复制安装命令
用 Codex 或 Claude 安装复制这段 Prompt,粘贴到 Codex、Claude 或其他助手里,让它先审查 Skill 页面再帮你安装。
复制前请先查看来源、License 和安全提示。
Your landlord kept your deposit.
用 Codex 或 Claude 安装复制这段 Prompt,粘贴到 Codex、Claude 或其他助手里,让它先审查 Skill 页面再帮你安装。
复制前请先查看来源、License 和安全提示。
来源文件:README.md
Your landlord kept your deposit. Your mom got a medical bill that makes no sense. You got laid off on a Tuesday. Someone you love died, and no one handed you the checklist.
Generic AI gives you filler for the moments that matter most. PM Skills gives your AI the exact framework a senior professional would use — for 1,117 real tasks, across work and life.
🍼 New parent · 💼 Just laid off · 🌍 New to this country · 👵 Caring for a parent · 🕊️ Losing someone · 💸 Money in crisis · 🔑 Starting over · 🤖 Getting serious about AI
PM Skills is an open-source library of 1117 Agent Skills — plain-markdown SKILL.md files that teach an AI assistant to do one professional task to a senior professional's standard, from writing a PRD to decoding a lease or running a blameless postmortem. Each skill bundles the framework, an output template, quality checks, and anti-patterns. It is MIT-licensed and works with Claude, ChatGPT, Gemini, Cursor, and Codex.
Decode a lease before you sign it. Write a PRD your team can execute. Simulate the promotion committee before the real one meets. Check the weather with zero API keys. Generic AI gives you filler; these give you the structure a senior professional actually uses.
Works natively in Claude Code and Hermes Agent, with ready-to-paste exports for ChatGPT, Gemini, Cursor, Codex and 8 more tools. (PM stands for Professional, not just Product Management.)
/plugin, search pm-skills, install. Done — ask "decode this lease" and watch.npx pm-claude-skills add and pick your tool from the menu (Cursor, Codex, Windsurf, ChatGPT, Gemini…).Nothing here can scare your setup. A skill is a markdown file your AI reads — no runtime, no telemetry, no accounts. Installing copies text files; uninstalling is deleting them. Skeptical? Good instinct: read one first — it's designed to be read by humans too.
Don't know what to look for? Describe your task in plain words at 🔎 find — "my landlord kept my deposit", "board meeting on Thursday" — and it names the skill.
Never miss a new skill. New ones drop regularly — subscribe to the newsletter and get a short email with a real example whenever they launch. No spam, unsubscribe anytime. Prefer no email? Follow via RSS or browse the newsletter archive.
Most skills here answer "do this task." A new family answers "think differently about my life."
LLMs have one big weakness: they're too correct. On open-ended questions they give the safe, average, textbook answer — technically right and completely forgettable. Two new bundles fight that head-on (inspired by parallel-divergent-ideation research):
💭 pm-thinking — think betterEscape the generic answer and stress-test your own decisions:
|
🎯 pm-focus — get unstuckADHD-friendly executive function (useful for everyone):
|
It's not just a folder of files — the whole library is explorable, runnable, and a little bit magic. All of this runs in your browser, free, nothing to install:
▶ Pick a skill → fill a short form → run it → a senior-grade artifact streams out. No install, your key stays in your browser (or run free with no key).
🌌 Galaxy 3D — fly through all 1117 skills as a living constellation. The ones you've run burn brighter. |
🎁 Wrapped — your practice, as a shareable story. 100% local — nothing leaves your browser. |
▶ Open the Playground to run any of the 1117 skills with your own key — or just browse them all.
