Now liveThe Skillselion MCP - thousands of ranked skills, loaded into your agent mid-task. No install.Get it →
useai-pro avatar

Dependency Auditor

  • 478 installs
  • 70 repo stars
  • Updated March 10, 2026
  • useai-pro/openclaw-skills-security

dependency-auditor is a Claude Code skill that audits npm, pip, and Go dependencies proposed by OpenClaw skills for developers who need supply-chain checks before package installation.

About

dependency-auditor is a supply-chain security skill from useai-pro/openclaw-skills-security that reviews dependencies OpenClaw skills attempt to install across npm, pip, and Go ecosystems. It checks package identity, install hooks, recency, reputation, and vulnerability severity to catch typosquatting and malicious packages before they enter the environment. The skill produces dependency findings with install recommendations and explicit block conditions when risk thresholds are exceeded. Developers reach for dependency-auditor whenever an agent skill triggers npm install, pip install, or go get flows and automated vetting is required.

  • Audits npm, pip, and Go dependencies used by OpenClaw skills
  • Detects known vulnerabilities, typosquatting, and malicious packages
  • Checks package identity, install hooks, recency, reputation, and vulnerability severity
  • Produces dependency findings with install recommendations and block conditions
  • Runs before any `npm install`, `pip install`, or `go get` suggested by a skill

Dependency Auditor by the numbers

  • 478 all-time installs (skills.sh)
  • +2 installs in the week ending Aug 5, 2026 (Skillselion tracking)
  • Ranked #515 of 2,203 Security skills by installs in the Skillselion catalog
  • Data as of Aug 5, 2026 (Skillselion catalog sync)
npx skills add https://github.com/useai-pro/openclaw-skills-security --skill dependency-auditor

Add your badge

Show developers this skill is listed on Skillselion. Paste this into your README.

Listed on Skillselion
Installs478
repo stars70
Last updatedMarch 10, 2026
Repositoryuseai-pro/openclaw-skills-security

How do you audit agent skill dependencies for supply-chain risk?

Catch supply-chain attacks before any skill or agent installs npm, pip, or Go packages.

Who is it for?

Developers enabling OpenClaw or agent skills that auto-install packages who need pre-install supply-chain vetting.

Skip if: Manual dependency upgrades in apps already covered by standard CI SCA scanners without agent-driven installs.

When should I use this skill?

An OpenClaw skill proposes npm, pip, or Go package installs and the agent should verify identity, hooks, reputation, and CVE severity first.

What you get

Dependency findings report with install recommendations, severity ratings, and block conditions for risky packages.

  • Dependency findings report
  • Install block or allow recommendation

Files

SKILL.mdMarkdownGitHub ↗

Dependency Auditor

You are a dependency security auditor for OpenClaw. When a skill tries to install packages or you review a project's dependencies, check for security issues.

When to Audit

  • Before running npm install, pip install, go get commands suggested by a skill
  • When reviewing a skill that adds dependencies to package.json or requirements.txt
  • When a skill suggests installing a package you haven't used before
  • During periodic security audits of your project

Audit Checklist

1. Package Legitimacy

For each package, verify:

  • [ ] Name matches intent — is it the actual package, or a typosquat?
  lodash     ← legitimate
  l0dash     ← typosquat (zero instead of 'o')
  lodash-es  ← legitimate variant
  lodash-ess ← typosquat (extra 's')
  • [ ] Publisher is known — check who published the package
  npm: Check npmjs.com/package/<name> for publisher identity
  pip: Check pypi.org/project/<name> for maintainer
  • [ ] Download count is reasonable — very new packages with 0-10 downloads are higher risk
  • [ ] Repository exists — the package should link to a real source repository
  • [ ] Last published recently — abandoned packages may have known unpatched vulnerabilities

2. Known Vulnerabilities

Check against vulnerability databases.

Note (offline-first): this skill declares network: false, so you must not fetch live URLs yourself. Treat links below as manual references for the user to open, and prefer local commands (npm audit, pip-audit, govulncheck) when possible.

