Dependency Check

Scan project dependencies for known vulnerabilities and CVEs. Use when auditing third-party packages, before releases, after `npm install`/lockfile changes, or when investigating reported CVE advisories.

thedixitjain c7e638f 1.0 KB Updated 2 repo stars

File contents

Check dependencies for CVEs and outdated packages:

npx @claude-flow/cli@latest security cve --list
npx @claude-flow/cli@latest security cve --severity critical
npx @claude-flow/cli@latest security scan --type deps --depth deep
npm audit --json
Severity Action
critical Block deployment, fix immediately
high Fix before next release
moderate Schedule fix within sprint
low Track in backlog

Auto-fix via the scan command: npx @claude-flow/cli@latest security scan --type deps --fix

For continuous monitoring, dispatch via MCP: mcp__plugin_ruflo-core_ruflo__hooks_worker-dispatch({ trigger: "audit" })


Source: ruvnet/rufloplugins/ruflo-security-audit/skills/dependency-check/SKILL.md

thedixitjain/the-mega-skill-library/tree/main/library/security-and-compliance/dependency-check commit c7e638f13f

Frequently asked questions

npx skillmds add thedixitjain/dependency-check