Anything below is a real ask that activates a real skill — say it in your own words, the description does the routing:
| 🏠 "decode this lease before I sign" → lease-decoder | 📋 "write the PRD for our referral feature" → prd-template | 🚨 "blameless postmortem for Friday's outage" → incident-postmortem |
| 💰 "practice my salary negotiation" → salary-negotiation | 📉 "why is churn up this quarter?" → churn-analysis | ⚖️ "rank the backlog with RICE" → rice-prioritisation |
| 🛂 "prep me for the visa interview" → the-visa-interview | 🔨 "is this contractor quote fair?" → home-contractor-quote-decoder | 🏡 "should we rent or buy?" → rent-vs-buy |
| 📝 "draft my self-review honestly" → performance-review | 🚀 "are we ready to launch?" → product-launch-checklist | 📬 "my inbox is 4,000 deep" → email-triage-system |
…all 1117 asks live in the catalog.
| You want to… | Do this |
|---|---|
| Browse the skills | SKILLS.md — the full catalog · or the searchable web catalog |
| Install in Claude Code | /plugin → search pm-skills (it's in the official Anthropic directory) — or npx pm-claude-skills add --agent claude |
| Install in Cursor / Codex / Windsurf / Cline… | npx pm-claude-skills add --agent cursor (or codex, windsurf, aider, cline, zed…) |
| Use one skill in ChatGPT / Gemini | Copy it from exports/chatgpt/ or exports/gemini/ and paste as instructions |
| Skills over MCP, in any session | claude mcp add pm-skills -- npx -y pm-claude-skills-mcp |
No npm install needed — npx pm-claude-skills … always runs the latest. npx pm-claude-skills list shows everything in your terminal. Full per-tool instructions: docs/installation.md.
Every skill follows the same discipline: what it produces, the inputs it needs, a real framework (severity scales, decision rules — not vibes), a concrete output template, quality checks, and anti-patterns. All 1117 pass the SkillSpec L3 gate and a security audit in CI.
| Decoders | Simulators | Calculators | Live data | Cowork | Tokens | Seatbelt | Essentials |
Browse all 1,099 → · try one in your browser →
| Family | What it does | Examples (of many) |
|---|---|---|
| 🔍 Decoders (25+) | Read the document before you sign it — plain language, 🔴🟡🟢 severity, the money math | lease · medical bill · job offer · severance · insurance policy · contractor quote · timeshare |
| 🎭 Simulators | Face the adversary early — the real meeting, then an out-of-character debrief | salary negotiation · promotion committee · thesis defense · visa interview · due-diligence call |
| 🧮 Calculators | Deterministic Python scripts + honest models — assumptions labeled, no false precision | rent vs buy · FIRE number · debt payoff · raise vs jump · daycare vs stay-home |
| 📡 Live data (17) | Real-time answers with zero API keys — weather, rates, flights, scores, all over plain curl | weather · currency · crypto · flights · earthquakes · is-it-down |
| 🏠 Life admin | The unglamorous logistics, done in order | relocation · new parent · caregiving · doctor visits · records requests |
| 💼 Career moments | The weeks that decide years | layoff kit · resignation kit · PIP response · first 90 days as manager · interview gauntlet |
| 🏛 Dead mentors (5) 🆕 | History's sharpest operators, resurrected — the real methods from public-domain classics, applied to modern work | Machiavelli on office politics · Sun Tzu on picking your fights · Franklin's decision algebra · Marcus Aurelius on bad days · Bennett's 1908 time audit |
| 🏛 Life systems (20) 🆕 | Navigating the bureaucracies and emergencies people face alone — civic, disability, immigration, disaster | voting-navigator · disability-benefit-appeal · arrival-setup · credential-recognition · go-bag-builder · after-the-disaster |
| 🧠 Human edges (20) 🆕 | The parts of life nobody built tools for — neurodivergence, invisible illness, grief, identity, the hard conversations | masking-budget · spoon-planner · diagnosis-limbo-kit · coming-out-rehearsal · grief-admin · rabbit-hole-rescue |
