sc-dependency-audit

sc-dependency-audit is a skill for Claude Code from fatihkan/badi. It costs 16 tokens per session (1,968 once invoked), scanned A, a copy of sc-dependency-audit, MIT.

A security checker for third-party dependencies, the libraries and packages a project uses. It reviews package files across common ecosystems for known vulnerabilities, supply-chain risks, suspicious package names, and unsafe build behavior.

In plain words
What is it for?
Use it to inspect dependency manifests and lock files for JavaScript, Python, Go, Rust, Java, .NET, PHP, and Ruby projects.
Why use it?
It helps identify risks introduced by external code before those packages reach production. This is useful because a project can be vulnerable even when its own code is safe.

Skill for Claude Code

Written for Claude Code: installed under .claude/.

Part of the badi plugin — 81 skills, 86 commands, 30 agents, 7 hooks shipped together

Good fit Use it to inspect dependency manifests and lock files for JavaScript, Python, Go, Rust, Java, .NET, PHP, and Ruby projects.

Compare 6 skills from other repositories ↓
Install with agentmods
npx agentmods add skills/fatihkan/badi/sc-dependency-audit
Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

Any agent
npx skills add fatihkan/badi --skill sc-dependency-audit
Clone the repo
git clone --depth 1 https://github.com/fatihkan/badi

Made for: Claude Code.

Or install badi, the plugin that ships this one along with the rest of its 81 skills, 86 commands, 30 agents, 7 hooks.

Wrote this? Show the measurements

A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.

agentmods badge for sc-dependency-audit

README.md
[![agentmods](https://agentmods.dev/badge/skills/fatihkan/badi/sc-dependency-audit/github.svg)](https://agentmods.dev/skills/fatihkan/badi/sc-dependency-audit)
Your own site
<a href="https://agentmods.dev/skills/fatihkan/badi/sc-dependency-audit"><img src="https://agentmods.dev/badge/skills/fatihkan/badi/sc-dependency-audit/github.svg" alt="Measured on agentmods" height="20"></a>

Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.

agentmods 80×15 button for sc-dependency-audit

Your own site · 80×15
<a href="https://agentmods.dev/skills/fatihkan/badi/sc-dependency-audit"><img src="https://agentmods.dev/badge/skills/fatihkan/badi/sc-dependency-audit.svg" alt="Reviewed on agentmods" width="80" height="20"></a>
Per session 16 Skills are progressive disclosure: only the name and description are preloaded; the body loads when the skill is used.
When invoked 1,968 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 2 findings. A grade says what 26 rules found in the file — not that it is safe.
Origin 92% copy Near-identical to another mod in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5.1 $0.00016 $0.01968
Opus 5 $0.00008 $0.00984
Sonnet 5 $0.00003 $0.00394
Haiku 4.5 $0.00002 $0.00197

Measured 2d ago against content hash 54968f10af78, method: parsed. Prices are Anthropic first-party input rates as of 2026-09-08, from the pricing page.

Security

Grade A, and why

sc-dependency-audit scanned grade A with 2 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Unrestricted tool accesslowExcessive agency

A wildcard tool grant or "run any command" leaves no least-privilege boundary at all.

- Gradle/Maven plugins that execute arbitrary code

Downgraded: this mod is about security review, or the phrase is quoted, so it is likely naming the pattern rather than instructing it.

Runs shell commandslowCapability

Expected in a hook, worth knowing in a rule or an instructions file.

- `setup.py` with `os.system()`, `subprocess`, or network calls
Origin

This is a copy

92% identical to sc-dependency-audit — 1 line differ, which has more behind it and is treated as the original. This page carries a canonical link to it rather than competing with it.

.claude/skills-vault/security-check/sc-dependency-audit/SKILL.md · 211 lines

How it starts

The opening of the file, as written. The whole thing — 211 lines — stays where its author put it; the contents beside it link to each section on GitHub.

SC: Dependency Audit — Supply Chain & Dependency Security

Purpose

Analyzes all project dependencies for known vulnerabilities, supply chain risks, typosquatting attempts, and dangerous build-time behaviors. Covers all major package ecosystems: npm, PyPI, crates.io, Maven Central, NuGet, Packagist, and Go modules.

Activation

Runs as part of Phase 1 (Reconnaissance), immediately after sc-recon.

