deps-vet
Record a vetted Hex package version in hex_vet.exs after a security review — manages the audit ledger, not the scanner. Use to approve a dep after /phx:deps-audit findings or to initialize hex_vet.exs.
Install / Use
npx skills add oliver-kriska/claude-elixir-phoenix --skill deps-vetInstalls into whichever agent you are using.
SKILL.md
Installable skill definition
Quality Score
Category
SecuritySupported Platforms
Our assessment of deps-vet
deps-vet scores 90/100 on our quality scale, 475th of 1,086 Security skills we index (top 44%).
Its SKILL.md is 6.0 KB long, well organised into 14 sections with 4 code examples: a thorough specification that gives an agent plenty to work with.
It has 560 GitHub stars, a meaningful sign that others use it.
Maintenance, license and trust
- The repository was last updated 2 days ago, so deps-vet is actively maintained.
- It is released under the MIT license, a permissive license that allows use, modification and commercial use with attribution.
- Its trust signals score 100/100, with no cautions. These come from repository metadata, not a code audit — read the skill file before letting an agent act on it.
deps-vet compared with similar skills
All 4 of these similar skills score higher than deps-vet; compare them before choosing.
| Skill | Score | Stars | Updated | Format |
|---|---|---|---|---|
| deps-vet (this skill)by oliver-kriska | 90 | 560 | 2d ago | SKILL.md |
| algorithmic-artby anthropics | 100 | 177.9k | 11d ago | SKILL.md |
| pptxby anthropics | 100 | 177.9k | 11d ago | SKILL.md |
| designby nextlevelbuilder | 100 | 130.2k | 12d ago | SKILL.md |
| ui-ux-pro-maxby nextlevelbuilder | 100 | 130.2k | 12d ago | SKILL.md |
Frequently asked questions
- How do I install deps-vet?
- Run
npx skills add oliver-kriska/claude-elixir-phoenix --skill deps-vet. The install tabs above show the steps for each supported agent. - Which AI agents does deps-vet work with?
- It is written for Universal, as a SKILL.md file. Other agents that read the same format can often use it too.
- Is deps-vet safe to use?
- It is MIT-licensed and scores 100/100 on trust signals. Skills are instructions an agent will follow, so read the file before installing it and do not approve commands you do not understand.
- Is deps-vet still maintained?
- The repository was last updated 2 days ago, so deps-vet is actively maintained.
Skill content
View source on GitHubname: deps-vet description: "Record a vetted Hex package version in hex_vet.exs after a security review — manages the audit ledger, not the scanner. Use to approve a dep after /phx:deps-audit findings or to initialize hex_vet.exs." argument-hint: "<pkg> <version> | --seed | --list | --check" effort: medium
Deps Vet — Hex package audit ledger
Review a Hex package version, run Phase 1 supply-chain rules against it,
prompt the user for a verdict, append the result to hex_vet.exs
(project-root audit ledger). Vetted versions get downgraded to INFO
on subsequent /phx:deps-audit runs.
Run this AFTER /phx:deps-audit to clear findings.
Run this BEFORE merging a mix.lock PR to certify new versions.
Usage
/phx:deps-vet phoenix 1.7.21 # vet a single package version
/phx:deps-vet --seed # import curated baseline seed (~30 pkgs)
/phx:deps-vet --list # show existing ledger entries
/phx:deps-vet --check # cross-check mix.lock vs ledger
Iron Laws
- NEVER auto-approve. Every entry MUST come from an
AskUserQuestionconfirmation. Drive-by trust ruins the ledger's value. - Lock wins on disagreement. If
mix.lockhas version X and the ledger vets X-1, emit INFO and treat X as unvetted. Don't silently trust the older entry. - Ledger lives at project root.
hex_vet.exsis a first-class security artifact, visible in PR review. Don't move it into.claude/. - Round-trip via
inspect/2. When appending, read the file withCode.eval_file/1, mutate the map, and write back viainspect(term, pretty: true, limit: :infinity). Hand-rolled string appends drift over time. - Always show findings before prompting. The user must see what's
being vetted. No silent
:safe_to_deploydefaults. - Confirmation counts are COMPUTED, never estimated. Any number in
an
AskUserQuestion(criteria split, new/overwrite/no-op) MUST be derived from the loaded data before prompting — e.g.Enum.frequencies_by(seed.audits, & &1.criteria). Eyeballing the file and approving on wrong numbers corrupts the consent.
Execution flow
Step 1: Locate or seed hex_vet.exs
If hex_vet.exs exists at project root:
Read it via Code.eval_file/1
Else:
Write the empty-ledger stub (see ${CLAUDE_SKILL_DIR}/references/hex-vet.md §"Empty ledger")
Inform user: "Created hex_vet.exs at project root."
