Generates comprehensive vulnerability reports from npm audit JSON output and the OSV (Open Source Vulnerabilities) API. Parses npm audit --json results, enriches each CVE with CVSS scores from the NVD REST API, and groups findings by severity. Produces SARIF output compatible with GitHub Advanced Security.
Scanned 6/8/2026
Install via CLI
openskills install agentskillexchange/skills---
name: "npm Audit Dependency Report Generator"
slug: "npm-audit-dependency-report-generator"
description: "Generates comprehensive vulnerability reports from npm audit JSON output and the OSV (Open Source Vulnerabilities) API. Parses npm audit --json results, enriches each CVE with CVSS scores from the NVD REST API, and groups findings by severity. Produces SARIF output compatible with GitHub Advanced Security."
verification: "security_reviewed"
source: "https://docs.npmjs.com/cli/v10/commands/npm-audit/"
author: "npm, Inc."
category: "CI/CD Integrations"
framework: "Claude Agents"
---
# npm Audit Dependency Report Generator
Generates comprehensive vulnerability reports from npm audit JSON output and the OSV (Open Source Vulnerabilities) API. Parses npm audit --json results, enriches each CVE with CVSS scores from the NVD REST API, and groups findings by severity. Produces SARIF output compatible with GitHub Advanced Security.
## Installation
Use the upstream install or setup path that matches your environment:
- npm-audit | npm Docs Skip to search Skip to content
- npm Docs
- npm package scope, access level, and visibility
- Docker and private modules
Requirements and caveats from upstream:
- Downloading and installing Node.js and npm
- Try the latest stable version of node
- Creating Node.js modules
Basic usage or getting-started notes:
- Creating a strong password
- Receiving a one-time password over email
- About two-factor authentication
- Source: https://docs.npmjs.com/cli/v10/commands/npm-audit/
## Documentation
- https://docs.npmjs.com/cli/v10/commands/npm-audit/
## Source
- [Agent Skill Exchange](https://agentskillexchange.com/skills/npm-audit-dependency-report-generator/)
No comments yet. Be the first to comment!
Ultra-compressed communication mode. Cuts token usage ~75% by speaking like caveman while keeping full technical accuracy. Supports intensity levels: lite, full (default), ultra, wenyan-lite, wenyan-full, wenyan-ultra. Use when user says "caveman mode", "talk like caveman", "use caveman", "less tokens", "be brief", or invokes /caveman. Also auto-triggers when token efficiency is requested.