skills/dependency-vuln-report/SKILL.md
Runs dependency vulnerability scans and produces a complete report with exact installed versions, reason for risk, and remediation priority for each finding. Use when the user asks for dependency scan, npm audit, bun audit, package vulnerabilities, CVE review, or security status of dependencies.
npx skillsauth add razbakov/skills dependency-vuln-reportInstall this skill globally with one command. Works with Claude Code, Cursor, and Windsurf.
3 of 9 scanners reported clean
Some scanners were skipped, did not run, or reported a non-clean status. Review each row below.
Generate a vulnerability report where every finding includes:
Do not group findings in a way that hides individual vulnerable packages.
npm audit --omit=dev --json > /tmp/audit-prod.json
node -e 'const lock=require("./package-lock.json");const a=require("/tmp/audit-prod.json");const pkgs=lock.packages||{};for(const [name,v] of Object.entries(a.vulnerabilities||{})){const key=`node_modules/${name}`;console.log(`${name}|${pkgs[key]?.version||"unknown"}|${v.severity}|${v.isDirect?"direct":"transitive"}|${v.fixAvailable?"fix-available":"no-auto-fix"}`)}'
Assign one priority per finding:
P0: High/Critical in production runtime with no automatic fix, or severe exploitability in real app paths.P1: High in production with fix available.P2: Moderate direct production dependency, or high dev-only toolchain risk.P3: Moderate transitive risk.P4: Low severity.When uncertain, prefer the stricter priority and state the assumption.
Always include:
packageversion usedseveritydirect/transitivereasonpriorityfix availabilityEach reason must be one concrete sentence tied to the advisory class, for example:
Avoid vague reasons like "security issue exists."
Before finalizing:
tools
--- name: handoff description: Get an agent past a browser/UI wall it can't (or must not) cross on its own — a login-gated dashboard, a CAPTCHA, a 2FA prompt, an API that keeps rejecting the write, or an irreversible click that policy says a human must make. This skill is an ESCALATION LADDER, not a first move: it tells you to try the automated browser surfaces FIRST (Chrome-in-Claude, computer-use, an autonomous browser sub-agent) and only fall back to the Handoff app — a wrapper browser that h
documentation
Summarize one or more YouTube videos from their links. Use this whenever the user pastes a youtube.com or youtu.be URL (or several) and wants to know what it's about — phrasings like "summarize to telegram", "tldr these videos", "what do these say", "summary of this talk", or just dropping links with no instruction at all. Fetches each video's real transcript via yt-dlp (not the page text, which never contains the transcript), cleans the captions, and writes a per-video summary. Default delivery is Telegram; honor any other surface the user names ("to my notes", "just here in chat", "email it"). Trigger even when the user only pastes bare links — bare YouTube links almost always mean "tell me what's in these".
data-ai
Daily Digest — Chief-of-Staff role consolidates the six top-managers into one Telegram message to the Commander, instead of six. Implements the protocol from agent-proactivity.md.
development
Seed a new or empty Instagram account with a 9-post grid (3×3) so the profile looks established the moment a new visitor lands. Designed for festivals, new businesses, product launches, conferences, communities — any time an empty IG profile would hurt conversion from external traffic (QR scans, flyer drops, cross-promo). Generates assets via /image-from-gemini (per content-publishing rules — never HTML), writes captions with hashtag sets, and outputs a posting order + cadence plan. Trigger generously: phrases like '9 posts for instagram', 'fill my IG', 'starter grid', 'launch grid', 'instagram seed', '9-post grid', 'IG account not to look empty', 'first instagram posts', 'feed bootstrap', '3x3 grid', 'instagram launch content'. Even if the user mentions only one piece (just the images, just the captions, just the order), use this skill — the grid only works as an integrated bundle.