
from universal-ai-skills-library13
Evaluates project dependencies for security risks, including single-maintainer bottlenecks, stale updates, and lack of security contacts.
This skill enables an agent to perform a systematic security audit of a project's supply chain by evaluating its direct dependencies against specific risk criteria. It identifies 'red flags' that suggest a dependency might be vulnerable to exploitation or takeover.
Use this skill when assessing the attack surface of a project, identifying unmaintained or risky dependencies before a security audit, or scoping security engagements specifically focused on supply chain health.
gh CLI for accurate data), and a post-audit phase to suggest safer alternatives.Designed for AI agents with access to the gh (GitHub CLI) tool and filesystem operations, such as Codex, Claude Code, and Cursor.
This skill has not been reviewed by our automated audit pipeline yet.