Install any skill in seconds. Free to start, no credit card required.
Get Started Free →Audit and manage dependencies across multi-language projects. Identifies vulnerabilities, license conflicts, transitive dependency risks, and safe-upgrade paths. Use when auditing third-party packages before release, investigating a CVE, planning a major version bump, or running a license-compliance review. Examples: 'audit our npm dependencies', 'do we have GPL contamination', 'plan the upgrade to React 19'.
.claude/skills/alirezarezvani-dependency-auditor/SKILL.md| Test case | Without → With | Effect | Δ tokens | Δ turns |
|---|---|---|---|---|
| case-01 | ✗→✓ | ▲ Improved | -29% | 0% |
| case-04 | ✗→✓ | ▲ Improved | 22% | 0% |
| case-05 | ✗→✓ | ▲ Improved | -14% | 0% |
| case-06 | ✗→✓ | ▲ Improved | -33% | 0% |
| case-07 | ✗→✓ | ▲ Improved | -35% | 0% |
> Skill Type: POWERFUL · Category: Engineering · Domain: Dependency Management & Security
Offline, deterministic dependency auditing across 8+ package ecosystems. The three scripts are pattern-matchers over manifests/lockfiles — they do not call live advisory APIs; pair their findings with npm audit / pip-audit / cargo audit for current CVE coverage.
bash# 1. Scan for vulnerabilities (built-in offline CVE pattern set; exit non-zero on high severity) python3 scripts/dep_scanner.py /path/to/project --format json --fail-on-high -o scan.json # 2. Check license compliance and conflicts python3 scripts/license_checker.py /path/to/project --policy strict --format json -o licenses.json # 3. Plan upgrades from the scanner's inventory python3 scripts/upgrade_planner.py scan.json --risk-threshold medium --timeline 90 --format json -o plan.json
Consume the outputs: scan.json findings drive which packages to pin/patch now; licenses.json conflicts go to the user as a legal-risk list; plan.json orders upgrades by risk with rollback notes. --quick-scan skips transitive deps; --security-only limits the plan to security fixes.
Verification loop: after applying upgrades, re-run step 1 and assert 0 high-severity findings before closing the audit.
| Language | Manifests parsed | |---|---| | JavaScript/Node | package.json, package-lock.json, yarn.lock | | Python | requirements.txt, pyproject.toml, Pipfile.lock, poetry.lock | | Go | go.mod, go.sum | | Rust | Cargo.toml, Cargo.lock | | Ruby | Gemfile, Gemfile.lock | | Java | pom.xml, gradle.lockfile | | PHP | composer.json, composer.lock | | C#/.NET | packages.config, project.assets.json |
The checker analyzes license inheritance through dependency chains and emits conflict pairs with remediation suggestions.
| Risk | Update type | Handling | |---|---|---| | Low | Patch, security fixes | Apply immediately | | Medium | Minor with new features | Batch into scheduled update | | High | Major version, API changes | Dedicated migration task + tests | | Critical | Known breaking changes | Planned migration with rollback procedure |
Prioritization: security patches > bug fixes > feature updates > major rewrites; deprecated features get immediate attention.
scripts/dep_scanner.py — multi-format parser; built-in offline vulnerability pattern set (~16 CVE patterns — a smoke layer, not a replacement for live advisories); transitive resolution from lockfiles; JSON + text output.scripts/license_checker.py — license detection from package metadata; compatibility matrix across 20+ license types; --policy permissive|strict; conflict detection with remediation.scripts/upgrade_planner.py — semver-based breaking-change prediction; risk-ordered migration plan with testing checklist and timeline estimation.Sample fixtures: test-project/ and test-inventory.json in this folder; expected shapes in expected_outputs/.
bash# Security gate in CI python3 scripts/dep_scanner.py . --format json --fail-on-high python3 scripts/license_checker.py . --policy strict --format json
See README.md for detailed usage and references/ for the vulnerability/license knowledge bases.