| ⚡ New-gen (10) 🆕 | How the next generation lives and earns — creator deals, clips, D&D, ranked, resale, the attention war | creator-deal-decoder · clip-factory · ttrpg-session-forge · the-vibe-check · ranked-climb-coach · attention-reset |
| 🔮 2027 (10) 🆕 | Problems you don't have yet, but will — the agent era's operational skills | agent-severance · deepfake-drill · agent-hiring-panel · context-bankruptcy · clone-brief · api-for-yourself · the-org-simulator |
| 🎲 Tabletop (5) 🆕 | Game night, upgraded — teach, judge, plan, design, and practice the trades | teach-the-game · rules-lawyer · game-night-planner · board-game-designer · tabletop-negotiator |
| 🧾 Freelance & renters & parents | Small bundles for specific lives | pricing your services · late invoices · deposit recovery · IEP meetings · students |
| 🎲 Hobbies (12) 🆕 | Life outside work — the genuinely fun stuff | wine pairing · houseplant care · board-game night · D&D campaign · stargazing · chess openings |
| 💪 Wellbeing (12) 🆕 | Body and mind, sustainably — not another app streak | home workout · sleep reset · habit builder · posture reset · screen-time detox |
| 🔐 Digital self-defense (12) 🆕 | When your digital life is under attack | identity-theft recovery · phishing triage · account recovery · data-broker removal · doxxing response |
| 👪 Family & relationships (12) 🆕 | The people who matter | new-baby logistics · wedding vows · co-parenting messages · condolences · in-law boundaries |
| 💭 Thinking modes (24) 🆕 | Change how your AI reasons — escape the generic answer, stress-test decisions | the-third-answer · five-minds · decision-panel · red-team-my-plan · devils-advocate · poke-holes-in-this |
| 🎯 Focus & executive function (26) 🆕 | Get unstuck and run your own brain — ADHD-friendly, for everyone | where-do-i-start · task-to-first-step · overwhelm-triage · the-one-thing · build-my-memory-file · weekly-unstuck |
| 📖 Learning & mastery (10) 🆕 | Learn anything faster and make it stick | learn-anything-roadmap · feynman-explainer · spaced-repetition-setup · skill-plateau-breaker · deliberate-practice-plan |
| 💰 Wealth-building (10) 🆕 | Build wealth on purpose — educational, not financial advice | investing-for-beginners · index-fund-starter · ask-for-a-raise · first-100k-plan · financial-independence-roadmap |
| 🤝 Social & relationships (10) 🆕 | The hard conversations and the human ones | make-friends-as-an-adult · networking-for-introverts · boundary-setting-scripts · give-hard-feedback-kindly · repair-after-a-fight |
| 🩺 Caregiving & aging (10) 🆕 | Care for aging parents and navigate the system — not medical/legal advice | medical-appointment-advocate · care-team-coordinator · caregiver-burnout-check · long-term-care-options · end-of-life-wishes-conversation |
| 🤖 AI-native life (10) 🆕 | Use AI itself well — the meta-skills that make every tool better | prompt-library-builder · delegate-to-ai · ai-context-primer · spot-ai-mistakes · get-more-from-ai |
| 🤝 Cowork (100) | The office knowledge work an AI coworker actually does — the frameworks — the whole bundle | email triage · spreadsheet audit · meeting cost meter · deck outline first · saying no kindly · delegation brief |
| ⚡ Cowork · Live (12) | The same jobs, done — Claude Cowork acts on your real data via connectors + sandbox and returns an artifact — the whole bundle | inbox triage (live) · meeting prep (live) · spreadsheet audit (live) · deck from doc · thread → decision · PR description (live) |
…plus HR, sales, operations, research, healthcare, educators, writers, social media, and more — the full profession index, or by bundle in plugins/ (121 bundles). Install any bundle: /plugin install pm-decoders@pm-skills.
Before installing anyone's skills (including these): skill-vetting — a security read for SKILL.md files. The library's own standard lives in SKILLSPEC.md; every skill's level is enforced in CI.
