{"slug":"jeremylongshore-auditing-npm-dependencies","source_name":"jeremylongshore/auditing-npm-dependencies","name":"Jeremylongshore/Auditing npm Dependencies","description":"Audit a Node.js project's installed npm dependency tree for known\nCVEs by wrapping the npm audit JSON output and emitting findings in\nthe canonical penetration-tester schema. Detects direct AND transitive\nvulnerabilities, normalizes npm's severity scale (info/low/moderate/\nhigh/critical) to the shared Severity enum, and parses both v1 and\nv2 audit output formats so the skill works against npm 6 and npm\n7+ lockfiles.\nUse when: pre-merge gate on a Node project, post-incident sweep\nafter a transiti","version":1,"lift":{"pass_rate_delta_pts":50,"pass_rate_pct":77.3,"total_cases":22,"passed_cases":17,"tokens_delta_pct":75.2,"turns_delta_pct":0,"verdict":"mixed","benchmark_model":"gemini-3.6-flash","grading_method":"judged","completed_at":"2026-08-13T03:02:58.495186+00:00"},"skill_score":0.7727,"benchmark_models":[{"model":"gemini-3.6-flash","headline":true,"delta_pts":50,"with_pass_pct":77.3,"without_pass_pct":27.3,"tokens_delta_pct":75.2,"turns_delta_pct":0,"total_cases":22,"cases_aggregated":19,"verdict":"mixed","never_hurt":false,"completed_at":"2026-08-13T03:02:58.495186+00:00","run_id":"cab5b2e7-a6d4-4010-8027-6e0a4f69eecf","version_number":1,"is_latest_version":true,"gate":null}],"trust":{"skill_safety":"passed","safety_status":"clean","intent_verdict":"safe","content_status":"clean","indexable":true},"license":"MIT","install_count":0,"manifest_hash":"42b4d7b8ee6be8486484a33aad665f968e718773710d4c463b1c642a3e3a0d68","raw_url":"https://app.decimal.ai/s/jeremylongshore-auditing-npm-dependencies/SKILL.md","scorecard_url":"https://app.decimal.ai/skills/jeremylongshore-auditing-npm-dependencies"}