dependency-vulnerability-scanning

Community

Block risky dependencies before they ship

Authormachenjie
Version1.0.0
Installs0

System Documentation

What problem does it solve?

It prevents unreviewed dependency and supply-chain changes from entering your build or runtime by enforcing a structured risk review across necessity, vulnerabilities, licenses, transitive impact, lockfile integrity, SBOM traceability, and maintainer health.

Core Features & Use Cases

  • Necessity justification for every dependency change: requires written rationale for why the dependency is needed, what functionality it provides, and which code paths will actually use it.
  • Full transitive vulnerability scanning: scans the entire lockfile tree (direct and transitive) and escalates CRITICAL/HIGH runtime CVEs unless reachability is documented.
  • License compatibility verification: checks SPDX identifiers and compatibility with distribution obligations, including legal review triggers for GPL/AGPL-family licenses.
  • Supply-chain health and install-script scrutiny: evaluates maintainer activity, security posture, install/postinstall hooks, and supply-chain integrity signals.
  • Lockfile and SBOM correctness enforcement: ensures deterministic installs via frozen/fixed lockfiles and requires SBOM regeneration to maintain traceability.

Quick Start

Use this capability to review any dependency addition, upgrade, downgrade, removal, vendoring, lockfile change, or dependency-update PR by producing a documented risk report that covers vulnerabilities, licenses, transitive impact, lockfile integrity, and SBOM updates.

Dependency Matrix

Required Modules

None required

Components

references

💻 Claude Code Installation

Recommended: Let Claude install automatically. Simply copy and paste the text below to Claude Code.

Please help me install this Skill:
Name: dependency-vulnerability-scanning
Download link: https://github.com/machenjie/rd-skills/archive/main.zip#dependency-vulnerability-scanning

Please download this .zip file, extract it, and install it in the .claude/skills/ directory.
View Source Repository

Agent Skills Search Helper

Install a tiny helper to your Agent, search and equip skill from 471,000+ vetted skills library on demand.