Works with the AI tools you already use

    Claude CodeClaude CodeCursorCursorCodex CLICodex CLIGitHub CopilotGitHub CopilotGemini CLIGemini CLI+20 more

    Dependency vulnerability auditor

    1

    Audits project dependencies for CVEs, license compliance risks, and supply-chain attacks.

    $6.99

    Secure checkout via Stripe

    30-day refund guarantee

    Converts to your local currency at checkout

    0 installsSecurity scanned
    Dependency vulnerability auditor

    Dependency vulnerability auditor

    Example session with this skill installed

    I am adding 'lodahs' to my package.json for a commercial web app. Can you check if this is safe? Here is the file: {"dependencies": {"lodahs": "^4.17.21"}}

    • Read your context and instructions
    • Compiled the dependency vulnerability auditor

    WARNING: 'lodahs' is a known typosquatting pattern for the popular 'lodash' library. This is a high-risk supply-chain red flag. Additionally, without a lockfile, the exact version resolved is non-deterministic. Recommendation: Remove 'lodahs' and install the official 'lodash' package instead.

    Connects securely to your tools. The creator never sees your data.

    What you get

    Identify AGPL/GPL license risks in commercial repositories.Detect typosquatting and malicious postinstall scripts in manifests.Prioritize CVEs based on fix availability and reachable code paths.Audit manifest files across Node, Python, Ruby, and Go ecosystems.

    About this skill

    The problem

    Dependency audits usually return a wall of version numbers without actual risk context. Developers often miss legal landmines like copyleft licenses or supply-chain red flags that haven't triggered a CVE yet.

    What it does

    • Analyzes package.json, requirements.txt, Gemfile, and go.mod files for security gaps.
    • Identifies license contamination risks, specifically flagging AGPL/GPL dependencies in commercial projects.
    • Detects supply-chain red flags such as typosquatting patterns and suspicious postinstall scripts.
    • Prioritizes vulnerabilities based on reachability and fix availability rather than just severity scores.

    Frameworks & tools

    Supports Node.js (npm, yarn, pnpm), Python (pip, poetry), Ruby (Bundler), and Go. Integrates with osv-scanner, npm audit, and pip-audit output.

    Why this beats prompting it yourself

    General LLMs often hallucinate CVE numbers or provide outdated vulnerability data. This skill follows a strict protocol to use authoritative local tools and focuses on structural risks, like license shifts and mutable git dependencies, that basic prompts overlook.

    Use cases

    • Reviewing a pull request that adds new, unfamiliar third-party packages.
    • Performing a license compliance sweep before a commercial product release.
    • Investigating suspicious package behavior or potential typosquatting.
    • Hardening supply-chain security by moving from branch-based to SHA-based pins.

    Known limitations

    Cannot perform live registry lookups. Analysis accuracy is significantly lower if a lockfile is not provided alongside the manifest.

    How to install

    Works the same in every agent - Claude, Cursor, Codex, Copilot and 20+ more.

    ~30 seconds
    1. 1

      Download the ZIP

      Free skills download straight away. Paid skills unlock right after purchase.

    2. 2

      Unzip into your skills folder

      Every agent reads skills from one folder on your machine. Drop the unzipped folder in there.

    3. 3

      Ask your agent to use it

      Restart the agent if it was already running. It picks the skill up automatically - no config needed.

    Skills folder by agent

    Click the path to copy it. Create the folder if it does not exist yet.

    Reviews

    No reviews yet

    Be one of the first to try it. Every listed skill passes our trust checks below.

    Security scanned

    Passed our 8-point scan before listing

    Fresh listing

    Recently published to Agensi

    30-day refund

    Not a fit? Get your money back

    Trust & safety

    Security scanned

    Verified clean 1 month ago

    • Passed all security checks, Safe to install

    Listed1 month ago
    Updated23 days ago

    What's inside

    Frequently Asked Questions