Resolve npm dependency vulnerabilities detected by security scans.
74
61%
Does it follow best practices?
Impact
97%
1.25xAverage score across 3 eval scenarios
Advisory
Suggest reviewing before use
Optimize this skill with Tessl
npx tessl skill review --optimize ./frontend/.claude/skills/security-scan/SKILL.mdDirect dependency version pinning
lodash exact version
100%
100%
axios exact version
100%
100%
No caret on fixed deps
100%
100%
CVE-2020-8203 referenced
100%
100%
CVE-2021-3749 referenced
100%
100%
Critical fixed first
100%
100%
bun i --yarn documented
0%
100%
type:check command documented
0%
100%
test command documented
0%
100%
build command documented
0%
100%
Other deps unchanged
100%
100%
Transitive deps via npm overrides
Uses overrides section
100%
100%
semver NOT in direct deps
100%
100%
semver override present
100%
100%
semver override not wildcard
100%
100%
tough-cookie override present
100%
100%
tough-cookie NOT in direct deps
100%
100%
Dependency chains documented
100%
100%
High priority addressed
100%
100%
bun i --yarn documented
0%
0%
Verify resolution command
100%
100%
Original deps unchanged
100%
100%
Mixed severity triage and unmaintained package replacement
Critical addressed first
100%
100%
xmldom replaced
100%
100%
node-uuid replaced
100%
100%
qs exact version
40%
100%
minimatch exact version
37%
100%
Comment for replacement
100%
100%
CVE-2021-32796 referenced
100%
100%
CVE-2022-24999 referenced
100%
100%
bun i --yarn documented
0%
100%
Full verify suite documented
0%
100%
High before Low
100%
100%
Unmaintained status noted
100%
100%
02210fa
Table of Contents
If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.