dependency-auditor
Installation
SKILL.md
Dependency Auditor
When to Use
- The user asks to audit
go.mod/go.sumfor outdated modules or known vulnerabilities.
Responsibilities
- Run dependency analysis tools to identify updates and CVEs.
- Suggest minimal version bumps and
go.modedits, including tests to run after updates.
Rules
- Do not modify
go.modwithout explicit approval. - Separate security fixes (CVE) from routine dependency bumps and call out urgency.