A skill is a single markdown file with a name, a description that tells the assistant when to activate it, and a body containing the working framework: required inputs, decision rules or severity scales, a concrete output template, quality checks, and anti-patterns. The assistant reads it and gains the judgment; humans can read, audit, and edit the same file. No runtime, no lock-in.
---
name: lease-decoder
description: "Decode a residential lease into plain English and rank the
clauses that can hurt you. Use when someone asks 'what am I signing'…"
---
## Framework: Severity Scale
- 🔴 Can cost you real money — auto-renewal into a full new term, break
penalties beyond re-rental costs, deposit conditions written to fail…
That's the whole trick: it's markdown. Your agent reads it and gains the judgment; you can read it too, audit it, edit it, or write your own. No lock-in, no runtime, no telemetry.
The pm-tokens bundle optimizes every stage of your agent's token journey — no API keys, stdlib Python, nothing leaves your machine. Five habits, typically 30–60% off a session's token flow:
# 1. Map the repo instead of reading it (~3% of the cost of reading everything)
python3 skills/repo-map/scripts/repo_map.py .
# 2. Crush bulk before it enters context (98% smaller on uniform JSON; errors always survive)
python3 skills/context-crusher/scripts/context_crush.py --mode json --file response.json
# 3. Measure what anything costs — at YOUR prices, times YOUR call volume
python3 skills/token-cost/scripts/token_cost.py --file CLAUDE.md --price-in 3 --calls 200
Plus the judgment skills: token-diet (output costs 3–5× input — diet it where safe), context-budget (cache-aware layout: stable first, volatile last), and session-handoff (resume at ~5% of transcript size). See your own breakdown in the 🪙 Token Dashboard — paste what rides in your context, get computed per-piece savings, all in-browser. The full how-to: docs/SAVE-TOKENS.md.
The pm-cowork bundle is 100 skills for the office work an AI coworker actually does. Install it (/plugin install pm-cowork@pm-skills), then — the whole trick — describe your mess, don't name the skill: say "my inbox is 4,000 deep", "nobody reads my status updates", "this spreadsheet came from someone who left" — the right skill activates on the ask.
Start where it hurts:
| Your pain | Say this | The skill that answers |
|---|---|---|
| Drowning in email | "triage my inbox and cut the volume at the source" | email-triage-system → inbox-unsubscribe-purge |
| Calendar is all meetings | "audit my recurring meetings and price them" | standing-meeting-audit + meeting-cost-meter |
| Inherited a scary spreadsheet | "audit this sheet before we trust it" | spreadsheet-audit → formula-detangler |
| Docs get rewritten in review | "outline first, get sign-off, then draft" | outline-before-prose |
| Weeks just happen to you | "set up my weekly review" | weekly-review-ritual — the hub the others plug into |
Three habits that compound: (1) The weekly review is the keystone — it feeds task-triage-matrix, deep-work-blocking, and personal-wip-limits automatically. (2) The skills chain on purpose — email-to-tasks feeds the task triage; the meeting audit feeds async-instead; delegation-brief hands off what the triage says to shed — follow the links inside each skill. (3) Teams adopt one norm at a time — start with agenda-or-cancel or working-agreements, let it stick, then add the next; the ten-norms-on-Monday rollout is how none of them survive.
Two CLI tools for the trust-and-cost problems the ecosystem keeps hand-waving — both keyless-to-inspect, both one command:
# Does your skill actually work? Prove it. Paired A/B — skill on vs off, same tasks,
# REAL token counts from the API's usage fields, optional blind judge, sha-pinned receipt.
npx pm-claude-skills prove --skill ./my-skill --tasks tasks.txt --runs 2 --judge
npx pm-claude-skills prove --skill ./my-skill --tasks tasks.txt --dry-run # plan + call count, spends nothing
# Your MCP servers are charging you rent. Measure it: per-server token cost,
# unused-in-N-days flags, "disconnect these three, save X tokens per message".
npx pm-claude-skills mcp-audit --connect
prove exists because the ecosystem is full of "65% better!" claims and almost none are measured — it's the honest-broker harness (the JetBrains "advertised 65%, measured 8.5%" story is exactly why). mcp-audit reads your Claude configs, speaks real MCP to each server to count its schema tokens, and scans your session logs for what you actually use. See also the 📊 AI Spend page — every agent's cost (Claude Code, Codex, Copilot) in one meter, all in-browser.
