Works with the AI tools you already use
Dependency Vuln Audit Skill
Audits dependencies for CVEs and supply-chain risks like typosquatting across Node, Python, Rust, and Go.
$9.99
Dependency Vuln Audit Skill
Example session with this skill installed
Run a full dependency audit on this directory. I'm worried about the new packages added in the last commit and any transitive vulnerabilities in our existing stack.
- Read your context and instructions
- Compiled the dependency vuln audit
- Generated the document
I have completed a dependency and supply-chain audit for the detected Node.js and Python environments. I ran npm audit and pip-audit, then analyzed the manifests for supply-chain red flags.
Dependency Security Audit Report
Vulnerability Summary
| Package | Version | Severity | Type | Fixed In | Risk |
|---|---|---|---|---|---|
axios | 0.21.1 | High | Direct | 0.21.4 | SSRF Vulnerability |
glob-parent | 5.1.1 | Medium | Transitive | 5.1.2 | Regular Expression Denial of Service |
requests | 2.25.0 | Low | Direct | 2.25.1 | Information Leak via Proxy |
poython-dateutil | 2.8.1 | Critical | Heuristic | - | Typosquatting Risk (impersonating python-dateutil) |
Recommended Remediation Commands
Run these commands to resolve the high-priority findings:
# Update direct Node.js dependency
npm install axios@0.21.4
# Update direct Python dependency
pip install --upgrade requests==2.25.1
# ACTION REQUIRED: Remove potential malicious package
pip uninstall poython-dateutil && pip install python-dateutil
Supply-Chain Heuristics
Typosquatting Alert: poython-dateutil was found in requirements.txt. This is a known high-risk naming pattern targeting python-dateutil.
Install Scripts: preinstall script detected in node-sass-builder. Ensure this package is from a trusted internal or verified source.
Abandoned Package: old-promise-poly has not been updated in 5 years. Consider replacing with native Promise or a maintained library.
Next steps
- Immediately uninstall
poython-dateutiland inspect the environment for unauthorized outbound traffic. - Execute the
npm installandpip installcommands provided above to patch known CVEs. - Review the
node-sass-builderinstall script for anycurlorbashexecution.
dependency-vuln-audit-skill.pdf
PDF · document
Example file from a real run - the skill writes it into your workspace.
Connects securely to your tools. The creator never sees your data.
What you get
About this skill
The problem
Native audit tools like npm audit or cargo audit only report known CVEs, leaving you blind to supply-chain risks like typosquatting or abandoned packages. Manually checking every transitive dependency in a deep tree for these red flags is impossible during a standard PR review.
What it does
- Detects project ecosystems and runs native audit tools (npm, pip, cargo, go, etc.) to fetch known CVEs.
- Analyzes manifest files for supply-chain risks including install scripts, abandoned packages, and typosquatting.
- Normalizes varying severity scales into a unified Critical/High/Medium/Low report.
- Categorizes findings into direct vs. transitive dependencies to clarify the remediation path.
- Generates exact CLI commands for every required version bump or override.
Frameworks & tools
Supports Node.js (npm, yarn, pnpm), Python (pip-audit), Rust (cargo audit), Go (govulncheck), Ruby (bundle audit), and PHP (composer audit).
Why this beats prompting it yourself
General LLMs often hallucinate version numbers or fail to differentiate between a direct dependency you control and a transitive one you don't. This skill executes real environment-aware tools and applies a specific supply-chain heuristic layer that standard prompts miss.
Use cases
- Pre-merge security checks on PRs that modify
package-lock.jsonorrequirements.txt. - Vetting a new package's supply-chain health before adding it to your production stack.
- Generating a unified security report for polyglot repositories with multiple languages.
Known limitations
Requires native audit tools to be installed in the environment. It does not automatically modify lockfiles or run fix commands.
How to install
Works the same in every agent - Claude, Cursor, Codex, Copilot and 20+ more.
- 1
Download the ZIP
Free skills download straight away. Paid skills unlock right after purchase.
- 2
Unzip into your skills folder
Every agent reads skills from one folder on your machine. Drop the unzipped folder in there.
- 3
Ask your agent to use it
Restart the agent if it was already running. It picks the skill up automatically - no config needed.
Skills folder by agent
Click the path to copy it. Create the folder if it does not exist yet.
Reviews
No reviews yet
Be one of the first to try it. Every listed skill passes our trust checks below.
Security scanned
Passed our 8-point scan before listing
Fresh listing
Recently published to Agensi
30-day refund
Not a fit? Get your money back
Trust & safety
Security scanned
Verified clean 15 days ago
- Passed all security checks, Safe to install