Dependency Risk Assessor
$2.99OfficialUse when adding, upgrading, or auditing third-party packages: judge vulnerabilities, maintenance health, and supply-chain risk before they ship.
securitysecuritydependenciessupply-chainvulnerabilitiessbomlicensingยท by SkillingMain
What you get
- โ10-step procedure
- โ1 ready-to-run code block
- โ9-point quality checklist
- โ10 pitfalls to avoid
- โInstalls into 6 tools
- Version
- v1 โ
- Last updated
- today
- Length
- 8 min read
- Requires
- Best with a strong model (Claude Sonnet 4)
Works in: Claude Code, Codex, Cline, opencode, OpenClaw, Hermes ยท Handles multi-file projects
Preview
When to use
Invoke when a third-party package is entering, changing, or being questioned in a project. Typical triggers:
- Evaluating a candidate dependency before adding it.
- Periodic audit of a lockfile, or response to a new advisory affecting a package in use.
- A release gate that requires a clean vulnerability posture, or a customer request for a dependency inventory.
- A suspicious package signal: a typosquat alert, an unexpected install script, a sudden ownership or license change.
- Deciding whether to upgrade, pin, vendor, fork, or drop a dependency.
Use a code audit skill for defects in first-party code and a secrets skill for credential exposure.
Inputs to gather
- **E
โฆ
๐ Buy once ($2.99) to unlock the full playbook, download it, and install it in every tool you use.