Agent safety: the pm-seatbelt bundle is the pre-flight checklist before an agent touches email, the browser, or files — least-privilege reviews, prompt-injection spotting, and the blast-radius drill for going autonomous. And RFC 0002 — HANDOFF.md is a dead-simple session-handoff convention (your agent, but it remembers Monday) — a file, not a server, with reference hooks.
The library grew an ecosystem — all optional, all linked from the full showcase:
📄 The one-page cheatsheet — the whole library on one printable poster · ▶ Skill Playground — try any skill in your browser, no install · 📸 the Gallery — the creative side, in screenshots · Anti-Pattern Museum — 2,900+ shareable rules · The Handbook (also a real printed book) · Workflow recipes · Subagents & slash commands · MCP server + REST API · n8n / Slack / Obsidian integrations · The Boardroom · SkillBench · Org Edition · 🇪🇸 🇫🇷 🇨🇳 🇯🇵 translations
The validator that keeps these 1,099 honest, as a GitHub Action:
- uses: mohitagw15856/pm-claude-skills@v76
with:
path: .claude/skills # optional — it finds them otherwise
It checks frontmatter, the Use when … trigger clause a model actually matches
on, leftover template text, and structure — and annotates each finding inline
on the pull request diff, because a finding on the line beats a finding in a
log nobody opens. Also available as npx pm-claude-skills skillcheck.
Zero dependencies, no Docker image, no model call.
A skill can tell a model to check the contrast. Only arithmetic can actually check it. Where a question has a right answer rather than a good one, the skill calls out to a tool instead of estimating — both are MIT, zero-dependency, and neither makes a model call, so they cost nothing to run and return the same answer every time.
notugly — design systems that are
provably not ugly. #777777 on white is 4.478 and fails AA; #767676 is 4.542
and passes, and no amount of looking at a screenshot separates those.
accessibility-audit, design-system-audit, design-handoff-brief,
brand-guidelines and the Figma reviews now fill their contrast rows from
npx notugly; the MCP server exposes check_contrast directly; and
design-system-generate wraps it for the case
where there is no design system and something ships on Thursday.
rulebook — 37 games, 203
rulings, and how commonly each house rule is actually played.
board-game-night-planner uses it for teach
times and for settling the argument, because a rules disagreement is usually two
groups who learned it differently and are both partly right.
v76.2.1 — SkillCheck as a GitHub Action, and the design skills now compute their contrast numbers instead of estimating them.
Everything else is in the changelog and the releases — a README should say what this is, not what it was.
Add a skill via PR (the standard, CONTRIBUTING), request one via issue, or publish your own repo to the community index and earn the badge. Translations follow the pattern in skills-i18n/.
If a skill saved you real money or a real mistake, star the repo — it's how others find it. Sponsors fund the playground's free runs and get naming rights, not influence: become a sponsor.
MIT — use them, fork them, ship them at work. Skills are judgment, and judgment wants to be free.
Built by Mohit with Claude. 1117 skills · 121 bundles · 35 professions · every commit gated. The long version of this README — every feature, wave, and frontier bet — lives in the Showcase.
name: dependency-audit
description: "Audits project dependencies for security vulnerabilities, license compliance issues, outdated packages, and transitive dependency risk. Use when asked to audit dependencies, review package security, check license compliance, assess dependency health, or produce a vulnerability report. Produces a vulnerability findings table, license compliance matrix, update priority matrix, dependency health score, and 30-day remediation plan."Produce a complete dependency audit report for a project — covering security vulnerabilities (with CVE references), license compliance against policy, outdated packages prioritised by risk, transitive dependency risk analysis, and a concrete remediation plan with timeline. A good dependency audit gives the team a clear, prioritised action list — not a raw dump of audit output that no one acts on.
