audit-dependencies
Audit every software dependency and supply-chain input in a repository, including direct and transitive packages, nested projects and workspaces, build plugins, CI actions, container images, vendored code, submodules, and runtime-loaded extensions. Use for dependency or package reviews; before adding, installing, upgrading, replacing, or removing dependencies; when manifests or lockfiles change; or when checking exact resolved versions, vulnerabilities, provenance, integrity, licenses, malicious packages, dependency confusion, maintainer risk, or supply-chain attacks. Do not use for broad source-code audits unrelated to dependencies.
Pinned to revision 680d339b0581, so it is the text this page describes rather than whatever the author pushed since.
Files
- skills/audit-dependencies/SKILL.md
- skills/audit-dependencies/agents/openai.yaml
- skills/audit-dependencies/references/ecosystem-evidence.md
- skills/audit-dependencies/references/supply-chain-signals.md
- skills/audit-dependencies/scripts/inventory_dependency_files.py
Every link opens the file at its source, pinned to the revision this page describes.