Step 2: Branch by mode
<pkg> <version>→ single-vet path (Step 3-7).--seed→ importpriv/hex_vet_seed.exs. Before prompting,Code.eval_file/1the seed and compute (Iron Law #6): thecriteriasplit (Enum.frequencies_by(seed.audits, & &1.criteria)) and, against any existing ledger, exact new / overwrite / no-op counts. Put those computed numbers in theAskUserQuestion. Also state up front that the seed is a provenance baseline, not certification of your currentmix.lock(per Iron Law #2, seed versions older than the locked ones stay unvetted). Ask before overwriting existing entries.--list→ render the audits table; exit.--check→ compare ledger entries withmix.lock; warn on drift. Read the lock viaCode.eval_file("mix.lock")with2>/dev/null— modern locks have quoted keys and emit afound quoted keywordwarning per package (tens of KB of noise that gets persisted as an oversized tool result otherwise).
Step 3: Fetch the tarball (single-vet)
Run the deps-audit corpus loader. Cache lives at
~/.cache/phx-deps-audit/corpus/<pkg>/<version>/contents/. Use:
bash ${CLAUDE_SKILL_DIR}/../deps-audit/scripts/fetch_tarball.sh \
<pkg> <version>
Step 4: Run Phase 1 rules
Source the rules from ../deps-audit/references/rules-impl.md.
Run run_all_rules over the cached dir. Write findings to a temp
vet-findings.jsonl. Set FINDINGS_FILE to override default path.
Step 5: Present findings
Print the findings table per ../deps-audit/references/output-renderer.md.
On zero findings: say "No findings — vet from a clean baseline."
On any finding: show severity, file, line, snippet inline.
Step 6: Prompt for verdict
Call AskUserQuestion with these 4 options:
:safe_to_deploy— full trust; findings investigated and cleared.:safe_to_run— trust in non-production envs only (test deps).:does_not_implement_crypto— Mozilla-style sub-criterion.Skip— defer decision; don't write an entry.
If any finding is BLOCK severity: default-highlight Skip. Require
explicit override before writing :safe_to_deploy over a BLOCK.
Step 7: Append to ledger
Read existing hex_vet.exs via Code.eval_file/1. Append the audit
map below to :audits. Write back via
Code.format_string!(inspect(...)).
%{
package: "<pkg>",
version: "<version>",
criteria: <verdict_atom>,
reviewer: "<git config user.email>",
notes: "<user-provided one-liner OR findings summary>",
reviewed_at: ~D[<today>]
}
Write back via Code.format_string!(inspect(term, pretty: true)).
Confirm to user: "Added <pkg> <version> to hex_vet.exs."
Integration
- Run after
/phx:deps-auditto clear vetted findings. - Run before merging a
mix.lockPR to certify new versions. - Run
/phx:deps-vet --checkto detect ledger drift vsmix.lock. /phx:deps-auditauto-downgrades vetted findings to INFO.policy.block_on_unvettedis enforced by the plugin'sdeps-audit-gate.shPreToolUse hook onmix deps.get/mix deps.update.
References
${CLAUDE_SKILL_DIR}/references/hex-vet.md— schema, parser, lookup${CLAUDE_SKILL_DIR}/references/seed.md—--seedflag, curated baseline${CLAUDE_SKILL_DIR}/../deps-audit/references/rules-impl.md— the same rules/phx:deps-auditruns
Out of scope (Phase 3+)
- Mix task surface — defer
mix phx.deps_vetto a separate Hex packagephx_deps_vetfor non-CC users. - Distributed imports — defer cargo-vet
imports:until trust-chain semantics are designed.
Related Skills
algorithmic-art
177.9kCreating algorithmic art using p5.js with seeded randomness and interactive parameter exploration. Use this when users request creating art using code, generative art, algorithmic art, flow fields, or particle systems.
pptx
177.9kUse this skill any time a .pptx or .potx file is involved in any way — as input, output, or both. This includes: creating slide decks, pitch decks, or presentations; reading, parsing, or extracting text from any .pptx or .potx file (even if the extracted content will be used elsewhere, like in an em…
design
130.2kComprehensive design skill: brand identity, design tokens, UI styling, logo generation (55 styles, Gemini, Atlas Cloud, or MuAPI AI), corporate identity program (50 deliverables, CIP mockups), HTML presentations (Chart.js), banner design (22 styles, social/ads/web/print), icon design (15 styles, SVG…
ui-ux-pro-max
130.2kUI/UX design intelligence for web, mobile, and desktop. This skill should be used when designing, building, reviewing, or fixing interfaces, including pages, components, design systems, accessibility, interaction, responsive layout, typography, color, charts, and stack-specific UI implementation.
Languages
Trust signals
From repository metadata: license, adoption, age and documentation. Not a code audit — see the Safety scan above for what the skill file itself contains.
