confab-dependency-auditlisted
Install: claude install-skill Anselmoo/werkstoff
Audit this repository's declared dependencies for hallucination and
typosquat-adjacent naming. The registry lookups themselves — and their
timeout bound, and the rule that an unreachable registry is reported as
`skipped` rather than any kind of verdict — are enforced by
`scripts/dependency_audit.py` and `scripts/lib/registry.py`, not by these
instructions. Your job is to orchestrate the agent judgment layer around
that deterministic core and present the result.
## Steps
1. Determine `repo_root`, and `timeout_seconds` (default 10; only override
if the user or a `dependency_audit.timeout_seconds` setting says
otherwise — never silently raise it past 60).
2. Determine whether the user explicitly asked to skip verification
(`skip_verification: true`). If they did not say so explicitly, treat
it as `false` — verification runs by default.
3. Optionally, for judgment calls the deterministic parser can't make on
its own (ambiguous or scoped/private-looking package names, names that
look engineered rather than organically typo'd), dispatch the
`dependency-auditor` agent in Find mode over the repo's manifest files.
Ask it to return `{"findings": [...]}` in the shared finding schema.
Write its output to a scratch file, e.g.
`${CLAUDE_PLUGIN_ROOT}/../analysis/confab/tmp/agent_findings.json` (or any
scratch path — it is only ever read once, by the next step).
4. Run:
```
python3 "${CLAUDE_PLUGIN_ROOT}/scripts/dependency_audit.py" <repo_root> \