More screenshots
Works with the AI tools you already use
Dependency Health Check Pro
The free Dependency Health Check reads your lockfiles and flags stale packages.
$5
dependency-health-check-pro
Example session with this skill installed
Audit this monorepo before the v2.4 release. I need to know what is actually dangerous, not a linter dump.
- Read your context and instructions
- Compiled the dependency-health-check-pro
- Generated the data export
412 packages resolved. CRITICAL: lodash@4.17.15 CVE-2021-23337 (CVSS 9.8), minimist@1.2.5 CVE-2021-44906. HIGH: 3 deprecated packages. MEDIUM: gpl-3.0 license conflict. Upgrade order: lodash first (unblocks express-validator), minimist second, replace csv-parser with papaparse, replace request with axios.
dependency-health-check-pro.csv
CSV · data export
Example file from a real run - the skill writes it into your workspace.
Connects securely to your tools. The creator never sees your data.
What you get
About this skill
The free version tells you what's outdated. The Pro version scans CVEs, generates fix PRs, enforces license compliance, and runs in your CI pipeline.
Free vs Pro
The free check reads manifests and lockfiles and reports CVEs, staleness, and deprecations. Pro adds remediation: a prioritized upgrade order that respects transitive constraints, license compliance auditing with copyleft detection, CI-ready SARIF output, and maintenance-decay scoring weighted by dependency-tree depth. Free lists the problems — Pro sequences the fixes.
Upgrade Path
Free for the quarterly look; Pro when dependency fixes become a standing workstream or you need license compliance for enterprise distribution.
The Problem
The free Dependency Health Check reads your lockfiles and flags stale packages. But knowing something is outdated is step one — you also need to know which packages have known CVEs, which ones violate your license policy, and how to actually fix the chain without breaking transitive dependencies. The Pro version adds automated vulnerability scanning, update automation scripts, license compliance checking, and a CI integration that fails builds on critical advisories.
What You Get
- CVE vulnerability scanning — scans both direct and transitive dependencies against advisory databases, with severity ratings (Critical/High/Medium/Low) and minimum safe versions for each.
- Automated update scripts — generates a prioritized fix order that respects transitive constraints, with
git apply-ready patches for safe upgrades and manual review flags for major version bumps. - License compliance auditing — flags copyleft licenses (GPL, AGPL), unknown licenses, and conflicts with your project's allowed license list (configurable per project).
- Lockfile integrity checking — detects diverged lockfiles, floating ranges on production dependencies, and missing lockfiles across npm, yarn, pnpm, pip, poetry, Go, Cargo, and Maven.
- Maintenance decay scoring — ranks packages by staleness, repository archival status, and deprecation flags, weighted by depth in the dependency tree.
- CI-ready output — SARIF/JSON for GitHub Security tab integration, plus Markdown for PR comments. Fail the build on new Critical/High findings.
Why This Beats Prompting It Yourself
An LLM asked to "check my dependencies" reads your 30-line package.json, ignores the 4,000-line lockfile where the actual vulnerable packages live, and tells you to "keep dependencies updated." It invents CVE numbers, can't distinguish declared ranges from resolved versions, and hallucinates on packages it doesn't recognize. This skill reads lockfiles verbatim, cross-references against structured advisory data, and produces machine-readable output for CI.
Example Session
You: "Audit this monorepo before the v2.4 release. I need to know what's actually dangerous, not a linter dump."
**Agent:
412 packages resolved. CRITICAL: lodash@4.17.15 CVE-2021-23337 (CVSS 9.8), minimist@1.2.5 CVE-2021-44906. HIGH: 3 deprecated packages. MEDIUM: gpl-3.0 license conflict. Upgrade order: lodash first (unblocks express-validator), minimist second, replace csv-parser with papaparse, replace request with axios.
Use Cases
- Pre-release security sweep for monorepos with mixed package managers (npm + pip + Go).
- CI pipeline integration to fail builds on new CVE advisories.
- License compliance audit before open-sourcing a project or onboarding enterprise clients.
- Post-acquisition dependency audit of an inherited codebase.
- Quarterly dependency hygiene review across a portfolio of projects.
Known Limitations
Requires internet access to query CVE advisory databases. License detection is based on package metadata — some packages declare licenses incorrectly. The upgrade order algorithm handles direct dependencies and one level of transitive constraints; deeply nested dependency conflicts may need manual resolution. SARIF output is compatible with GitHub Security tab; other platforms may need format conversion.
How to install
Works the same in every agent - Claude, Cursor, Codex, Copilot and 20+ more.
- 1
Download the ZIP
Free skills download straight away. Paid skills unlock right after purchase.
- 2
Unzip into your skills folder
Every agent reads skills from one folder on your machine. Drop the unzipped folder in there.
- 3
Ask your agent to use it
Restart the agent if it was already running. It picks the skill up automatically - no config needed.
Skills folder by agent
Click the path to copy it. Create the folder if it does not exist yet.
Reviews
No reviews yet
Be one of the first to try it. Every listed skill passes our trust checks below.
Security scanned
Passed our 8-point scan before listing
Fresh listing
Recently published to Agensi
30-day refund
Not a fit? Get your money back
Trust & safety
Security scanned
Verified clean 2 months ago
- Passed all security checks, Safe to install