dependency-audit

Featured

Audits direct and transitive dependencies for license compliance, maintenance health, CVEs, abandoned packages, and bloat. Triggers on: "audit dependencies", "license check", "dependency health", "abandoned packages", "unused dependencies", "license compliance", "supply chain", "dependency risk".

AI & Automation 313 stars 46 forks Updated 4 days ago MIT

Install

View on GitHub

Quality Score: 93/100

Stars 20%
83
Recency 20%
100
Frontmatter 20%
70
Documentation 15%
100
Issue Health 10%
50
License 10%
100
Description 5%
100

Skill Content

# Dependency Audit Comprehensive dependency risk assessment: license compatibility analysis, maintenance health scoring, CVE detection, bloat identification, and transitive dependency risk mapping. Produces an actionable report with prioritized remediation steps organized by urgency (security → license → maintenance → bloat). ## Reference Files | File | Contents | Load When | | ------------------------------------- | -------------------------------------------------------------------------- | ------------------------ | | `references/license-compatibility.md` | License compatibility matrix, copyleft detection, commercial-safe licenses | Always | | `references/health-metrics.md` | Maintenance health indicators, scoring criteria, abandonment detection | Always | | `references/bloat-detection.md` | Identifying unused deps, duplicate functionality, heavy transitive trees | Bloat analysis requested | | `references/cve-sources.md` | CVE databases, advisory sources, vulnerability severity interpretation | Security audit requested | ## Prerequisites - Access to the project's dependency files (`pyproject.toml`, `requirements.txt`, `package.json`, `Cargo.toml`, `go.mod`) - Lock file (for exact versions and transitive dependencies) - Project license (to determine compatibility requirements) ## Workfl...

Details

Author
Mathews-Tom
Repository
Mathews-Tom/armory
Created
5 months ago
Last Updated
4 days ago
Language
Python
License
MIT

Bundled in these plugins

Similar Skills

Semantically similar based on skill content — not just same category