dependency-audit is agent-read markdown (skill) from fusengine/agents: Use when running ecosystem-specific vulnerability scans across project dependencies (npm/composer/pip/cargo/go/etc), with optional auto-fix..
Indexed from public GitHub and served as immutable, content-addressed versions. Install it pinned to an exact SHA-256 with the mdr CLI, and every file is verified against the hash recorded here before it reaches your agent. The deterministic audit below grades the latest version, and the same file always earns the same grade.
What the file says
<objective>
This skill runs native package-manager audit tools across a project's full dependency tree,
detecting the package manager from lock files and running the matching command:
npm/yarn/pnpm/bun audit, composer audit, pip-audit/safety check, cargo audit, govulncheck,
pod audit, or bundle audit.
It parses each tool's output, classifies findings by severity (CRITICAL/HIGH/MEDIUM/LOW),
and suggests fix versions or alternatives. With the --fix flag it applies safe auto-fixes
where supported (npm audit fix, cargo audit fix) and gives manual guidance for ecosystems
without auto-fix.
Out of scope: researching a single named dependency's CVE history in depth belongs to
cve-research.
</objective>
# Dependency Audit Skill
## Overview
Run dependency vulnerability checks using native package manager audit tools.
## Supported Ecosystems
| Ecosystem | Tool | Auto-fix |
|-----------|------|----------|
| npm/yarn/pnpm/bun | `npm audit` / `yarn audit` | Yes |
| PHP/Composer | `composer audit` | Manual |
| Python/pip | `pip-audit` / `safety check` | Manual |
| Rust/Cargo | `cargo audit` | Yes |
| Go | `govulncheck ./...` | Manual |
| Swift/CocoaPods | `pod audit` | Manual |
…
Pin to a label to follow the author's releases, or to a sha256 to freeze the exact bytes forever. Either way the resolved hash is written to mdr.lock, and mdr install reproduces it on any machine.
A 17 of 17 checks passed. Deterministic, no model, same answer every run.
pass: Frontmatter block present
pass: Frontmatter declares a name
pass: Frontmatter declares a description
pass: Size between 200 bytes and 200 KB (1989 bytes)
pass: No zero-width or bidi control characters
pass: No instruction hidden inside an HTML comment
pass: No link to an exfiltration or paste host
pass: No credential-shaped string
pass: No instruction to send local credentials anywhere
pass: No text hidden with inline styles
pass: No prompt-injection phrasing
pass: No curl or wget piped into a shell
pass: No recursive delete of root, home or parent
pass: No instruction to read or print local credentials
pass: No base64 blob over 200 characters
pass: No link to a raw IP address
pass: No script tag
Source
GitHub
fusengine/agents · 28 stars · license MIT · pushed 2026-09-24 · branch main
API
GET https://markdownregistry.com/api/v1/artifacts/art_xs2wfz4cge2ug6pn
GET https://markdownregistry.com/api/v1/resolve?ref=fusengine/agents/dependency-audit
GET https://markdownregistry.com/api/v1/blob/a0742f4060223357453e080cc994e8ba8db85ed91923d31789a27d372d9cc982
Your agent does the legwork. You hear about the deals worth your word. Hand yours the standing instructions at modelranch.com and it joins the network that reads files like this one.
fusengine/agents · plugins/ai-pilot/skills/agent-creator/SKILL.md · Use when creating expert agents. Generates agent.md with frontmatter, hooks, required sections, and skill references.
fusengine/agents · plugins/ai-pilot/skills/brainstorming/SKILL.md · Use when creating a feature/component or adding functionality. Fires BEFORE APEX Analyze to refine requirements via…
fusengine/agents · plugins/ai-pilot/skills/challenge/SKILL.md · Use before a root-cause, done/verified claim, irreversible action, or 2nd-time fix reaches the owner (APEX or plain…
fusengine/agents · plugins/ai-pilot/skills/elicitation/SKILL.md · Use when an expert agent self-reviews and self-corrects code after the Execute phase, before sniper validation…
fusengine/agents · plugins/ai-pilot/skills/fuse-browser-usage/SKILL.md · Use when about to call any mcp__fuse-browser__* tool. Routes fetch/crawl/SERP vs live browser session vs screenshot…
fusengine/agents · plugins/ai-pilot/skills/pr-summary/SKILL.md · Summarize current pull request with diff, comments, and changed files. Use when reviewing PRs or before merging.
fusengine/agents · plugins/ai-pilot/skills/react-effects-audit/SKILL.md · Use when auditing React or Next.js components for unnecessary or unsafe useEffect usage -- detects 9 anti-patterns from…
fusengine/agents · plugins/ai-pilot/skills/research/SKILL.md · Use when researching documentation, best practices, or complex technical investigations -- Context7 + Exa + Sequential…
khaledsaeed18/dotclaude · .claude-plugin/plugins/security/skills/dependency-audit/SKILL.md · Audit a project's dependencies for outdated and vulnerable packages and surface breaking-change notes for upgrades…
khaledsaeed18/dotclaude · skills/security/dependency-audit/SKILL.md · Audit a project's dependencies for outdated and vulnerable packages and surface breaking-change notes for upgrades…
okhp3/skillz · community/dependency-audit/SKILL.md · Assesses what a project depends on — known vulnerabilities, licence obligations, abandoned packages, and supply chain…