review-deps

Installation
SKILL.md

Review Deps

Cross-Platform AI Agent Skill This skill works with any AI agent platform that supports the skills.sh standard.

Dependency Review

Comprehensive dependency audit covering vulnerability scanning, license compliance, and staleness analysis. This skill performs analysis only — it identifies risks and recommends upgrades without modifying code or lock files.

Anti-Hallucination Guidelines

CRITICAL: Dependency reviews must be based on ACTUAL tool output and VERIFIED data:

  1. Run before claiming — Never report vulnerabilities without running the actual audit tool
  2. Evidence-based findings — Every finding must reference specific package names and versions
  3. No invented CVEs — Only reference CVE/GHSA identifiers returned by audit tools or Dependabot
  4. Tool output required — Copy exact output from audit commands as evidence
  5. Quantifiable results — Count actual issues from tool output, do not estimate
  6. No false positives — Verify each finding against actual installed versions
  7. Version accuracy — Report exact installed version and exact fix version from tool output
Related skills
Installs
6
GitHub Stars
4
First Seen
Mar 26, 2026