Skill comparison
Use this as a shortlist, then open the skill detail page before adopting.
Decision summary
Strongest overall
ghost-scan-deps
Shortlist this skill and compare it with close alternatives before production adoption.
Fastest prototype
ghost-scan-deps
Best first install candidate based on install readiness and adoption.
Freshest repo
ghost-scan-deps
Most recent maintenance signal among this shortlist.
| Signal | ghost-scan-deps Ghost Security - Software Composition Analysis (SCA) scanner. Scans dependency lockfiles for known vulnerabilities, identifies CVEs, and generates findings with severity levels and remediation guidance. Use when the user asks about dependency vulnerabilities, vulnerable packages, CVE checks, security audits of dependencies, or wants to scan lockfiles like package-lock.json, yarn.lock, go.sum, or Gemfile.lock. |
|---|---|
| Quality | 73/100 Strong |
| Decision verdict | 72/100 Strong shortlist Shortlist this skill and compare it with close alternatives before production adoption. |
| Adoption | 405 stars Verified outcomes are shown on each skill page |
| Freshness | Sep 3, 2026 |
| Use-case fit | |
| Workflow fit | |
| Platform hints | Claude Code |
| Warnings | The skill installs the wraith binary via `curl ... | bash`, which executes remote code. While the script is from the same organization, this is a supply chain risk that could be mitigated by pinning a specific version or using a checksum verification. · No OpenAgentSkill engagement data yet |
Skill comparison
Use this as a shortlist, then open the skill detail page before adopting.
Decision summary
Strongest overall
ghost-scan-deps
Shortlist this skill and compare it with close alternatives before production adoption.
Fastest prototype
ghost-scan-deps
Best first install candidate based on install readiness and adoption.
Freshest repo
ghost-scan-deps
Most recent maintenance signal among this shortlist.
| Signal | ghost-scan-deps Ghost Security - Software Composition Analysis (SCA) scanner. Scans dependency lockfiles for known vulnerabilities, identifies CVEs, and generates findings with severity levels and remediation guidance. Use when the user asks about dependency vulnerabilities, vulnerable packages, CVE checks, security audits of dependencies, or wants to scan lockfiles like package-lock.json, yarn.lock, go.sum, or Gemfile.lock. |
|---|---|
| Quality | 73/100 Strong |
| Decision verdict | 72/100 Strong shortlist Shortlist this skill and compare it with close alternatives before production adoption. |
| Adoption | 405 stars Verified outcomes are shown on each skill page |
| Freshness | Sep 3, 2026 |
| Use-case fit | |
| Workflow fit | |
| Platform hints | Claude Code |
| Warnings | The skill installs the wraith binary via `curl ... | bash`, which executes remote code. While the script is from the same organization, this is a supply chain risk that could be mitigated by pinning a specific version or using a checksum verification. · No OpenAgentSkill engagement data yet |
| Best for | Security and compliance workflows · Claude Code teams · builders willing to evaluate younger projects |
| Not ideal for | teams that need a vendor-supported SLA · production agents without a repository review |
| OpenAgentSkill engagement | 0 views 0 install copies |
| Install | $ npx skills add ghostsecurity/skills --skill ghost-scan-deps |
| Best for | Security and compliance workflows · Claude Code teams · builders willing to evaluate younger projects |
| Not ideal for | teams that need a vendor-supported SLA · production agents without a repository review |
| OpenAgentSkill engagement | 0 views 0 install copies |
| Install | $ npx skills add ghostsecurity/skills --skill ghost-scan-deps |