← スキル一覧に戻る

dependency-audit
by place-to-stand
⭐ 0🍴 0📅 2026年1月19日
SKILL.md
name: dependency-audit description: Audit npm dependencies for security vulnerabilities, outdated packages, unused deps, license compliance, and bundle impact. Use regularly for security hygiene, before major releases, or when bundle size grows unexpectedly.
Dependency Audit
Comprehensive audit of project dependencies for security, maintenance, and efficiency.
Scope
1. Security Vulnerabilities
- Run
npm auditfor known vulnerabilities - Check severity levels (critical, high, medium, low)
- Identify transitive dependency risks
- Review Dependabot/security advisories if available
2. Outdated Packages
- Compare current vs latest versions
- Identify packages with major version gaps
- Check for deprecated packages
- Review changelogs for breaking changes
3. Unused Dependencies
- Dependencies in package.json not imported anywhere
- devDependencies that should be dependencies (or vice versa)
- Duplicate functionality (multiple packages doing same thing)
- Per AGENTS.md: "Remove unused deps promptly"
4. License Compliance
- Identify licenses of all dependencies
- Flag copyleft licenses (GPL, AGPL) if problematic
- Check for license compatibility
- Document any commercial license requirements
5. Bundle Impact Analysis
- Large dependencies affecting client bundle
- Dependencies that should be dynamically imported
- Server-only packages accidentally in client bundle
- Tree-shaking effectiveness
6. Supply Chain Risk
- Packages with very few maintainers
- Packages with no recent updates (abandoned)
- Packages with suspicious update patterns
- Typosquatting risks
7. Core Dependency Health (project-specific)
Check health of key dependencies:
- Next.js - Framework updates, security patches
- Drizzle ORM - Database layer stability
- Supabase client - Auth/storage compatibility
- TanStack Query - Caching layer
- Radix UI / shadcn - Component primitives
- TipTap - Rich text editor
- dnd-kit - Drag and drop
- date-fns - Date handling
- Zod - Validation schemas
Actions
- Run
npm auditand capture output - Run
npm outdatedto list version gaps - Search for unused imports with grep patterns
- Check
package.jsonagainst actual imports - Analyze bundle with build output
Output Format
Security Findings
[SEVERITY: CRITICAL|HIGH|MEDIUM|LOW]
Package: package-name@version
Vulnerability: CVE or advisory ID
Description: What the vulnerability allows
Fix: Upgrade path or mitigation
Outdated Packages
Package: package-name
Current: x.y.z
Latest: a.b.c
Risk: Breaking changes likelihood
Action: Upgrade/Hold/Investigate
Unused Dependencies
Package: package-name
Type: dependency|devDependency
Evidence: Not found in codebase
Action: Remove from package.json
Bundle Impact
Package: package-name
Size: XXkB (gzipped)
Location: client|server|both
Issue: Should be server-only / dynamically imported
Dependency Management Rules (from AGENTS.md)
- Install via
npm install <package>@latest - Record rationale in PRs
- Remove unused deps promptly
- Do not edit
package.jsonor lockfiles directly (use CLI)
Post-Audit
Generate:
- Security remediation priority list
- Safe upgrade commands
- Packages to remove
- Bundle optimization opportunities
- Maintenance risk assessment
スコア
総合スコア
50/100
リポジトリの品質指標に基づく評価
✓SKILL.md
SKILL.mdファイルが含まれている
+20
○LICENSE
ライセンスが設定されている
0/10
○説明文
100文字以上の説明がある
0/10
○人気
GitHub Stars 100以上
0/15
○最近の活動
3ヶ月以内に更新がある
0/10
○フォーク
10回以上フォークされている
0/5
✓Issue管理
オープンIssueが50未満
+5
✓言語
プログラミング言語が設定されている
+5
○タグ
1つ以上のタグが設定されている
0/5
レビュー
💬
レビュー機能は近日公開予定です