Vet, pin and update third-party dependencies deliberately.
Scanned 9/3/2026
Install to Claude Code
npx -y skills add Andersseen/agentyx --skill dependency-security --agent claude-codeInstalls into .claude/skills of the current project.
Are you the author of Dependency Security?
Add the live security badge to your README — it updates automatically with every re-scan.
[](https://www.skillsdirectory.com/skills/andersseen-dependency-security)More formats (shields.io, HTML) on the badges page.
---
name: dependency-security
description: Vet, pin and update third-party dependencies deliberately.
---
# Dependency security
Most code shipped in a modern application is code nobody on the team wrote. Treat adding a dependency
as a security decision.
## Vet before adding
Check maintenance activity, release history, install footprint and transitive dependency count. A
small utility that pulls in dozens of packages costs more than writing the function yourself.
## Pin and lock
Commit the lockfile and keep ranges narrow for anything security relevant. Reproducible installs are
what let you tell whether a change came from your code or from a dependency.
## Update on a schedule, not in panic
Apply security patches promptly and take routine updates in small regular batches. Large infrequent
upgrades are where breakage accumulates and where an urgent patch gets stuck behind unrelated
changes.
## Audit in CI
Fail the build on known critical vulnerabilities in the dependency tree. Review each advisory for
exploitability in your context before treating it as urgent.
## Beware install-time execution
Post-install scripts run with your permissions on developer machines and in CI. Disable them where
the toolchain allows, and know what remains enabled.
Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.
No comments yet. Be the first to comment!
Use this skill when developing or maintaining browser extension code in the `browser/` directory, including Chrome/Firefox/Edge compatibility, content scripts, background scripts, or i18n updates.
Official Google SEO guide covering search optimization, best practices, Search Console, crawling, indexing, and improving website search visibility based on official Google documentation
SEO optimization with keyword analysis, readability assessment, technical validation, content quality. Use for search rankings, blog posts, content audits, or encountering keyword density, readability scores, meta tags, schema markup errors.
Python backend development expertise for FastAPI, security patterns, database operations, Upstash integrations, and code quality. Use when: (1) Building REST APIs with FastAPI, (2) Implementing JWT/OAuth2 authentication, (3) Setting up SQLAlchemy/async databases, (4) Integrating Redis/Upstash caching, (5) Refactoring AI-generated Python code (deslopification), (6) Designing API patterns, or (7) Optimizing backend performance.
PTES-aligned adversarial security audit for backend, frontend, and mobile applications. Produces a CVSS-scored Hacker Report with verified PoCs and phased remediation.