MUST be used whenever fixing dependency issues in a Flows app. This skill finds AND fixes vulnerabilities, outdated packages, deprecated dependencies, and license issues — it does not just report them. Triggers: dependencies, packages, fix dependencies, update packages, fix vulnerabilities, npm audit fix, pnpm audit fix, CVE fix, outdated, deprecated, supply chain, license.
Detected risks:
The dependencies-audit skill is intended to be used whenever fixing dependency issues in a Flows app, and it both finds and fixes problems rather than only reporting them. It targets a package.json (the root one if no path is given) and addresses vulnerabilities, outdated packages, deprecated dependencies, license problems, and supply-chain risks, producing the review-packages.md artifact required by the Flows app review process. It is scoped to the Read, Glob, Grep, Shell, and Write tools.
The procedure runs in ordered steps. First it reads and lists all dependencies and devDependencies and records their counts. Next it looks up npm metadata for each package (latest version, weekly downloads, last publish date, and deprecated flag) using npm view and the npm downloads API, batching lookups through a Node script for efficiency, then updates outdated packages: those more than one major version behind are updated to latest, and those a minor or more behind are updated to latest minor, with pnpm install and pnpm run build run afterward and any build-breaking major update reverted and noted as a manual-fix item. It then runs a security audit (including a production-only audit of what ships to users), parses severity counts and per-vulnerability details, treats any package with a known CVE as an automatic Fail, runs pnpm audit fix, manually updates remaining high or critical CVEs, and uses pnpm overrides for vulnerable transitive dependencies before re-running the audit to confirm resolution.
Subsequent steps assign health scores of Pass, Warn, or Fail based on weekly downloads, recency, deprecation, version currency, and known CVEs, with edge-case handling that trusts @cognite/* and @types/* packages and treats very new packages as Warn rather than auto-Fail. Fail-scored packages are then replaced: deprecated ones get their recommended replacement with imports updated across the codebase, unmaintained ones get an actively maintained alternative, and low-download non-Cognite packages are evaluated for removal in favor of a native or inline equivalent. The final steps check for supply-chain risks by detecting install scripts (preinstall, install, postinstall) and mitigating non-build-tool packages with suspicious scripts, and check license compatibility, replacing problematic packages. Each fix is followed by reinstalling and rebuilding to confirm nothing breaks.
It finds and fixes issues. It addresses vulnerabilities, outdated packages, deprecated dependencies, and license problems directly, and produces the review-packages.md artifact rather than just reporting findings.
It produces review-packages.md, the artifact required by the Flows app review process.
Each package gets Pass, Warn, or Fail based on weekly download counts, how recently it was published, whether it is deprecated, how current its version is, and whether it has a known CVE. A known CVE, deprecation, very low downloads, or no update in 2+ years drives a Fail.
@cognite/* packages are trusted even with low download counts, @types/* DefinitelyTyped packages are trusted with focus on version match to the main package, and packages newer than six months are flagged as Warn rather than auto-Fail on low downloads.
It runs pnpm audit fix first, manually updates remaining high or critical CVEs, and for vulnerable transitive dependencies uses pnpm overrides in package.json to force the patched version, then re-runs pnpm audit and the build to confirm.
Quick Setup:
.claude/skills/Repository
cognitedata/builder-skills