Ask for these if not already provided:
package.json, requirements.txt, go.mod, pom.xml, etc., or provide the audit tool outputEcosystem: [npm / pip / Maven / Go / etc.] Audit date: [Date] Auditor: [Name] Total direct dependencies: [N] Total transitive dependencies: [N] Audit tool(s) used: [npm audit / pip-audit / Snyk / OWASP Dependency-Check / etc.]
| Category | Finding | Risk level |
|---|---|---|
| Critical vulnerabilities | [N] CVEs requiring immediate action | [Critical / High / Low] |
| High vulnerabilities | [N] CVEs — fix within 7 days | [High / Medium] |
| License violations | [N] packages with non-compliant licenses | [High / Low] |
| Severely outdated packages | [N] packages > 2 major versions behind | [Medium] |
| Packages with no active maintenance | [N] packages — no commits in 12+ months | [Medium] |
| Overall dependency health score | [Score]/100 | [Red / Amber / Green] |
Scoring methodology: Critical CVEs: −20 each. High CVEs: −10 each. License violations: −15 each. Abandoned packages: −5 each. Maximum deduction: 100. Score ≥80 = Green, 60–79 = Amber, <60 = Red.
Immediate actions required:
| Package | Installed version | Fix version | CVE | Severity | CVSS score | Description | Exploitability |
|---|---|---|---|---|---|---|---|
| [package-name] | [X.Y.Z] | [A.B.C] | [CVE-YYYY-NNNNN] | Critical | [9.x] | [e.g. Prototype pollution via merge function — remote code execution possible] | [Known exploit / PoC available / No known exploit] |
| [package-name] | [X.Y.Z] | [A.B.C] | [CVE-YYYY-NNNNN] | High | [7.x] | [e.g. Path traversal in file serving utility] | [PoC available] |
| [package-name] | [X.Y.Z] | [A.B.C] | [CVE-YYYY-NNNNN] | High | [7.x] | [e.g. Regular expression denial of service (ReDoS)] | [No known exploit] |
| Package | Installed version | Fix version | CVE | Severity | CVSS score | Description |
|---|---|---|---|---|---|---|
| [package-name] | [X.Y.Z] | [A.B.C] | [CVE-YYYY-NNNNN] | Medium | [5.x] | [Description] |
| [package-name] | [X.Y.Z] | [A.B.C] | [CVE-YYYY-NNNNN] | Medium | [4.x] | [Description] |
| Package | Installed version | Fix version | CVE | Severity | Description |
|---|---|---|---|---|---|
| [package-name] | [X.Y.Z] | [A.B.C] | Low | [Description] |
| Package | CVE | Severity | Recommended mitigation |
|---|---|---|---|
| [package-name] | [CVE-YYYY-NNNNN] | [High] | [e.g. "Remove this package — alternative: [replacement]"] |
| [package-name] | [CVE-YYYY-NNNNN] | [Medium] | [e.g. "Vendor has a fix in progress — track issue [URL]. Mitigate by [X]"] |
| License | Category | Policy | Notes |
|---|---|---|---|
| MIT | Permissive | Allowed | Attribution required in distributed products |
| Apache 2.0 | Permissive | Allowed | Attribution + NOTICE file required |
| BSD 2-Clause / 3-Clause | Permissive | Allowed | Attribution required |
| ISC | Permissive | Allowed | |
| MPL 2.0 | Weak copyleft | Allowed with review | Source disclosure required for modified MPL files only |
| LGPL v2 / v3 | Weak copyleft | Allowed with review | Dynamic linking permitted; static linking may require disclosure |
| GPL v2 / v3 | Strong copyleft | Restricted | May require open-sourcing the entire codebase — legal review required |
| AGPL v3 | Strong copyleft | Restricted | Network use triggers copyleft — especially risky for SaaS |
| SSPL | Source available | Prohibited | Not OSI-approved — treat as proprietary |
