repository-dependency-reviewer

Review repository dependencies for risks using local manifests and Endor MCP tools.

10|2|Updated May 4, 2026
One-click install
npx skills add https://github.com/endorlabs/endor-labs-agent-kit --skill repository-dependency-reviewer
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: repository-dependency-reviewer
Source: https://github.com/endorlabs/endor-labs-agent-kit/tree/main/gemini/repository-dependency-reviewer
Command: npx skills add https://github.com/endorlabs/endor-labs-agent-kit --skill repository-dependency-reviewer

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill requires endorctl, Gemini CLI, and includes scripts (resource) and references (resource) components.

What problem does it solve?

This Skill automates the process of reviewing repository dependencies for risk, saving you time and ensuring your project is secure.

Core Features & Use Cases

  • Dependency Risk Review: Inspects dependency files and resolves package coordinates, checking them against Endor MCP tools.
  • Risky Dependency Reporting: Reports risky dependencies, unresolved versions, recommended next checks, and data gaps.
  • Use Case: Use this Skill to automatically review your project's dependencies and receive a report on any potential risks.

Quick Start

Use @repository-dependency-reviewer to review the dependencies of the current repository.

Frequently Asked Questions about repository-dependency-reviewer

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I automate repository dependency risk review for my project?

To automate repository dependency risk review, use this Skill to inspect local manifests and resolve package coordinates against Endor MCP tools. It automatically reports risky dependencies, unresolved versions, and data gaps to ensure your software is secure.

Do I need Endor MCP access to perform vulnerability checks on dependencies?

Yes, you need Endor MCP access to perform vulnerability checks. The Skill relies on Endor MCP tools to check resolved package coordinates against known risks and provide accurate dependency risk assessments for your repository.

Can I use Gemini CLI to check repository dependencies for security vulnerabilities?

Yes, you can use Gemini CLI along with endorctl to check repository dependencies for security vulnerabilities. The Skill leverages these dependencies to automate the review process and generate reports on potential risks and unresolved versions.

What is dependency review and how does it identify risky dependencies?

Dependency review is the process of inspecting dependency files and resolving package coordinates to check against Endor MCP tools. It identifies risky dependencies by reporting unresolved versions, recommended next checks, and data gaps in your software development workflow.

What's the best way to review repository dependencies for risk management in software development?

The best way to review repository dependencies for risk management is to automate the process using Endor MCP tools. This Skill inspects local manifests, resolves package coordinates, and reports risky dependencies, saving time and ensuring project security.

Why does dependency review report unresolved versions and data gaps?

Dependency review reports unresolved versions and data gaps to highlight incomplete or missing package information during the risk assessment. This alerts you to dependencies that cannot be fully verified against Endor MCP tools, indicating potential security blind spots.