Check Deps
Check dependencies for vulnerabilities and outdated packages
- Type
- Slash Command
- Repository
- jeremylongshore/tons-of-skills-marketplace
- GitHub stars
- 2.8k
- License
- MIT
- Repo last updated
- Sep 27, 2026
What Check Deps is
Check Deps is a slash command published in the jeremylongshore/tons-of-skills-marketplace repository on GitHub, which has about 2.8k stars. The repository describes itself as: “Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com.”
A slash command is a reusable prompt saved as a markdown file and run by typing its name after a slash. In Claude Code, custom commands have been merged into skills: a file in .claude/commands/ and a skill folder in .claude/skills/ both create the same kind of command, and existing command files keep working.
Check Deps gives you a repeatable way to run the same instructions without retyping them, optionally with arguments.
How to install Check Deps
Claude Code
- Download check-deps.md from the repository.
- Save it to ~/.claude/commands/ (all projects) or .claude/commands/ (one project). As a skill, you can instead save it as ~/.claude/skills/<name>/SKILL.md.
- Run it by typing / followed by its name.
Claude Cowork
- Turn the command into a skill: create a folder with the file saved as SKILL.md and zip it.
- In Customize → Skills, click +, then upload the ZIP.
- Run it from any task with / and the skill name.
New to extending Cowork? Our plugins guide and Customize guide explain how skills, plugins, and connectors fit together.
Inside the source file
An excerpt from plugins/security/dependency-checker/commands/check-deps.md, shared under the repository's MIT license. Read the full file on GitHub.
Analyze project dependencies for known vulnerabilities, outdated packages, and license compliance issues.
Analysis Process
- Detect Package Manager
- Identify package.json (npm/yarn/pnpm)
- Identify requirements.txt/Pipfile (pip)
- Identify composer.json (PHP)
- Identify Gemfile (Ruby)
- Identify go.mod (Go)
- Vulnerability Scanning
- Check against CVE databases
- Identify known security advisories
- Report CVSS scores
- Check transitive dependencies
- Version Analysis
- Identify outdated packages
- Check for available security patches
- Report breaking vs. non-breaking updates
- Suggest safe upgrade paths
- License Compliance
- Scan dependency licenses
- Flag incompatible licenses
- Report license obligations
Report Output
Generate comprehensive dependency report with:
- Vulnerable packages with CVE details
- Outdated packages with available versions
- License compliance issues
- Recommended updates with impact analysis
- Upgrade commands for each package manager
Best Practices
- Run before every deployment
- Update dependencies regularly
- Review transitive dependencies
- Use lock files (package-lock.json, Pipfile.lock)
- Test after updating dependencies
Before you install
- Read the whole file first. Skills, commands, and subagents are instructions Claude will follow, so make sure they match what you want.
- Check which tools, scripts, or MCP servers it uses. Local servers and scripts run with your permissions.
- Try it in a test project or a copy of your files before pointing it at real work.
- Pin the version you tested, and review changes before updating.
- Watch for instructions that fetch web content or run shell commands; those are where prompt injection risks start. See our prompt injection guide.
FAQ
What is Check Deps?
Check Deps is a slash command for Claude Code and Claude Cowork from the jeremylongshore/tons-of-skills-marketplace repository on GitHub. Check dependencies for vulnerabilities and outdated packages
How do I install Check Deps in Claude Code?
Download check-deps.md from the repository. Save it to ~/.claude/commands/ (all projects) or .claude/commands/ (one project). As a skill, you can instead save it as ~/.claude/skills/<name>/SKILL.md. Run it by typing / followed by its name.
Can I use Check Deps in Claude Cowork?
Turn the command into a skill: create a folder with the file saved as SKILL.md and zip it. In Customize → Skills, click +, then upload the ZIP. Run it from any task with / and the skill name.
Is Check Deps safe to install?
It is a third-party community resource, not reviewed by Anthropic or this site. Read the source file first, check which tools and connectors it uses, and install only from sources you trust.
Similar resources
- Analyze Coverage Analyze code coverage metrics and identify untested code Slash Command · jeremylongshore/tons-of-skills-marketplace
- Analyze Trends Analyze price trends with technical indicators, pattern recognition, and Slash Command · jeremylongshore/tons-of-skills-marketplace
- Analyze Pool Analyze liquidity pools for APY, impermanent loss, and optimization Slash Command · jeremylongshore/tons-of-skills-marketplace
- Analyze Sentiment Analyze market sentiment from social media, news, and on-chain metrics Slash Command · jeremylongshore/tons-of-skills-marketplace
- Clean Remove old sprint directories with safety checks and archiving options Slash Command · jeremylongshore/tons-of-skills-marketplace
- Changelog Weekly Generate a changelog draft for the last 7 days Slash Command · jeremylongshore/tons-of-skills-marketplace
- Cloudformation Generate Convert Terraform to CloudFormation or generate CFN templates Slash Command · jeremylongshore/tons-of-skills-marketplace
- Changelog Validate Validate changelog config, tokens, and template paths Slash Command · jeremylongshore/tons-of-skills-marketplace