| Proprietary / Commercial | Commercial | Requires contract | Verify license covers current use case and scale |
| Unknown / Unlicensed | — | Prohibited | No license = all rights reserved — cannot use legally |
| Package | License | Issue | Recommendation | Risk if unaddressed |
|---|---|---|---|---|
| [package-name] | GPL v3 | Copyleft — may require open-sourcing this project | Replace with [alternative] or get legal sign-off | Legal / IP risk |
| [package-name] | AGPL v3 | Network copyleft — SaaS use triggers disclosure | Replace with [alternative] | Legal / IP risk |
| [package-name] | Proprietary | License may not cover current usage tier | Verify license scope with vendor | Contract breach |
| [package-name] | Unknown | No license declared in package metadata | Contact maintainer or replace | Cannot use legally |
| License | Package count | Compliance status |
|---|---|---|
| MIT | [N] | Compliant |
| Apache 2.0 | [N] | Compliant |
| BSD-3-Clause | [N] | Compliant |
| ISC | [N] | Compliant |
| MPL 2.0 | [N] | Review required |
| GPL v3 | [N] | Non-compliant |
| Unknown | [N] | Non-compliant |
| Package | Installed | Latest stable | Versions behind | Last updated | Breaking changes summary |
|---|---|---|---|---|---|
| [package-name] | [1.x.x] | [3.x.x] | 2 major | [Date] | [e.g. "API redesign in v2; async support added in v3"] |
| [package-name] | [0.x.x] | [2.x.x] | 2 major | [Date] | [Summary] |
| Package | Installed | Latest stable | Versions behind | Security fix in newer version? |
|---|---|---|---|---|
| [package-name] | [2.x.x] | [3.x.x] | 1 major | [Yes — CVE-YYYY-NNNNN / No] |
| [package-name] | [4.x.x] | [5.x.x] | 1 major | [No] |
| Package | Installed | Latest | Contains security fix? |
|---|---|---|---|
| [package-name] | [2.3.1] | [2.3.9] | [Yes / No] |
| [package-name] | [1.0.0] | [1.2.1] | [No] |
Transitive (indirect) dependencies carry risk because they are not explicitly managed. These are the highest-risk transitive dependencies in this project:
| Vulnerable transitive dep | Pulled in by | Installed version | Fix available | Action |
|---|---|---|---|---|
| [transitive-package] | [direct-parent] | [X.Y.Z] | [Yes — upgrade [parent] to [version]] | Upgrade direct dependency [parent] |
| [transitive-package] | [direct-parent] | [X.Y.Z] | [No] | Remove [parent] or use [alternative] |
These packages are depended on by many other packages in the project — a vulnerability or deprecation would have cascading effects:
| Package | Depended on by (N packages) | Actively maintained? | Risk level |
|---|---|---|---|
| [package-name] | [N] | [Yes / No — last commit: date] | [High / Medium] |
| [package-name] | [N] | [Yes] | [Medium] |
| Package | Last release | Last commit | Weekly downloads | Recommended alternative |
|---|---|---|---|---|
| [package-name] | [Date] | [Date] | [N] | [alternative-package] |
| [package-name] | [Date] | [Date] | [N] | [Maintained fork: URL] |
Week 1 — Critical vulnerabilities (Days 1–7)
| Action | Owner | Package | Effort | Notes |
|---|---|---|---|---|
| Upgrade [package] [old] → [new] | [Name] | [package-name] | [30 min] | [No API changes / check breaking changes guide: URL] |
| Replace [package] with [alternative] | [Name] | [package-name] | [2 hours] | [No fix available — must replace] |
| Patch override for [transitive-dep] | [Name] | [transitive-dep] | [15 min] | [Add resolutions/overrides entry in manifest] |
# Commands for Week 1 upgrades:
# npm
npm install [package]@[target-version]
