plugins/security-audit/skills/scanning-dependencies/SKILL.md
Scan project dependencies for vulnerabilities, license issues, and supply chain risks. Use when auditing third-party packages or before releases.
npx skillsauth add qte77/claude-code-utils scanning-dependenciesInstall this skill globally with one command. Works with Claude Code, Cursor, and Windsurf.
3 of 9 scanners reported clean
Some scanners were skipped, did not run, or reported a non-clean status. Review each row below.
Scope: $ARGUMENTS
| Ecosystem | Manifest | Lock File | Scanner Command |
|-----------|----------|-----------|-----------------|
| Node.js | package.json | package-lock.json | npm audit --json |
| Python | pyproject.toml / requirements.txt | uv.lock / requirements.txt | pip-audit --format=json |
| Rust | Cargo.toml | Cargo.lock | cargo audit --json |
| Go | go.mod | go.sum | govulncheck ./... |
| # | Package | Version | CVE | Severity | Fix Version | Direct/Transitive |
|---|---------|---------|-----|----------|-------------|-------------------|
| 1 | lodash | 4.17.20 | CVE-2021-23337 | High | 4.17.21 | Direct |
| 2 | py-yaml | 5.4.0 | CVE-2020-14343 | Critical | 5.4.1 | Transitive |
| License | Count | Packages | Compatible |
|---------|-------|----------|------------|
| MIT | 42 | ... | Yes |
| GPL-3.0 | 1 | foo-lib | Review |
development
Analyzes industry websites for design patterns, layout, typography, and content strategies using first-principles thinking. Use when researching website design, UI patterns, or competitive design analysis.
development
Audits website usability for UX optimization, covering forms, navigation, validation, and microcopy. Use when reviewing user experience, task completion flows, or interface friction points.
development
Audits website accessibility for WCAG 2.1 AA compliance, generating findings and code fixes. Use when reviewing accessibility, keyboard navigation, screen reader compatibility, or inclusive design.
development
Writes tests following TDD (using vitest and @testing-library/react) best practices. Use when writing unit tests, integration tests, or component tests in TypeScript.