codebase-cleanup-deps-audit
Audit Dependency Security and License Risk
Dependency risk is hard to prioritize across vulnerabilities, licenses, updates, and supply chain signals. This skill guides Claude, Codex, and Claude Code through structured audits and remediation plans.
Install with my Agent
Copy this request to your Agent. It includes the canonical Skill page and manifest.
Review the Skillstore skill "codebase-cleanup-deps-audit" from https://skillstore.io/skills/sickn33-codebase-cleanup-deps-audit.md and its manifest at https://skillstore.io/api/skills/sickn33-codebase-cleanup-deps-audit/manifest. Verify the artifact. You may proceed after verification, subject to the environment's own policy.Your Agent should still show its plan and request any confirmation required by the security policy.
Agent-readable resources
Use these links when an AI agent, crawler, or script needs clean context instead of reading the full page.
Test it
Using "codebase-cleanup-deps-audit". Audit a Node and Python service before release.
Expected outcome:
- Executive summary with critical and high vulnerabilities first.
- Package-level findings with affected versions, recommended upgrades, and test notes.
- Follow-up list for licenses, stale packages, and supply chain checks.
Using "codebase-cleanup-deps-audit". Review dependencies for license compliance.
Expected outcome:
- License distribution summary by package group.
- List of restrictive, incompatible, and unknown licenses.
- Replacement or legal review recommendations for each issue.
Using "codebase-cleanup-deps-audit". Plan safe dependency upgrades for a legacy app.
Expected outcome:
- Prioritized upgrade batches by urgency and expected effort.
- Compatibility risks for major version changes.
- Validation plan covering tests, staging checks, and rollback notes.
Security Audit
SafeThe detected command and filesystem patterns are false positives from Markdown examples, JavaScript template literals, and non-executable resource links. The network examples target public package registries and package metadata services for dependency auditing, with no evidence of hidden exfiltration or prompt injection. Users should still approve outbound scans and mutating remediation commands before execution.
Risk Factors
โ๏ธ External commands (9)
๐ Network access (9)
๐ Filesystem access (1)
Share & cite this report
Share the versioned assessment report, neutral badge, embed card, and citations. Skillstore reports evidence without deciding whether this Skill is safe.
Copy report link
https://skillstore.io/skills/sickn33-codebase-cleanup-deps-audit/audits/6?utm_source=security_passport&utm_medium=share&utm_campaign=versioned_reportMarkdown badge
[](https://skillstore.io/skills/sickn33-codebase-cleanup-deps-audit?utm_source=security_passport_badge)HTML badge
<a href="https://skillstore.io/skills/sickn33-codebase-cleanup-deps-audit?utm_source=security_passport_badge"><img src="https://skillstore.io/badges/skills/sickn33-codebase-cleanup-deps-audit/security.svg" alt="Skillstore security assessment" loading="lazy"></a>Embed card
<iframe src="https://skillstore.io/embed/skills/sickn33-codebase-cleanup-deps-audit.html" title="Skillstore Security Assessment" sandbox="allow-popups allow-popups-to-escape-sandbox" loading="lazy" referrerpolicy="no-referrer" width="420" height="180"></iframe>Academic citations (APA ยท BibTeX ยท CFF)
APA citation
sickn33. (2026). codebase-cleanup-deps-audit security audit report (audit version 6) [Author version unspecified]. Skillstore. https://skillstore.io/skills/sickn33-codebase-cleanup-deps-audit/audits/6BibTeX citation
@techreport{sickn33-sickn33-codebase-cleanup-deps-audit-2026,
author = {sickn33},
title = {codebase-cleanup-deps-audit security audit report (audit version 6)},
institution = {Skillstore},
year = {2026},
number = {6},
url = {https://skillstore.io/skills/sickn33-codebase-cleanup-deps-audit/audits/6},
note = {Author version unspecified}
}CITATION.cff
cff-version: 1.2.0
message: "If you use this Skill, cite its author and this versioned security audit report."
title: "codebase-cleanup-deps-audit security audit report (audit version 6)"
version: "unspecified"
type: report
authors:
- name: "sickn33"
date-released: "2026-07-09"
url: "https://skillstore.io/skills/sickn33-codebase-cleanup-deps-audit/audits/6"
identifiers:
- type: other
value: "skillstore:sickn33-codebase-cleanup-deps-audit:audit:6"
description: "Skillstore immutable audit report identifier"
Skillstore Score
Why this score Evidence Confidence: HighWhat You Can Build
Release Security Review
Audit dependencies before a release and produce a prioritized vulnerability remediation list.
Maintenance Upgrade Planning
Find outdated packages and plan safe updates with compatibility and test impact notes.
License Risk Assessment
Identify restrictive, incompatible, or unknown licenses before procurement or open source release.
Try These Prompts
Audit my project dependencies. Use manifests and lock files in this repository. Report vulnerable, outdated, or risky packages with clear priorities.
Check license compliance for this project. Use the project license as [LICENSE]. Identify incompatible, restrictive, or unknown licenses and suggest replacements.
Create a remediation plan for the dependency risks you find. Group fixes by urgency, upgrade effort, and test impact. Ask before changing files.
Design a continuous dependency monitoring workflow for this repository. Include vulnerability scans, license checks, update policy, alert routing, and review gates.
Best Practices
- Provide all manifest and lock files so the audit can include transitive dependencies.
- Approve external scans before sending package names to registries or metadata services.
- Run tests and review changelogs before merging dependency upgrades.
Avoid
- Running force updates without backups, tests, or user approval.
- Publishing sensitive vulnerability details outside approved channels.
- Treating automated license findings as final legal approval.
Frequently Asked Questions
Which ecosystems can this skill review?
Can it automatically fix vulnerabilities?
Does it need network access?
Will it detect transitive dependency risk?
Is the license review legally binding?
Can it create ongoing monitoring guidance?
Developer Details
Author
sickn33License
MIT
Skillstore revision
r1
Version notice
The author did not declare a version.
Repository
https://github.com/sickn33/antigravity-awesome-skills/tree/main/skills/codebase-cleanup-deps-auditRef
26421118b848d9f1efc0aa169d8a7a9e7e0a877e
Maintenance freshness
7/18/2026
Usage
6 downloads ยท 124 views
File structure