More screenshots

    Works with the AI tools you already use

    Claude CodeClaude CodeCursorCursorCodex CLICodex CLIGitHub CopilotGitHub CopilotGemini CLIGemini CLI+20 more

    Dependency Health Check

    2

    Your Go project's `go.mod` references `golang.org/x/crypto v0.17.0`. The current version is `v0.31.0`.

    Free

    11 installsSecurity scanned
    dependency-health-check

    dependency-health-check

    Example session with this skill installed

    "Audit dependency health for this monorepo — it's Node.js + Python + Go"

    • Read your context and instructions
    • Compiled the dependency-health-check
    • Generated the document

    DEPENDENCY HEALTH REPORT
    ════════════════════════

    Manifests detected: 3 ecosystems, 5 manifests
    Scan date: 2026-09-21

    CRITICAL (2)
    ────────────
    Package Ecosystem Current Latest Notes
    ─────────────────── ───────── ─────── ─────── ─────────────────────────────────────────────
    golang.org/x/crypto Go v0.17.0 v0.31.0 CVE-2024-45337 (CVSS 9.1) — auth bypass
    requests pip 2.28.1 2.32.3 CVE-2024-35195 (CVSS 7.5) — cert verification
    bypass

    WARNING (4)
    ───────────
    Package Ecosystem Current Latest Notes
    ───────────── ───────── ─────── ────── ──────────────────────
    express npm 4.18.2 5.0.1 1 major version behind
    pydantic poetry 1.10.12 2.9.2 1 major version behind
    gin-gonic/gin Go 1.9.0 1.10.0 1 minor version behind

    INFO (3)
    ────────
    Package Ecosystem Current Latest Notes
    ────────── ───────── ─────── ────── ───────────────────────
    typescript npm 5.3.3 5.6.3 3 minor versions behind
    py

    dependency-health-check.pdf

    PDF · document

    Generated

    Example file from a real run - the skill writes it into your workspace.

    Connects securely to your tools. The creator never sees your data.

    About this skill

    The Problem

    Your Go project's go.mod references golang.org/x/crypto v0.17.0. The current version is v0.31.0. Between those versions, CVE-2024-45337 was patched — a critical authentication bypass. Your dependency checker (if you have one) only runs on package.json and ignores Go entirely. Six months later, a penetration test flags the vulnerability. You spend a sprint upgrading, backporting fixes, and explaining to the security team why a known CVE sat in your dependency tree for half a year. The fix: scan all your dependency manifests, not just the ones you remember to check.

    What You Get

    • Auto-detect all package managers — scan the project tree for npm, yarn, pnpm, pip, poetry, Go modules, Cargo, Bundler, and Maven manifests using content sniffing, not filename guessing
    • Check for known CVEs using ecosystem-specific tools — npm audit, pip-audit, govulncheck, cargo audit, bundle audit — with fallback to reference tables when CLI tools aren't available
    • Classify findings by severity — Critical (CVE CVSS >= 7.0, officially deprecated, unmaintained 12+ months), Warning (>= 1 major version behind, CVSS < 7.0), Info (>= 1 minor version behind, devDependency outdated)
    • Detect version conflicts across workspaces — flag when package.json in root pins v5.2.0 but a sub-package requires v5.3.0, or when go.mod has replace directives masking incompatibilities
    • Produce a machine-readable report — every row includes package name, current version, latest version, severity tier, and specific notes about why it was flagged
    • Stay read-only — never modify manifest files, lockfiles, or any project source. The skill scans and reports; you decide what to upgrade

    Why This Beats Prompting It Yourself

    You can ask an agent "check my dependencies" and it will run npm audit if you have a package.json. But it won't also scan your go.mod, Cargo.toml, and pom.xml in the same pass. It won't cross-reference requirements.txt against known advisory tables when pip-audit isn't installed. It won't detect that two workspaces pin conflicting versions of the same library. This skill runs a systematic 5-step process across all nine supported ecosystems, producing a unified report regardless of what languages your project uses.

    Example Session

    You: "Audit dependency health for this monorepo — it's Node.js + Python + Go"

    Agent:

    DEPENDENCY HEALTH REPORT
    ════════════════════════
    
    Manifests detected: 3 ecosystems, 5 manifests
    Scan date: 2026-09-21
    
    CRITICAL (2)
    ────────────
    Package              Ecosystem  Current  Latest   Notes
    ───────────────────  ─────────  ───────  ───────  ─────────────────────────────────────────────
    golang.org/x/crypto  Go         v0.17.0  v0.31.0  CVE-2024-45337 (CVSS 9.1) — auth bypass
    requests             pip        2.28.1   2.32.3   CVE-2024-35195 (CVSS 7.5) — cert verification
                                                      bypass
    
    WARNING (4)
    ───────────
    Package        Ecosystem  Current  Latest  Notes
    ─────────────  ─────────  ───────  ──────  ──────────────────────
    express        npm        4.18.2   5.0.1   1 major version behind
    pydantic       poetry     1.10.12  2.9.2   1 major version behind
    gin-gonic/gin  Go         1.9.0    1.10.0  1 minor version behind
    
    INFO (3)
    ────────
    Package     Ecosystem  Current  Latest  Notes
    ──────────  ─────────  ───────  ──────  ───────────────────────
    typescript  npm        5.3.3    5.6.3   3 minor versions behind
    py
    

    Use Cases

    • Starting work on an unfamiliar codebase — assess dependency debt before making changes
    • Pre-merge PR review — validate that dependency version bumps don't introduce CVEs
    • Routine security audits — scheduled scans of all project manifests
    • Monorepo maintenance — detect cross-workspace version conflicts
    • Pre-deployment security gates — block deploys with Critical CVEs in dependency tree
    • Evaluating upgrade feasibility — see which packages are major versions behind before planning migration work

    Known Limitations

    Read-only scanning cannot fix vulnerabilities — upgrades require manual intervention with testing. CVE databases lag behind discoverability — a dependency may have undisclosed vulnerabilities. Lockfile analysis requires the lockfile to be present and committed. Cross-manifest version conflict detection works for monorepos but not for independently deployed microservices with separate dependency trees.

    Upgrade to Pro

    Free lists CVEs, staleness, and deprecations. Dependency Health Check Pro ($5) sequences the fixes: transitive-aware upgrade order, license compliance, SARIF output, and decay scoring. Upgrade when dependency work is a standing task — Pro version.

    How to install

    Works the same in every agent - Claude, Cursor, Codex, Copilot and 20+ more.

    ~30 seconds
    1. 1

      Download the ZIP

      Free skills download straight away. Paid skills unlock right after purchase.

    2. 2

      Unzip into your skills folder

      Every agent reads skills from one folder on your machine. Drop the unzipped folder in there.

    3. 3

      Ask your agent to use it

      Restart the agent if it was already running. It picks the skill up automatically - no config needed.

    Skills folder by agent

    Click the path to copy it. Create the folder if it does not exist yet.

    Reviews

    No reviews yet

    Be one of the first to try it. Every listed skill passes our trust checks below.

    Security scanned

    Passed our 8-point scan before listing

    11 installs

    Downloaded by developers to date

    Free forever

    No account required to browse

    Trust & safety

    Security scanned

    Verified clean 4 months ago

    • Free to download with an account

    Listed4 months ago
    Updated9 days ago

    What's inside

    Frequently Asked Questions