gh-deps-intel — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited gh-deps-intel (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
Use this as the canonical dependency-upgrade workflow skill. The shared deps-workbench helpers provide lightweight preflight inventory, classification, and usage mapping; this skill remains the deeper GitHub-aware analysis and reporting engine. This skill absorbs the former dep-upgrade-spec role.
execute.plan.execute, still stop if auth, package-manager access, or repo safety checks fail./home/bjorn/.codex/skill-support/bin/deps-workbench inventory --cwd <repo> --out <json>/home/bjorn/.codex/skill-support/bin/deps-workbench classify --input <json> --out <json>/home/bjorn/.codex/skill-support/bin/deps-workbench usage-scan --cwd <repo> --packages <pkg...> --out <json>gh api/CLI only, use scripts/gh_release_diff.py, scripts/gh_compare_notes.py, or scripts/gh_rate_limit_diag.py directly.scripts/gh_deps_intel.py package --dependency <name>.scripts/gh_deps_intel.py full as the single orchestrator path (REST-first with GraphQL fallback for release retrieval).--mode safe; use --mode fast only when the user opts in.plan: Markdown + JSON report + order; no dep mutations.execute: run batches, apply upgrades, repo-native verification, refresh report.gh logged in (gh auth status)python3bun/pnpm/npm/yarn, uvpython /home/bjorn/.agents/skills/gh-deps-intel/scripts/gh_deps_intel.py full --repo . --out reports --mode safereports/dependency-upgrade-report.mdreports/dependency-upgrade-report.jsonsafe (default): serial GitHub API pacing + backoff/retries.fast: bounded parallel enrich; auto fallback to safe on rate limit/errors.python scripts/gh_deps_intel.py full --repo . --out reports --mode safepython scripts/gh_deps_intel.py package --repo . --out reports --mode safe --dependency workflowpython scripts/upgrade_one_dep.py workflow --repo . --out reports --mode safepython scripts/gh_deps_intel.py scan --repo . --out reportspython scripts/gh_deps_intel.py enrich --repo . --out reports --mode safepython scripts/gh_deps_intel.py analyze --repo . --out reports --mode safepython scripts/gh_deps_intel.py rate-limit| Path | Type | Purpose | Use When |
|---|---|---|---|
scripts/gh_deps_intel.py | orchestrator | Scan/enrich/analyze/report end-to-end | Any dep intel request |
scripts/upgrade_one_dep.py | utility | Single-dep package wrapper | One-package refactor spec |
scripts/detect_repo.py | script | Runtime, package managers, workspace | Repo/runtime context only |
scripts/collect_deps.py | script | Deps from package.json + pyproject.toml | Manifest inventory |
scripts/outdated_probe.py | script | Outdated cmds per manager | current/wanted/latest |
scripts/repo_resolver.py | script | Registry meta → GitHub repos | package → repo map |
scripts/gh_release_fetch.py | script | Releases/tags/changelog, cache+retries | Release/changelog text |
scripts/runtime_policy.py | script | Node/Python compatibility targets | Pick compatible version |
scripts/impact_analyzer.py | script | Breaking/deprecations/features, actions | Migration deltas |
scripts/render_report.py | script | Markdown + JSON reports | Final outputs |
scripts/gh_release_diff.py | utility | Release window for owner/repo | Ad-hoc release research |
scripts/gh_compare_notes.py | utility | Compare two refs/tags | No changelog; need commits |
scripts/gh_rate_limit_diag.py | utility | Current rate limit | Check API budget first |
references/workflow.md | reference | Run order + decision tree | Process |
references/command-mapping.md | reference | PM command equivalents | bun/pnpm/npm/yarn/uv/pip map |
references/github-api-endpoints.md | reference | Endpoints + backoff | API details |
references/compatibility-policy.md | reference | Runtime-pinned rules | Version policy |
references/report-spec.md | reference | Schema + sections | Machine+human contract |
references/troubleshooting.md | reference | Failures + mitigations | Auth/rate/parse issues |
Always produce both files in the same stable contract:
For package mode, include:
python scripts/gh_release_diff.py owner/repo --current 1.2.3 --target 2.0.0python scripts/gh_compare_notes.py owner/repo v1.2.3 v2.0.0python scripts/gh_rate_limit_diag.py/home/bjorn/.codex/skill-support/bin/deps-workbench.~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.