auditing-dependencies

Installation
SKILL.md

Security: Dependency Management

Purpose: Prevent security vulnerabilities through proper npm dependency auditing, updating, and monitoring.

When to use: Before adding new dependencies, during security reviews, when setting up CI/CD pipelines, or when package.json changes.

Critical Security Principle

Dependencies are attack vectors. Each package you add introduces potential vulnerabilities:

  • Direct vulnerabilities in the package code
  • Transitive dependencies (dependencies of dependencies)
  • Supply chain attacks (malicious package updates)
  • Unmaintained packages with known CVEs

Default stance: Minimize dependencies. Every package is a liability.

Dependency Audit Workflow

1. Check for Known Vulnerabilities

Related skills
Installs
4
First Seen
Feb 4, 2026