scan-dependencies

Installation
SKILL.md

Skill: Evaluate Dependency Security via deps.dev Findings API

Description

This skill automates the process of auditing package dependencies before adoption. By querying the Open Source Insights (deps.dev) API, it checks a batch of package versions for active security findings (advisories and vulnerabilities) and outputs a clear action plan (ALLOW, CAUTION, or BLOCK).

Inputs

An array of target dependencies. Each dependency must contain:

  • system: The ecosystem name. Must be uppercase: NPM, PYPI, MAVEN, GO, CARGO, NUGET, or RUBYGEMS.
  • name: The canonical name of the package (e.g., org.apache.logging.log4j:log4j-core for Maven, or normalized lowercase for PyPI/NuGet).
  • version: The explicit version string to audit. This may be unset.
Installs
2
Repository
google/deps.dev
GitHub Stars
448
First Seen
6 days ago
scan-dependencies — google/deps.dev