dependency-security-getting-started

$npx mdskill add Significant-Gravitas/skills-catalog/dependency-security-getting-started

Use this at the start of dependency or vulnerability work.

SKILL.md

.github/skills/dependency-security-getting-startedView on GitHub ↗
---
name: "dependency-security-getting-started"
description: "Set up dependency and security hygiene from repository evidence, with a clear scope, source list, risk queue, and approval line."
triggers: ["dependency security", "security hygiene", "dependency review", "start dependency audit", "software supply chain"]
version: "1"
---

# Dependency security getting started

Use this at the start of dependency or vulnerability work.

## Set the scope

Record the repository, branch or commit, supported runtimes, deployed services,
package managers, and environments in scope. Ask which systems face the public,
handle sensitive data, or have strict uptime needs. List anything you cannot
inspect.

## Build the evidence set

Collect manifests, lockfiles, container definitions, software bills of
materials, scanner exports, and the commands used to produce them. Date every
external advisory and release note. Keep requested versions separate from
installed versions.

## Return the first brief

Give the user:

1. Scope and evidence checked.
2. Gaps that could change the result.
3. Confirmed risks, each with package, installed version, source, and exposure.
4. The next three checks or upgrades, in order.
5. Actions that need owner approval.

## Approval line

You may inspect, rank, plan, and draft a patch or pull request. Do not merge,
deploy, suppress a finding, change production, or claim a fix without verified
advisory, stack, version, and test evidence.

More from Significant-Gravitas/skills-catalog

SkillDescription
account-health-and-qbrsUse when a support account wobbles or a quarterly business review looms: read the health signals, run the success plan, and prep the review from evidence.
accounts-receivable-follow-upReview open receivables and draft factual, staged payment follow-ups without inventing status or contacting a customer.
ad-copy-variantsWrite ad variants that each test one idea, within platform limits and supported claims.
alex-getting-startedUse on the first conversation with Alex, or whenever their memory has no product preferences yet: learn what the user is building and who for, where specs, roadmap and numbers live, who decides dates and scope, and get them to a first real product deliverable.
alliance-co-commercializationUse when a strategic alliance needs joint selling governance: operating model, joint targeting, steering prep, and milestone accountability.
anika-getting-startedUse on the first conversation with Anika, or whenever their memory has no partnership preferences yet: learn which partners and alliances the user owns, what motion they run, and get one real partner read on screen in the same session.
assure-partner-led-deliveryUse when partners deliver client work in your name: own the in-flight book, run the weekly delivery review, and rescue engagements before clients feel it.
automate-finance-reportingUse to connect a number source, map an export into the finance ledger, or QA a sheet: the column mapping, the dedupe key, the load summary, and the checks that must pass before a read ships.
billing-refunds-and-exceptionsUse when money is on the table: verify the charge, check the policy, and stage a refund or exception draft that stops at the owner's yes.
board-and-investor-metrics-briefPrepare a concise board or investor metrics brief with definitions, sources, comparisons, drivers, risks, and decisions needed.