Dependency Risk Assessor

$2.99Official

Use when adding, upgrading, or auditing third-party packages: judge vulnerabilities, maintenance health, and supply-chain risk before they ship.

securitysecuritydependenciessupply-chainvulnerabilitiessbomlicensingยท by SkillingMain

What you get

  • โœ“10-step procedure
  • โœ“1 ready-to-run code block
  • โœ“9-point quality checklist
  • โœ“10 pitfalls to avoid
  • โœ“Installs into 6 tools
Version
v1 โ†’
Last updated
today
Length
8 min read
Requires
Best with a strong model (Claude Sonnet 4)

Works in: Claude Code, Codex, Cline, opencode, OpenClaw, Hermes ยท Handles multi-file projects

Preview

When to use

Invoke when a third-party package is entering, changing, or being questioned in a project. Typical triggers:

  • Evaluating a candidate dependency before adding it.
  • Periodic audit of a lockfile, or response to a new advisory affecting a package in use.
  • A release gate that requires a clean vulnerability posture, or a customer request for a dependency inventory.
  • A suspicious package signal: a typosquat alert, an unexpected install script, a sudden ownership or license change.
  • Deciding whether to upgrade, pin, vendor, fork, or drop a dependency.

Use a code audit skill for defects in first-party code and a secrets skill for credential exposure.

Inputs to gather

  • **E

โ€ฆ

๐Ÿ”’ Buy once ($2.99) to unlock the full playbook, download it, and install it in every tool you use.