Back to skills
SKILL.md
Dependency Audit
ASecurityVulnerability and licence audit for npm, pip and dotnet with an upgrade plan.
- 8 stars
- 0 votes
- 0 copies
- 0 views
- Added September 19, 2026
Security analysis
92/100- Installs packages at runtime which could introduce malicious dependencies
npx -y skills add Adilmunawar/ZD-claude-plugin --skill dependency-audit --agent claude-codeAre you the author of Dependency Audit?
Add the live security badge to your README. It updates with every re-scan.
[](https://www.skillsdirectory.com/skills/adilmunawar-dependency-audit)---
name: dependency-audit
disable-model-invocation: true
argument-hint: "[path]"
context: fork
allowed-tools: Read, Grep, Glob, Bash, Write
description: Vulnerability and licence audit for npm, pip and dotnet with an upgrade plan.
---
1. Detect: `package-lock.json`, `requirements.txt`/`pyproject.toml`, `*.csproj`.
2. Run: `npm audit --json --omit=dev`; `pip install pip-audit && pip-audit -r requirements.txt --format json`; `dotnet list package --vulnerable --include-transitive`; licences via `npx license-checker --summary` / `pip-licenses`.
3. Table: package, current, fixed-in, severity, direct/transitive, breaking?
4. Upgrade plan: safe patch/minor upgrades as one command; majors listed separately with the changelog link.
5. Flag copyleft licences (GPL/AGPL) in shipped code; note model/dataset licences for Hugging Face artefacts.
Attribution
Comments
Loading comments…