Audits project dependencies for CVEs, outdated packages, and license compliance across npm, yarn, pnpm, pip, Go, and Cargo.
- What it does
- This skill guides an agent through a dependency audit: it detects the package manager from lockfiles, runs vulnerability scans, checks for outdated dependencies, and reviews license compliance. It produces a severity-ranked security report with CVE lists, upgrade distributions, risky licenses, and executable fix commands, using a bundled report template. It covers npm, yarn, pnpm, Go, Python, and Rust projects.
- When to use it
- Use it when someone wants to check dependency security, mentions CVE, vulnerability, or audit, asks about outdated dependencies, or invokes the dependency-audit command. It is not intended for version updates alone, code-level security review, runtime dependency analysis, deep license analysis, or Docker image scanning.
- Requirements
- Instructions only; no scripts ship with the skill. It relies on external audit tools that may need installation or network access: npm/yarn/pnpm audit, govulncheck, pip-audit, npm-check-updates, license-checker, and go-licenses, plus jq for parsing npm audit JSON output.
Dependency Audit
扫描项目依赖,检测安全漏洞、过时包和 license 合规问题。
Overview
全面审计项目依赖:CVE 漏洞扫描、过时依赖检测、license 合规检查、重复依赖分析。输出按严重程度排序的安全报告和可执行的修复命令。
When to Use
- User wants to check dependency security
- User mentions CVE, vulnerability, or audit
- User wants to know outdated dependencies
- User says "审计依赖" / "check dependencies"
- User inputs
/dependency-audit
When NOT to Use:
- User only wants to update versions
- User wants code-level security review
- User wants to analyze runtime dependencies
- User wants deep license analysis
- User wants to scan Docker images
Core Pattern
Step 1: 检测包管理器
Step 2: 漏洞扫描
核心命令(按包管理器分别执行,缺失工具自动跳过):
⚠️ npm audit 在发现漏洞时退出码非 0 —— 不要用 if npm audit ...; then 判断成功,直接解析 --json 输出:
输出:漏洞总数 + 按严重程度(critical/high/medium/low)分类的 CVE 列表。
Step 3: 过时依赖检测
核心命令(按包管理器分别执行,缺失工具自动跳过):
统计:过时依赖数量、major/minor/patch 升级分布、是否有安全相关更新。
Step 4: License 合规检查
核心命令(按包管理器分别执行):
检测重点:GPL/AGPL 等 copyleft 许可证、未知/自定义许可证、许可证兼容性。
Step 5: 生成报告
使用 templates/audit-report.md 模板,输出:
- 安全概览 — 漏洞数量和严重程度分布
- 高危漏洞 — 需要立即修复的 CVE
- 过时依赖 — 按升级难度排序
- License 合规 — 风险许可证列表
- 修复命令 — 每个问题附带可执行命令
Quick Reference
Common Mistakes