behind
INFO (3)
────────
Package Ecosystem Current Latest Notes
────────── ───────── ─────── ────── ───────────────────────
typescript npm 5.3.3 5.6.3 3 minor versions behind
py
dependency-health-check.pdf
PDF · document
Example file from a real run - the skill writes it into your workspace.
Connects securely to your tools. The creator never sees your data.
About this skill
The Problem
Your Go project's go.mod references golang.org/x/crypto v0.17.0. The current version is v0.31.0. Between those versions, CVE-2024-45337 was patched — a critical authentication bypass. Your dependency checker (if you have one) only runs on package.json and ignores Go entirely. Six months later, a penetration test flags the vulnerability. You spend a sprint upgrading, backporting fixes, and explaining to the security team why a known CVE sat in your dependency tree for half a year. The fix: scan all your dependency manifests, not just the ones you remember to check.
What You Get
- Auto-detect all package managers — scan the project tree for npm, yarn, pnpm, pip, poetry, Go modules, Cargo, Bundler, and Maven manifests using content sniffing, not filename guessing
- Check for known CVEs using ecosystem-specific tools —
npm audit,pip-audit,govulncheck,cargo audit,bundle audit— with fallback to reference tables when CLI tools aren't available - Classify findings by severity — Critical (CVE CVSS >= 7.0, officially deprecated, unmaintained 12+ months), Warning (>= 1 major version behind, CVSS < 7.0), Info (>= 1 minor version behind, devDependency outdated)
- Detect version conflicts across workspaces — flag when
package.jsonin root pins v5.2.0 but a sub-package requires v5.3.0, or whengo.modhasreplacedirectives masking incompatibilities - Produce a machine-readable report — every row includes package name, current version, latest version, severity tier, and specific notes about why it was flagged
- Stay read-only — never modify manifest files, lockfiles, or any project source. The skill scans and reports; you decide what to upgrade
Why This Beats Prompting It Yourself
You can ask an agent "check my dependencies" and it will run npm audit if you have a package.json. But it won't also scan your go.mod, Cargo.toml, and pom.xml in the same pass. It won't cross-reference requirements.txt against known advisory tables when pip-audit isn't installed. It won't detect that two workspaces pin conflicting versions of the same library. This skill runs a systematic 5-step process across all nine supported ecosystems, producing a unified report regardless of what languages your project uses.
Example Session
You: "Audit dependency health for this monorepo — it's Node.js + Python + Go"
Agent:
DEPENDENCY HEALTH REPORT
════════════════════════
Manifests detected: 3 ecosystems, 5 manifests
Scan date: 2026-09-21
CRITICAL (2)
────────────
Package Ecosystem Current Latest Notes
─────────────────── ───────── ─────── ─────── ─────────────────────────────────────────────
golang.org/x/crypto Go v0.17.0 v0.31.0 CVE-2024-45337 (CVSS 9.1) — auth bypass
requests pip 2.28.1 2.32.3 CVE-2024-35195 (CVSS 7.5) — cert verification
bypass
WARNING (4)
───────────
Package Ecosystem Current Latest Notes
───────────── ───────── ─────── ────── ──────────────────────
express npm 4.18.2 5.0.1 1 major version behind
pydantic poetry 1.10.12 2.9.2 1 major version behind
gin-gonic/gin Go 1.9.0 1.10.0 1 minor version behind
INFO (3)
────────
Package Ecosystem Current Latest Notes
────────── ───────── ─────── ────── ───────────────────────
typescript npm 5.3.3 5.6.3 3 minor versions behind
py
Use Cases
- Starting work on an unfamiliar codebase — assess dependency debt before making changes
- Pre-merge PR review — validate that dependency version bumps don't introduce CVEs
- Routine security audits — scheduled scans of all project manifests
- Monorepo maintenance — detect cross-workspace version conflicts
- Pre-deployment security gates — block deploys with Critical CVEs in dependency tree
- Evaluating upgrade feasibility — see which packages are major versions behind before planning migration work
Known Limitations
Read-only scanning cannot fix vulnerabilities — upgrades require manual intervention with testing. CVE databases lag behind discoverability — a dependency may have undisclosed vulnerabilities. Lockfile analysis requires the lockfile to be present and committed. Cross-manifest version conflict detection works for monorepos but not for independently deployed microservices with separate dependency trees.
Upgrade to Pro
Free lists CVEs, staleness, and deprecations. Dependency Health Check Pro ($5) sequences the fixes: transitive-aware upgrade order, license compliance, SARIF output, and decay scoring. Upgrade when dependency work is a standing task — Pro version.
How to install
Works the same in every agent - Claude, Cursor, Codex, Copilot and 20+ more.
- 1
Download the ZIP
Free skills download straight away. Paid skills unlock right after purchase.
- 2
Unzip into your skills folder
Every agent reads skills from one folder on your machine. Drop the unzipped folder in there.
- 3
Ask your agent to use it
Restart the agent if it was already running. It picks the skill up automatically - no config needed.
Skills folder by agent
Click the path to copy it. Create the folder if it does not exist yet.
Reviews
No reviews yet
Be one of the first to try it. Every listed skill passes our trust checks below.
Security scanned
Passed our 8-point scan before listing
11 installs
Downloaded by developers to date
Free forever
No account required to browse
Trust & safety
Security scanned
Verified clean 4 months ago
- Free to download with an account