Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add skills/jansenanalytics/claudex/dep-auditnpx skills add JansenAnalytics/claudex --skill dep-auditgit clone --depth 1 https://github.com/JansenAnalytics/claudexWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/jansenanalytics/claudex/dep-audit)<a href="https://agentmods.dev/skills/jansenanalytics/claudex/dep-audit"><img src="https://agentmods.dev/badge/skills/jansenanalytics/claudex/dep-audit.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00026 | $0.00551 |
| Opus 5 | $0.00013 | $0.00275 |
| Sonnet 5 | $0.00005 | $0.00110 |
| Haiku 4.5 | $0.00003 | $0.00055 |
Grade A, and why
dep-audit scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 4d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 69 lines — stays where its author put it; the contents beside it link to each section on GitHub.
dep-audit
Audit and update project dependencies: find outdated packages, check for vulnerabilities, auto-update safely with lockfile regeneration.
When to Use
- Checking for outdated dependencies
- Scanning for CVEs / security vulnerabilities
- Updating packages safely (minor/patch)
- Managing dependency conflicts
- Regenerating lockfiles after updates
Supported Ecosystems
| Ecosystem | Lockfile | Audit | Outdated | Update |
|---|---|---|---|---|
| npm/yarn/pnpm | package-lock.json / yarn.lock / pnpm-lock.yaml | ✅ | ✅ | ✅ |
| pip | requirements.txt / Pipfile.lock | ✅ (pip-audit) | ✅ | ✅ |
| cargo | Cargo.lock | ✅ | ✅ | ✅ |
| go | go.sum | ✅ (govulncheck) | ✅ | ✅ |
Scripts
scripts/dep-check.sh [path]
Universal dependency checker. Auto-detects ecosystem, runs security audit, and lists outdated packages.
bash scripts/dep-check.sh /path/to/project
scripts/safe-update.sh [path] [--major]
Safely updates dependencies (minor/patch by default). Creates a git stash before updating, regenerates lockfile. Use --major for major version bumps (interactive confirmation).
bash scripts/safe-update.sh /path/to/project
bash scripts/safe-update.sh /path/to/project --major
scripts/outdated.sh [path]
Lists all outdated dependencies with current vs latest versions, grouped by severity (patch/minor/major).
bash scripts/outdated.sh /path/to/project
References
references/update-strategies.md— Safe update workflows and strategiesreferences/semver-guide.md— Semver rules and common gotchasreferences/breaking-changes.md— Common breaking changes by ecosystem
Tips
- Always run
dep-check.shbeforesafe-update.shto understand the landscape - For monorepos, run from the root — scripts detect workspace configs
- Use
--majorflag with caution; review changelogs first - After updating, run the project's test suite to verify nothing broke
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 4d ago First seen · 69 lines · 26 tokens per session scan A 30b6d0eda706
dep-audit is a skill published in the GitHub repository JansenAnalytics/claudex (5 stars, last pushed 2mo ago), licensed MIT. It adds 26 tokens to every session and 551 once invoked, about $0.0001 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other skills, from other repositories
dependency-manager
Manage project dependencies — update packages, audit vulnerabilities, resolve conflicts, and keep dependencies healthy. Use when updating packages, fixing vulnerability alerts, or resolving dependency issues.
dependency-audit
Dependency auditing: vulnerability scanning, license compliance, outdated package detection, and update strategies. Use when checking or updating project dependencies.
task-management
Task management CLI for tracking and managing feature subtasks with status, dependencies, and validation.
depsguard
Install and run DepsGuard, a zero-dependency CLI that scans and fixes package manager configs (npm, pnpm, yarn, bun, uv) for supply chain security best practices.
plugin-publish
发布 Zhin.js 插件到 npm 和 Zhin 插件市场。Use when asked to publish a plugin, prepare for release, check publish readiness, or submit to the Zhin plugin marketplace. 引导完成发布前检查、版本管理和提交流程。.
dependency-checker
Run npm audit --json against the target project and summarise high/critical vulnerabilities.