dependency-check
Scan project dependencies for known vulnerabilities and CVEs. Use when auditing third-party packages, before releases, after `npm install`/lockfile changes, or when investigating reported CVE advisories.
How do I install this agent skill?
npx skills add https://github.com/ruvnet/ruflo --skill dependency-checkIs this agent skill safe to install?
- Gen Agent Trust Hubwarn
The skill executes an external NPM package dynamically at runtime to perform dependency scanning, which introduces potential supply chain risks.
- Socketpass
No alerts
- Snykwarn
Risk: MEDIUM · 1 issue
What does this agent skill do?
Check dependencies for CVEs and outdated packages:
npx @claude-flow/cli@latest security cve --list
npx @claude-flow/cli@latest security cve --severity critical
npx @claude-flow/cli@latest security scan --type deps --depth deep
npm audit --json
| Severity | Action |
|---|---|
| critical | Block deployment, fix immediately |
| high | Fix before next release |
| moderate | Schedule fix within sprint |
| low | Track in backlog |
Auto-fix via the scan command: npx @claude-flow/cli@latest security scan --type deps --fix
For continuous monitoring, dispatch via MCP:
mcp__plugin_ruflo-core_ruflo__hooks_worker-dispatch({ trigger: "audit" })
How can the creator link this skill?
Add the canonical catalog link to the repository README so users can inspect current installs and available audits. The publishing guide covers the complete discovery path.
<a href="https://skillzs.dev/skills/ruvnet/ruflo/dependency-check">View dependency-check on skillZs</a>