pilinux/gorest · Archived

dependency-auditor

Inspect Go module dependencies, detect outdated or vulnerable modules, and recommend safe updates or pinning strategies.

First seen Mar 2, 2026

Installation

$ npx skills add pilinux/gorest --skill dependency-auditor

Stronger alternatives

This repository is archived — consider an actively maintained alternative.

Similar popular skills

Related neighbors and high-traction skills in the same topics — useful to compare before installing.

Also in this package

Other skills from pilinux/gorest · top by installs.

npx skills add pilinux/gorest

Browse all from pilinux/gorest

More details

Agent compatibility

Declared targets from SKILL.md / docs. Unmarked agents are not listed — the skill may still install via the CLI.

Claude Code Not declared
Cursor Not declared
Codex Not declared
GitHub Copilot Not declared
Windsurf Not declared
Gemini CLI Not declared
Cline Not declared
OpenCode Not declared

Repository health

Stars 502
License LICENSE
Default branch main
Open issues 0
Status Archived

Skill metadata

Parsed from SKILL.md frontmatter.

LicenseMIT
More metadata
mode
analysis
purpose
deps

Package contents

Files included with this skill beyond the listing page.

  • skill md SKILL.md 1,092 B
  • docs SUMMARY.md 146 B

History

  1. First seen on skills.sh
  2. First recorded snapshot · 1 installs

SKILL.md

Dependency Auditor

When to Use

  • The user asks to audit go.mod/go.sum for outdated modules or known vulnerabilities.

Responsibilities

  • Run dependency analysis tools to identify updates and CVEs.
  • Suggest minimal version bumps and go.mod edits, including tests to run after updates.

Rules

  • Do not modify go.mod without explicit approval.
  • Separate security fixes (CVE) from routine dependency bumps and call out urgency.

Commands

  • go list -m -u all (list outdated modules)
  • govulncheck ./... (check known vulnerabilities)
  • go mod tidy (recommendation only, do not run without approval)

Output

  • Outdated modules with current and latest versions.
  • Vulnerabilities (CVE) with severity and affected ranges.
  • Recommended next steps and tests to run after updates.

Related Skills

  • ci-orchestrator, static-analysis