npm audit fix --force # use with caution — may introduce breaking changes
# pip
pip install --upgrade [package]==[target-version]
pip-audit --fix # if using pip-audit
# Go
go get [module]@[version]
go mod tidy
# Maven
# Update pom.xml version property, then:
mvn versions:use-latest-releases -DallowMajorUpdates=false
mvn dependency:resolve
Week 2 — High vulnerabilities and license violations (Days 8–14)
| Action | Owner | Package | Effort | Notes |
|---|---|---|---|---|
| Upgrade [package] | [Name] | [package-name] | [1 hour] | |
| Replace GPL-licensed [package] | [Name] | [package-name] | [4 hours] | [Alternative: [package]] |
| Legal review for [package] license | Legal team | [package-name] | [Legal team SLA] | [Submit via [process]] |
Week 3 — Medium vulnerabilities and abandoned packages (Days 15–21)
| Action | Owner | Package | Effort | Notes |
|---|---|---|---|---|
| Upgrade [package] | [Name] | [package-name] | [30 min] | |
| Replace abandoned [package] | [Name] | [package-name] | [2 hours] | [Maintained fork or alternative: [URL]] |
Week 4 — Process improvements (Days 22–30)
| Action | Owner | Effort | Notes |
|---|---|---|---|
| Enable Dependabot / Renovate for automated PRs | [Name] | [2 hours] | [Config in Section 6] |
Add npm audit / pip-audit to CI — fail on Critical/High | [Name] | [1 hour] | [Config in Section 6] |
| Document license policy in CONTRIBUTING.md | [Name] | [1 hour] | [Based on policy in Section 2] |
| Schedule next quarterly audit | [Name] | [15 min] | [Add to team calendar] |
Add the following to your CI pipeline to catch vulnerabilities before they merge:
# GitHub Actions — adapt for your CI platform
dependency-audit:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v3
# npm
- name: npm audit
run: npm audit --audit-level=high
# Fails build on High or Critical vulnerabilities
# pip
- name: pip-audit
run: |
pip install pip-audit
pip-audit --requirement requirements.txt --severity high
# Go
- name: govulncheck
run: |
go install golang.org/x/vuln/cmd/govulncheck@latest
govulncheck ./...
# .github/dependabot.yml — automated dependency update PRs
version: 2
updates:
- package-ecosystem: "[npm / pip / gomod / maven]"
directory: "/"
schedule:
interval: "weekly"
day: "monday"
open-pull-requests-limit: 10
labels:
- "dependencies"
- "automated"
ignore:
# Ignore major version bumps — review these manually
- dependency-name: "*"
update-types: ["version-update:semver-major"]
# npm — license checker
npx license-checker --onlyAllow 'MIT;Apache-2.0;BSD-2-Clause;BSD-3-Clause;ISC' \
--failOn 'GPL;AGPL;LGPL'
# Python — pip-licenses
pip install pip-licenses
pip-licenses --allow-only="MIT;Apache Software License;BSD License;ISC License" \
--fail-on="GNU General Public License"
# Go — go-licenses
go install github.com/google/go-licenses@latest
go-licenses check ./... --allowed_licenses=MIT,Apache-2.0,BSD-2-Clause,BSD-3-Clause
| Category | Max points | Score | Notes |
|---|---|---|---|
| No critical vulnerabilities | 30 | [N]/30 | −20 per critical CVE |
| No high vulnerabilities | 20 | [N]/20 | −10 per high CVE |
| License compliance | 20 | [N]/20 | −15 per violation |
| No abandoned packages | 15 | [N]/15 | −5 per abandoned package |
| Up-to-date major versions | 10 | [N]/10 | −2 per major version behind |
| Automated scanning enabled | 5 | [N]/5 | All-or-nothing |
| Total | 100 | [Score]/100 | [Red / Amber / Green] |
评论 (0)
暂无评论,成为第一个评论者吧!