NPM:
  npm audit
  Check: https://github.com/advisories

PyPI:
  pip-audit
  Check: https://osv.dev

Go:
  govulncheck
  Check: https://vuln.go.dev

Severity classification:

SeverityAction
Critical (CVSS 9.0+)Do not install. Find alternative.
High (CVSS 7.0-8.9)Install only if patched version available.
Medium (CVSS 4.0-6.9)Install with awareness. Monitor for patches.
Low (CVSS 0.1-3.9)Generally acceptable. Note for future.

3. Suspicious Package Indicators

Red flags that warrant deeper investigation:

  • Package has postinstall, preinstall, or install scripts
  // package.json — check "scripts" section
  "scripts": {
    "postinstall": "node setup.js"  // ← What does this do?
  }
  • Package imports child_process, net, dns, http in unexpected ways
  • Package reads environment variables or file system on import
  • Package has obfuscated or minified source code (unusual for npm packages)
  • Package was published very recently (< 1 week) and has minimal downloads
  • Package name is similar to a popular package but from a different publisher
  • Package has been transferred to a new owner recently

4. Dependency Tree Depth

Check transitive dependencies:

Direct dependency → sub-dependency → sub-sub-dependency
     (you audit)      (who audits?)     (nobody audits?)
  • Flag packages with excessive dependency trees (100+ transitive deps)
  • Check if any transitive dependency has known vulnerabilities
  • Prefer packages with fewer dependencies

5. License Compatibility

Verify licenses are compatible with your project:

LicenseCommercial UseCopyleft Risk
MIT, ISC, BSDYesNo
Apache-2.0YesNo
GPL-3.0CautionYes — derivative works must be GPL
AGPL-3.0CautionYes — even network use triggers copyleft
UNLICENSEDNoUnknown — avoid

Output Format

DEPENDENCY AUDIT REPORT
=======================
Package: <name>@<version>
Registry: npm / pypi / go
Requested by: <skill name or user>

CHECKS:
  [PASS] Name verification — no typosquatting detected
  [PASS] Publisher — @official-org, verified
  [WARN] Vulnerabilities — 1 medium severity (CVE-2026-XXXXX)
  [PASS] Install scripts — none
  [PASS] License — MIT
  [WARN] Dependencies — 47 transitive dependencies

OVERALL: APPROVE / REVIEW / REJECT

RECOMMENDATIONS:
  - Update to version X.Y.Z to resolve CVE-2026-XXXXX
  - Consider alternative package 'safer-alternative' with fewer dependencies

Common Typosquatting Patterns

Watch for these naming tricks:

TechniqueLegitimateTyposquat
Character swapexpressexrpess
Missing characterrequestrequst
Extra characterlodashlodashs
Homoglyphbabelbabe1 (L → 1)
Scope confusion@types/node@tyeps/node
Hyphen trickreact-domreact_dom
Prefix/suffixwebpackwebpack-tool

Rules

1. Never auto-approve npm install or pip install from untrusted skills 2. Always check install scripts before running — they execute with full system access 3. Pin dependency versions in production — avoid ^ or ~ ranges for security-critical packages 4. If a skill wants to install 10+ packages, review each one individually 5. When in doubt, read the package source code — it's usually small enough to skim

Related skills

How it compares

Use dependency-auditor at agent skill install time; use repository CI scanners for routine app dependency updates.

FAQ

Which package managers does dependency-auditor cover?

dependency-auditor reviews npm, pip, and Go dependencies that OpenClaw skills try to install, checking identity, hooks, recency, reputation, and vulnerability severity.

What does dependency-auditor output after a review?

dependency-auditor produces dependency findings with install recommendations and block conditions when packages show typosquatting, risky hooks, or high-severity vulnerabilities.

This week in AI coding

Five minutes, every Monday - the tools, releases and tactics for developers.

unsubscribe anytime.