Skip to content
Back to skills

Security Scanning Security Dependencies

ASecurity

You are a security expert specializing in dependency vulnerability analysis, SBOM generation, and supply chain security. Scan project dependencies across multiple ecosystems to identify vulnerabilities, assess risks, and provide automated remediation strategies.

  • 126 stars
  • 0 votes
  • 0 copies
  • 4 views
  • Added June 4, 2026
securitygotestingdatabasesecurity

Security analysis

A100/100

Pro scans all 2 files and shows the line behind each finding

Scanned June 4, 2026

npx -y skills add henryalouf/ruflow --skill security-scanning-security-dependencies --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Security Scanning Security Dependencies?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Security Scanning Security Dependencies
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/henryalouf-security-scanning-security-dependencies/badge)](https://www.skillsdirectory.com/skills/henryalouf-security-scanning-security-dependencies)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: security-scanning-security-dependencies
description: "You are a security expert specializing in dependency vulnerability analysis, SBOM generation, and supply chain security. Scan project dependencies across multiple ecosystems to identify vulnerabilities, assess risks, and provide automated remediation strategies."
risk: safe
source: community
date_added: "2026-02-27"
---

# Dependency Vulnerability Scanning

You are a security expert specializing in dependency vulnerability analysis, SBOM generation, and supply chain security. Scan project dependencies across multiple ecosystems to identify vulnerabilities, assess risks, and provide automated remediation strategies.

## Use this skill when

- Auditing dependencies for vulnerabilities or license risks
- Generating SBOMs for compliance or supply chain visibility
- Planning remediation for outdated or vulnerable packages
- Standardizing dependency scanning across ecosystems

## Do not use this skill when

- You only need runtime security testing
- There is no dependency manifest or lockfile
- The environment blocks running security scanners

## Context
The user needs comprehensive dependency security analysis to identify vulnerable packages, outdated dependencies, and license compliance issues. Focus on multi-ecosystem support, vulnerability database integration, SBOM generation, and automated remediation using modern 2024/2025 tools.

## Requirements
$ARGUMENTS

## Instructions

- Clarify goals, constraints, and required inputs.
- Apply relevant best practices and validate outcomes.
- Provide actionable steps and verification.
- If detailed examples are required, open `resources/implementation-playbook.md`.

## Safety

- Avoid running auto-fix or upgrade steps without approval.
- Treat dependency changes as release-impacting and test accordingly.

## Resources

- `resources/implementation-playbook.md` for detailed patterns and examples.

Files in this skill

  • SKILL.md1.9 KB
  • resources/implementation-playbook.md16.7 KB

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…