dependency_auditlisted
Install: claude install-skill jxoesneon/Ciel
# dependency_audit
Scan project and acquired skills for vulnerable or outdated dependencies.
## Operations
- `audit.scan(path)` — aggregated across ecosystems.
- `audit.by_severity(path, min)` — filter.
- `audit.updates(path)` — available update paths.
- `audit.explain(cve_id)` — fetch CVE details with `web_fetch`.
## I/O Contract
```yaml
io_contract:
input: { op, path, "min_severity?" }
output: { findings: [ { pkg, version, cve, severity, fix_version } ] }
idempotent: true
side_effects: [network]
```
## Backends
Calls `npm audit`, `pip-audit`, `cargo audit`, `bundle audit`, `govulncheck` as available. Cross-checks with OSV database via `web_fetch`.
## Policy
`acquisition.config.cve_threshold` blocks skill integration when exceeded.