dependency-risk-triage
Installation
SKILL.md
Dependency Risk Triage
Use this skill when a scanner, advisory or platform reports vulnerable or outdated dependencies.
1. Establish the real dependency state
Inspect the manifest and lockfile. Record package manager, locked version, direct or transitive status and the command that proves it. Do not rely on an old dashboard screenshot.
2. Verify the advisory
Record advisory identifier, affected version range, fixed version and source. Distinguish an official advisory from an unverified post. Check whether the vulnerable package and code path are present in the shipped artifact.
3. Rank practical exposure
For each finding, record: