sca-audit
Scan project dependencies for known vulnerabilities (CVEs). Use when reviewing dependency files (package.json, requirements.txt, go.mod, pom.xml, Gemfile, Cargo.toml, etc.), triaging Dependabot/Renovate alerts, or performing pre-deployment security checks.
How do I install this agent skill?
npx skills add https://github.com/owasp/secure-agent-playbook --skill sca-auditIs this agent skill safe to install?
- Gen Agent Trust Hubpass
The skill facilitates Software Composition Analysis (SCA) to identify vulnerabilities in project dependencies. It uses standard security tools like osv-scanner and trivy. There is a low risk of indirect prompt injection if an attacker provides a malicious dependency file to be scanned.
- Socketpass
No alerts
- Snykpass
Risk: LOW · No issues
What does this agent skill do?
Software Composition Analysis Audit
Scan dependencies for known CVEs by following the full procedure in plays/sca-audit.md.
Steps
-
Identify Dependency Manifests — Scan for all dependency files and lockfiles across ecosystems (Node.js, Python, Go, Java, Ruby, Rust, .NET, PHP). Prefer lockfiles for exact resolved versions.
-
Run Vulnerability Scan — Use available tools in preference order:
osv-scanner --lockfile=<path> --format=json(recommended, multi-ecosystem)npm audit --json(Node.js)pip-audit -r requirements.txt --format=json(Python)govulncheck ./...(Go)trivy fs --format json --scanners vuln <path>(multi-ecosystem)- If no scanner is installed, stop and ask the user to install one (e.g.,
brew install osv-scanner). Manual analysis is not viable — even small projects have 50+ dependencies. For individual package triage, point the user to OSV.dev.
-
Analyze Results — For each vulnerability: determine reachability (is the vulnerable code path used?), check exploitability context (deployment matters), and identify fix availability (patch vs major version bump).
-
Dependency Health — Beyond CVEs, flag unmaintained packages (2+ years inactive), typosquatting risks, license concerns, and version pinning issues.
Output
Scan summary (ecosystems, dependency count, scanner used), findings sorted by severity using templates/finding.md, condensed table for medium/low, dependency health flags, and exact remediation commands.
OWASP References
- A06:2021: Vulnerable and Outdated Components
- OWASP Dependency-Check
- OWASP SCVS
How can the creator link this skill?
Add the canonical catalog link to the repository README so users can inspect current installs and available audits. The publishing guide covers the complete discovery path.
<a href="https://skillzs.dev/skills/owasp/secure-agent-playbook/sca-audit">View sca-audit on skillZs</a>