AgentHub

dark-dependency-audit

Audit third-party dependencies for CVEs, transitive risk, and supply-chain attacks (typosquatting, protestware, hijacke…

Live
Open / InstallLast updated July 27, 2026

Description

Audit third-party dependencies for CVEs, transitive risk, and supply-chain attacks (typosquatting, protestware, hijacked maintainer, malicious postinstall) before adding them and periodically after. Lockfile discipline, pinning, minimizing the tree. Use for "is this package safe", "audit dependencies", "add this library", "npm/pip/go audit", vendor review. Triggers: "/dark-audit", "dependency", "package", "supply chain", "CVE в пакете", "зависимост", "пакет", "безопасно ли ставить этот пакет", "аудит зависимостей", "уязвимость в зависимости". Vulnerabilities in OUR OWN code (authn/authz, IDOR, rate limiting, CORS) = dark-security. A reusable SKILL.md agent skill by prometazinesoldier.

Author

prometazinesoldier

Platform

cli

Pricing model

free

Categories

Skills

Tags

skill
claude-skill
github
en

Capabilities

  • SKILL.md package