| Case | Status | Duration (ms) | Turns | Tokens | Tool calls | ||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Without | With | Δ | Without | With | Δ | Without | With | Δ | Without | With | Δ | ||
case-01 | fail→pass | 15,201 | 11,356 | -25% | 1 | 1 | 0% | 3,156 | 2,251 | -29% | 0 | 0 | — |
case-02 | fail→fail | 4,961 | 4,377 | -12% | 1 | 1 | 0% | 247 | 1,256 | +409% | 0 | 0 | — |
case-03 | fail→fail | 22,201 | 6,363 | -71% | 1 | 1 | 0% | 4,623 | 1,601 | -65% | 0 | 0 | — |
case-04 | fail→pass | 11,406 | 3,684 | -68% | 1 | 1 | 0% | 1,225 | 1,492 | +22% | 0 | 0 | — |
case-05 | fail→pass | 10,364 | 2,691 | -74% | 1 | 1 | 0% | 1,734 | 1,484 | -14% | 0 | 0 | — |
case-06 | fail→pass | 15,590 | 4,032 | -74% | 1 | 1 | 0% | 2,444 | 1,639 | -33% | 0 | 0 | — |
case-07 | fail→pass | 14,921 | 2,558 | -83% | 1 | 1 | 0% | 2,174 | 1,410 | -35% | 0 | 0 | — |
case-08 | pass→pass | 10,487 | 4,186 | -60% | 1 | 1 | 0% | 1,861 | 1,793 | -4% | 0 | 0 | — |
case-09 | fail→pass | 11,424 | 2,841 | -75% | 1 | 1 | 0% | 2,092 | 1,487 | -29% | 0 | 0 | — |
case-10 | pass→pass | 14,351 | 7,381 | -49% | 1 | 1 | 0% | 2,557 | 2,353 | -8% | 0 | 0 | — |
case-11 | fail→pass | 12,824 | 4,885 | -62% | 1 | 1 | 0% | 1,626 | 1,704 | +5% | 0 | 0 | — |
case-12 | pass→pass | 10,274 | 5,584 | -46% | 1 | 1 | 0% | 1,792 | 1,922 | +7% | 0 | 0 | — |
case-13 | pass→pass | 10,123 | 3,860 | -62% | 1 | 1 | 0% | 1,581 | 1,699 | +7% | 0 | 0 | — |
case-14 | pass→pass | 12,382 | 17,052 | +38% | 1 | 1 | 0% | 2,129 | 3,086 | +45% | 0 | 0 | — |
case-15 | pass→pass | 15,302 | 10,313 | -33% | 1 | 1 | 0% | 2,663 | 2,874 | +8% | 0 | 0 | — |
case-16 | pass→pass | 4,310 | 1,873 | -57% | 1 | 1 | 0% | 795 | 1,246 | +57% | 0 | 0 | — |
case-17 | fail→pass | 6,275 | 3,436 | -45% | 1 | 1 | 0% | 1,237 | 1,681 | +36% | 0 | 0 | — |
case-18 | fail→pass | 16,761 | 10,404 | -38% | 1 | 1 | 0% | 2,319 | 2,391 | +3% | 0 | 0 | — |
case-19 | pass→pass | 52,395 | 5,700 | -89% | 1 | 1 | 0% | 2,586 | 2,035 | -21% | 0 | 0 | — |
case-20 | fail→pass | 12,815 | 3,400 | -73% | 1 | 1 | 0% | 2,096 | 1,653 | -21% | 0 | 0 | — |
case-21 | fail→fail | 8,869 | 7,938 | -10% | 1 | 1 | 0% | 862 | 2,112 | +145% | 0 | 0 | — |
case-22 | fail→pass | 15,163 | 4,614 | -70% | 1 | 1 | 0% | 2,070 | 1,833 | -11% | 0 | 0 | — |
DecimalAI ran this skill against gemini-3.6-flash twice over the same eval suite — once with the skill loaded and once without — and compared the two runs case by case. 22 cases were attempted, and 20 counted toward the lift figure. The other 2 produced results that are not comparable between the two arms, so they are excluded from the headline rather than averaged into it. The headline lift of +50 percentage points is the difference between those two pass rates over the 20 comparable cases. 1 case got worse with the skill loaded, and it is included in that figure.
Without the skill loaded, the model failed this case. With it loaded, the same prompt on the same model passed. This is one improved case from the latest verified run; every case, including any that regressed, is in the table above.
Other measured skills in the registry, with their headline benchmark lift.