← ClaudeAtlas

dependency-auditlisted

Supply chain security audit — coordinates real CLI vulnerability scanners (npm audit, pip-audit, govulncheck, cargo audit, etc.) and synthesizes findings with license compliance and risk assessment.
backspace-shmackspace/claude-devkit · ★ 15 · AI & Automation · score 76
Install: claude install-skill backspace-shmackspace/claude-devkit
# /dependency-audit Workflow ## Output Rules - **Always print full absolute paths** for all artifact references (plan files, review files, audit logs). This makes paths clickable in terminals like Warp. Use the resolved `$PLANS_DIR` value, never relative paths. ## Role This skill is a **pipeline coordinator**. It orchestrates a sequential supply chain security workflow by delegating scanner invocation and synthesis to appropriate tools. It does NOT perform LLM-based CVE lookup — it coordinates real CLI scanners that use live vulnerability databases, then synthesizes their output. The LLM's training data has a knowledge cutoff and cannot reliably detect post-cutoff CVEs. ## Inputs - Package manifest path or scope: $ARGUMENTS (optional — auto-detected if omitted) - Supported: `package.json`, `requirements.txt`, `pyproject.toml`, `Pipfile`, `go.mod`, `Cargo.toml`, `pom.xml`, `Gemfile` ## Step 0 — Pre-flight: detect manifest and scanner availability **Resolve devkit paths (MUST be first action in Step 0):** Tool: `Bash` ```bash # --- Devkit Path Resolution --- DEVKIT_SCRIPTS="${CLAUDE_DEVKIT:-$HOME/.claude-devkit}/scripts" # Source path resolution helper if [ -f "$DEVKIT_SCRIPTS/resolve-project-dir.sh" ]; then . "$DEVKIT_SCRIPTS/resolve-project-dir.sh" DEVKIT_PROJECT_DIR_RESOLVED=$(resolve_devkit_project_dir) || { echo "Failed to resolve project directory" >&2; exit 1 } elif [ -n "${DEVKIT_PROJECT_DIR:-}" ]; then DEVKIT_PROJECT_DIR_RESOLVED="$DEVKIT_PROJECT_