sca-pip-audit

Run pip-audit for Python dependency vulnerability scanning. Checks installed packages and requirements files against the OSV and PyPI advisory databases.

Safety Notice

This listing is imported from skills.sh public index metadata. Review upstream SKILL.md and repository scripts before running.

Copy this and send it to your AI assistant to learn

Install skill "sca-pip-audit" with this command: npx skills add vchirrav/product-security-ai-skills/vchirrav-product-security-ai-skills-sca-pip-audit

SCA Scan with pip-audit (Python)

You are a security engineer running Software Composition Analysis (SCA) on a Python project using pip-audit.

When to use

Use this skill when asked to check Python dependencies for vulnerabilities.

Prerequisites

  • pip-audit installed (pip install pip-audit)
  • Verify: pip-audit --version

Instructions

  1. Identify the target — Determine the Python project or requirements file.
  2. Run the scan:
    pip-audit --format=json --output=pip-audit-results.json
    
    • From requirements file: pip-audit -r requirements.txt --format=json --output=results.json
    • Strict mode (fail on any vuln): pip-audit --strict --format=json
    • Fix automatically: pip-audit --fix
    • With descriptions: pip-audit --desc --format=json
  3. Parse the results — Read JSON output and present findings:
| # | Package | Installed | Fixed Versions | Vulnerability ID | Description |
|---|---------|-----------|---------------|-----------------|-------------|
  1. Summarize — Provide:
    • Total packages audited vs vulnerabilities found
    • Packages with available fixes
    • Upgrade commands: pip install --upgrade <package>==<fixed-version>
    • Packages with no fix available (may need alternatives)

Source Transparency

This detail page is rendered from real SKILL.md content. Trust labels are metadata-based hints, not a safety guarantee.

Related Skills

Related by shared tags or category signals.

Security

malware-scan-yara

No summary provided by upstream source.

Repository SourceNeeds Review
Security

network-scan-nmap

No summary provided by upstream source.

Repository SourceNeeds Review
Security

mobile-security-mobsf

No summary provided by upstream source.

Repository SourceNeeds Review
Security

dast-nuclei

No summary provided by upstream source.

Repository SourceNeeds Review