dependency-inventory

$npx mdskill add Significant-Gravitas/skills-catalog/dependency-inventory

Use this before judging age or security risk.

SKILL.md

.github/skills/dependency-inventoryView on GitHub ↗
---
name: "dependency-inventory"
description: "Build an evidence-backed inventory of direct, transitive, runtime, development, and container dependencies."
triggers: ["dependency inventory", "list packages", "lockfile review", "SBOM", "what dependencies do we use"]
version: "1"
---

# Dependency inventory

Use this before judging age or security risk.

## Collect

Find every package manifest and lockfile in scope. Include workspace roots,
plugins, examples that ship, container base images, build actions, and language
runtime pins. Prefer installed or locked versions over ranges in manifests.

For each item record:

- ecosystem, package, installed version, and requested range;
- direct or transitive status;
- runtime, development, build, or test use;
- the file and line or tool output that proves it;
- service or image that carries it;
- whether the version could not be resolved.

## Reconcile

Do not merge packages that share a name across ecosystems. Flag duplicate major
versions, unlocked production dependencies, stale generated lockfiles, and
manifests with no matching lockfile. If a scanner and lockfile disagree, show
both and name the check needed to settle it.

## Output

Return a table, an evidence-gap list, and totals by ecosystem and use. Never
infer that a package runs in production only because it appears in a manifest.
Do not call the inventory complete while a deployable service or image remains
unchecked.

More from Significant-Gravitas/skills-catalog

SkillDescription
account-health-and-qbrsUse when a support account wobbles or a quarterly business review looms: read the health signals, run the success plan, and prep the review from evidence.
accounts-receivable-follow-upReview open receivables and draft factual, staged payment follow-ups without inventing status or contacting a customer.
ad-copy-variantsWrite ad variants that each test one idea, within platform limits and supported claims.
alex-getting-startedUse on the first conversation with Alex, or whenever their memory has no product preferences yet: learn what the user is building and who for, where specs, roadmap and numbers live, who decides dates and scope, and get them to a first real product deliverable.
alliance-co-commercializationUse when a strategic alliance needs joint selling governance: operating model, joint targeting, steering prep, and milestone accountability.
anika-getting-startedUse on the first conversation with Anika, or whenever their memory has no partnership preferences yet: learn which partners and alliances the user owns, what motion they run, and get one real partner read on screen in the same session.
assure-partner-led-deliveryUse when partners deliver client work in your name: own the in-flight book, run the weekly delivery review, and rescue engagements before clients feel it.
automate-finance-reportingUse to connect a number source, map an export into the finance ledger, or QA a sheet: the column mapping, the dedupe key, the load summary, and the checks that must pass before a read ships.
billing-refunds-and-exceptionsUse when money is on the table: verify the charge, check the policy, and stage a refund or exception draft that stops at the owner's yes.
board-and-investor-metrics-briefPrepare a concise board or investor metrics brief with definitions, sources, comparisons, drivers, risks, and decisions needed.