Skip to content
Development
Command

/audit-deps

Audit all project dependencies for vulnerabilities, licensing issues, and maintenance status.

From plugin
rohitg00-claude-code-toolkit
2.5k199 skills138 agents199 commands
Install
$ npx -y skills add rohitg00/awesome-claude-code-toolkit --agent claude-code

How it fires

How this command gets triggered: by you, by Claude, or both.

  • Fires itselfClaude auto-loads it when your prompt matches the work.
  • You can call itInvoke it directly when you want it.
  • Slash command/audit-deps

Context preview

What this command does when you run it.

Audit all project dependencies for vulnerabilities, licensing issues, and maintenance status.

Command definition

audit-deps.md
name: audit-deps
description: Audit all project dependencies for vulnerabilities, licensing issues, and maintenance status.

Audit all project dependencies for vulnerabilities, licensing issues, and maintenance status.

Steps

1. Detect the package manager and run native audit:

  • npm: `npm audit --json`
  • pnpm: `pnpm audit --json`
  • pip: `pip-audit --format json`
  • cargo: `cargo audit --json`

2. Check package maintenance status:

  • Last publish date for each dependency.
  • Open issue count and response time.
  • Whether the package is deprecated.

3. Verify license compatibility:

  • List all dependency licenses.
  • Flag any copyleft licenses (GPL) in permissive projects.
  • Flag packages with no license specified.

4. Analyze dependency tree depth and size impact. 5. Identify unused dependencies by cross-referencing imports. 6. Generate a prioritized action list.

Format

Dependency Audit - <date>

Vulnerabilities: <C>critical, <H>high, <M>moderate, <L>low
Licenses: <N> permissive, <N> copyleft, <N> unknown
Maintenance: <N> actively maintained, <N> stale, <N> deprecated
Unused: <list>

Priority actions:
  1. [CRITICAL] Upgrade <pkg> to fix CVE-XXXX
  2. [WARNING] Replace deprecated <pkg> with <alternative>

Rules

  • Always report the full vulnerability chain (which direct dep pulls in the vulnerable transitive dep).
  • Flag any dependency with no updates in the last 12 months.
  • Check that lock files are present and committed.
  • Never recommend removing a dependency without verifying it is truly unused.
Read more
Ships withrohitg00-claude-code-toolkit

The most comprehensive toolkit for Claude Code -- 135 agents, 35 curated skills (+400,000 via SkillKit), 42 commands, 176+ plugins, 20 hooks, 15 rules, 7 templates, 15 MCP configs, 26 companion apps, 53 ecosystem entries, and more.

Get the whole plugin