dependency-risk-brief
pixelfox2033-vwict/dependency-risk-brief
Transforms raw dependency vulnerability alerts into structured, contextualized one-page risk cards with clear upgrade-versus-defer recommendations.
Overview
This skill acts as a security triage assistant for application owners handling dependency alerts from scanners or advisory feeds. It evaluates actual code exposure, blast radius, severity context, and breaking change risks, outputting a concise decision card that outlines whether to upgrade immediately, defer, or implement mitigating controls.
Capabilities
- ▸Contextual vulnerability triage
- ▸Reachability and exposure analysis
- ▸Blast radius evaluation
- ▸Upgrade-vs-defer decision making
- ▸One-page risk card generation
- ▸Multilingual support (en, zh, bilingual)
Best for
Triaging Dependabot or vulnerability scanner alerts with human context, Deciding whether to immediately patch a critical CVE or defer based on reachability, Explaining dependency risks and upgrade trade-offs to engineering managers, Assessing the blast radius and breaking change risk of major version bumps
Works with
実タスクにどれだけ役立つか(機能の豊富さ・用途の明確さ)。 — AIによるcapabilities/use-cases解析
実装・指示の品質。 — AIによるSKILL.md/README解析
リポジトリがどれだけ活発に保守されているか。 — GitHub 最終push日時の新しさ
ドキュメントの充実度・分かりやすさ。 — README/独自要約の情報量
危険・不審な挙動が無いか。 — AIによるセキュリティレビュー
ありふれたラッパーではない独自性。 — AIによる独自性判定
コミュニティの採用度。 — GitHub Stars/Forks(対数スケール)
対応AIエージェントの広さ。 — AIによる対応エージェント判定
ライセンス不明/制限あり(Red)のSkillは総合スコアに0.85倍の補正を適用します。 ランキングはこのScoreのみで決まり、広告で変わりません。 算出方法の詳細 →
Security considerations
Ensures no exploit recipes or attack steps are generated, and strictly prohibits handling or exposing registry tokens.
Categories
Summary and analysis are original content generated by AI Skills Rank. The skill's source text is not reproduced here — view it on the linked repository.