Agent Plugins Marketplace
All plugins

dependency-audit

v1.1.0

Evidence-first dependency auditing: runs each ecosystem's real audit tooling for CVEs, outdated packages, license obligations and supply-chain signals, and reports only tool-verified facts under TOOL-REPORTED, INFERRED and UNKNOWN evidence tiers. Obligations-based license analysis instead of a compatibility matrix, and strictly non-destructive remediation.

Codex1 Skill

By Alfio CaprinoLicense: MIT8 GitHub starsUpdated 3 hours ago

Directory evidence

Runtimes
Codex
Parsed components
1 skill or MCP entry
Source updated
Aug 26, 2026
Manifest status
Canonical path parsed

The directory validates manifest shape and source location. It does not execute the plugin or provide a security endorsement. Review the indexing methodology

Install plugin

Installs for the current user
codex plugin marketplace add IchenDEV/agent-plugin-mkt
codex plugin marketplace upgrade agent-plugin-marketplace
codex plugin add dependency-audit-2@agent-plugin-marketplace

Paste and run these commands in a terminal with Codex. They add and refresh the PluginsMP catalog, then install this plugin.

The installer fetches third-party code from the source repository shown on this page. This directory validates manifest structure and source location, but does not perform a security audit; review the manifest, components, and source before installing.

Get the source manually
git clone https://github.com/acaprino/daodan

Clone the source repository, then follow its setup instructions to add the plugin to a compatible client. The plugin root is exports/codex/plugins/dependency-audit/.

Plugin files

exports/codex/plugins/dependency-audit/
├── .codex-plugin/plugin.json
└── skills/dependency-audit/SKILL.md

Included Skills1

dependency-auditskills/dependency-audit/SKILL.md

Knowledge base for the evidence-first method: the per-ecosystem tool matrix, the obligations analysis model, and the verifiable signal catalog. TRIGGER WHEN: auditing dependencies for vulnerabilities, license obligations, outdated packages, or supply-chain risk in any ecosystem; loaded by the /dependency-audit:deps-audit command. DO NOT TRIGGER WHEN: dead-code or unused-dependency cleanup (use senior-review:code-review or typescript-development:knip), Python-only lint/type audits (use python-development:python-audit), or code-level security review (use senior-review:security-auditor).

Plugin manifests1

exports/codex/plugins/dependency-audit/.codex-plugin/plugin.json
{
  "author": {
    "name": "Alfio Caprino"
  },
  "description": "Evidence-first dependency auditing: runs each ecosystem's real audit tooling for CVEs, outdated packages, license obligations and supply-chain signals, and reports only tool-verified facts under TOOL-REPORTED, INFERRED and UNKNOWN evidence tiers. Obligations-based license analysis instead of a compatibility matrix, and strictly non-destructive remediation.",
  "license": "MIT",
  "name": "dependency-audit",
  "version": "1.1.0"
}

If you maintain this plugin, link to this source-backed listing from your README so users can review its manifest and indexed components.

[dependency-audit on Agent Plugins Marketplace](https://pluginsmp.com/plugins/dependency-audit-2)