scan-dependencies
Installation
SKILL.md
Skill: Evaluate Dependency Security via deps.dev Findings API
Description
This skill automates the process of auditing package dependencies before adoption. By querying the Open Source Insights (deps.dev) API, it checks a batch of package versions for active security findings (advisories and vulnerabilities) and outputs a clear action plan (ALLOW, CAUTION, or BLOCK).
Inputs
An array of target dependencies. Each dependency must contain:
system: The ecosystem name. Must be uppercase:NPM,PYPI,MAVEN,GO,CARGO,NUGET, orRUBYGEMS.name: The canonical name of the package (e.g.,org.apache.logging.log4j:log4j-corefor Maven, or normalized lowercase for PyPI/NuGet).version: The explicit version string to audit. This may be unset.