Output

File: security-report/dependency-audit.md

Phase 1: Discovery

Lock File Detection

Search for dependency manifest and lock files:

Ecosystem Manifest Lock File
Node.js package.json package-lock.json, yarn.lock, pnpm-lock.yaml
Python requirements.txt, pyproject.toml, Pipfile, setup.py, setup.cfg Pipfile.lock, poetry.lock
Go go.mod go.sum
Rust Cargo.toml Cargo.lock
Java pom.xml, build.gradle, build.gradle.kts gradle.lockfile
C# *.csproj, packages.config packages.lock.json
PHP composer.json composer.lock
Ruby Gemfile Gemfile.lock

Dependency Inventory

For each detected ecosystem:

  1. Parse manifest files to list all direct dependencies with version constraints
  2. Parse lock files to list all transitive dependencies with resolved versions
  3. Count total dependencies (direct + transitive)
  4. Flag missing lock files — if manifest exists but no lock file, flag as risk

Known Vulnerability Scanning

For each dependency, check for known vulnerabilities by analyzing:

  1. Version age — flag dependencies not updated in 2+ years
  2. Known CVE patterns — check version ranges against known vulnerable version ranges
  3. Deprecated packages — check for deprecation notices in manifest metadata
  4. Yanked/retracted versions — detect usage of versions pulled from registries

Common vulnerable dependency patterns to flag:

Node.js:

  • lodash < 4.17.21 (prototype pollution)
  • minimist < 1.2.6 (prototype pollution)
  • json5 < 2.2.2 (prototype pollution)
  • node-fetch < 2.6.7 (SSRF via redirect)
  • express < 4.19.2 (open redirect)
  • jsonwebtoken < 9.0.0 (algorithm confusion)
  • Any dependency using eval or Function() in source

Read the full file on GitHub · 211 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 2d ago First seen · 211 lines · 16 tokens per session scan A 54968f10af78

Subscribe to this mod's changes

sc-dependency-audit is a skill published in the GitHub repository fatihkan/badi (7 stars, last pushed yesterday), licensed MIT. It adds 16 tokens to every session and 1,968 once invoked, about $0.0001 per session on Opus 5. A static security scan graded it A with 2 findings (unrestricted tool access, runs shell commands). It is 92% identical to sc-dependency-audit, differing in 1 line, and is treated as a copy.

Related

Other skills, from other repositories

pr-triage

4-phase PR backlog management with audit, deep code review, validated comments, and optional worktree setup. Use when triaging pull requests, catching up on pending code reviews, or managing a backlog of open PRs. Args: 'all' to review all, PR numbers to focus (e.g. '42 57'), 'en'/'fr' for language, no arg = audit…

FlorianBruniaux/claude-code-plugins · 86 tokens

audit-agents-skills

Audit Claude Code agents, skills, and commands for quality and production readiness. Use when evaluating skill quality, checking production readiness scores, or comparing agents against best-practice templates.

FlorianBruniaux/claude-code-plugins · 41 tokens

eval-agents

Audit Claude Code agents defined in .claude/agents/ for description specificity, model tier appropriateness, tools scoping, and system prompt quality. Detects dispatch ambiguity between agents, flags over-permissive tool grants, and checks for human-in-the-loop patterns that break programmatic orchestration. Use when…

FlorianBruniaux/claude-code-plugins · 93 tokens

check-cache-bugs

Audit Claude Code setup for cache bugs (CC#40524): sentinel, --resume/--continue, attribution header + ArkNill B3/B4/B5.

FlorianBruniaux/claude-code-plugins · 38 tokens

issue-triage

3-phase issue backlog management with audit, deep analysis, and validated triage actions. Use when triaging GitHub issues, sorting bug reports, cleaning up stale tickets, or detecting duplicate issues. Args: 'all' to analyze all, issue numbers to focus (e.g. '42 57'), 'en'/'fr' for language, no arg = audit only.

FlorianBruniaux/claude-code-plugins · 81 tokens

git-ai-archaeology

Analyze AI config evolution in a git repo. Use when mapping AI adoption history, finding when configs were first introduced, charting commit velocity by month, or identifying maturity phases in a project's AI tooling.

FlorianBruniaux/claude-code-plugins · 47 tokens