dep-auditAudit project dependencies for known vulnerabilities (CVEs). Supports npm, pip, Cargo, and Go. Zero API keys required. Safe-by-default: report-only mode, fix...
Install via ClawdBot CLI:
clawdbot install tkuehnl/dep-auditGrade Fair — based on market validation, documentation quality, package completeness, maintenance status, and authenticity signals.
Potentially destructive shell commands in tool definitions
rm -rf /Calls external URL not in known-safe list
https://docs.npmjs.com/cli/commands/npm-auditUses known external API (expected, informational)
raw.githubusercontent.comAI Analysis
The skill's external network calls (e.g., raw.githubusercontent.com) are consistent with its stated purpose of fetching vulnerability databases and are not exfiltrating user data. The 'UNSAFE_SHELL' signal appears to be a false positive from a command example ('rm -rf /') likely used for illustrative contrast, not an actual script instruction. No credential harvesting, hidden instructions, or obfuscation are present.
Generated Mar 1, 2026
Open source maintainers can use dep-audit to regularly scan their repositories for vulnerabilities before releases or after dependency updates. This helps ensure code security and compliance, especially for projects with multiple contributors and dependencies across npm, pip, Cargo, or Go ecosystems. It supports generating SBOMs for transparency and audit trails.
Enterprises can integrate dep-audit into their CI/CD pipelines to audit dependencies in internal projects for known CVEs, enhancing supply chain security. It scans lockfiles from various package managers without requiring API keys, making it easy to deploy across teams. The safe-by-default approach with report-only mode minimizes risks during automated scans.
Freelance developers can use dep-audit to quickly audit client projects for vulnerabilities, providing security assessments as part of their services. It supports multiple ecosystems, allowing freelancers to handle diverse tech stacks without additional setup. The tool's ability to generate fix suggestions and SBOMs adds value in client reporting and remediation efforts.
Institutions teaching software development can incorporate dep-audit into coursework to help students learn about dependency security and vulnerability management. It scans student projects for CVEs in supported ecosystems, providing practical insights into real-world security practices. The Discord integration facilitates interactive learning in classroom settings.
Startups building minimum viable products (MVPs) can use dep-audit to ensure their dependencies are free from critical vulnerabilities before launch. It scans projects with minimal configuration, saving time for small teams focused on rapid development. The ability to audit across npm, pip, Cargo, and Go covers common tech stacks used in early-stage startups.
Offer dep-audit as a free open-source tool for basic vulnerability scanning, with premium features like advanced reporting, historical trend analysis, and team dashboards available via subscription. Revenue can be generated from enterprises needing enhanced security insights and compliance tracking. This model encourages adoption while monetizing value-added services.
Provide consulting services to help organizations integrate dep-audit into their workflows, including custom configurations, training, and support for specific ecosystems like Discord v2. Revenue comes from one-time setup fees and ongoing maintenance contracts. This model leverages the tool's flexibility to address unique client security needs.
Develop a marketplace where third-party developers can create and sell plugins extending dep-audit's capabilities, such as support for additional package managers or integration with other security tools. Revenue is generated through commissions on plugin sales and listing fees. This model fosters community growth and expands the tool's ecosystem.
💬 Integration Tip
Integrate dep-audit into CI/CD pipelines by running detection and audit scripts as part of build processes, using the JSON output for automated reporting and alerts.
Scored Apr 19, 2026
Audited Apr 17, 2026 · audit v1.0
Information Security Management System (ISMS) audit expert for ISO 27001 compliance verification, security control assessment, and certification support. Use...
ISO 13485 internal audit expertise for medical device QMS. Covers audit planning, execution, nonconformity classification, and CAPA verification. Use for int...
Safely triage and remediate GitHub dependency hygiene issues with explicit guardrails. Use when Dependabot PRs fail, pnpm lockfiles break, transitive vulnerabilities appear (e.g., glob/lodash/brace-expansion), or CI/Vercel fails due to dependency resolution. Prioritize low-risk fixes, branch+PR workflow, and plain-English explanations.
Prioritize vulnerability remediation using KEV-style exploitation context plus asset criticality. Use for CVE triage, patch order decisions, and remediation...
Audit an iOS app repo (Swift/Xcode or React Native/Expo) for App Store compliance and release readiness; output a pass/warn/fail report and publish checklist.
Local-first, event-driven RAG for commercial real estate audit & investigation case folders. Index a case directory named like "项目问题编号__标题" (with stage subfolders such as 01_policy_basis/02_process/04_settlement_payment) and query it with citations (file:// links + PDF