Back to skills
SKILL.md
Dependency Vulnerability Scanning
ASecurityDependency graph vulnerability, provenance, license, or exception risk.
- 7 stars
- 0 votes
- 0 copies
- 1 view
- Added September 8, 2026
Security analysis
100/100Pro scans all 5 files and shows the line behind each finding
npx -y skills add machenjie/rd-skills --skill dependency-vulnerability-scanning --agent claude-codeAre you the author of Dependency Vulnerability Scanning?
Add the live security badge to your README. It updates with every re-scan.
[](https://www.skillsdirectory.com/skills/machenjie-dependency-vulnerability-scanning)---
name: dependency-vulnerability-scanning
description: "Dependency graph vulnerability, provenance, license, or exception risk."
---
# dependency-vulnerability-scanning
## Registry Trigger
**Use when**
- dependency/advisory reachability, origin, license, install-time, or exception risk
**Do not use when**
- mechanics/version only, without risk acceptance
## Skill Role
Own graph risk; `package-dependency-management` owns mechanics.
## High-Value Rules
- Resolve graph/origin/license/remediation/exception/artifact scope; labels do not decide risk.
- Bind remediation and exception decisions to the reachable graph and current authority.
- Preserve graph and artifact reachability when judging supply-chain risk.
## Anti-Patterns
- Clean scans and “dev-only/not reachable” do not close supply-chain risk.
## Stop Conditions
- Stop on unresolved evidence/authority, sensitive hooks, or uncontained material risk.
## Output Contract
- Return a dependency-risk decision: state graph delta, reachability, execution origin, license evidence, remediation, bounded exceptions, and proof limits
## Targeted References
| Path | Type | Load when | Do not load when | Required by | Required output |
|---|---|---|---|---|---|
| [benchmarks and patterns](references/benchmarks-and-patterns.md) | benchmark-pattern | vulnerability origin license remediation or exception signals compete | one current graph and policy path resolves package risk without comparison | analysis-agent, task-agent, review-agent | option-comparison, selected-approach |
| [checklist](references/checklist.md) | decision-checklist | resolved graph delta needs reachability execution origin license remediation and exception closure | no dependency graph or package-risk acceptance changes | analysis-agent, task-agent, review-agent | checklist-result, residual-risk |
| [evidence patterns](references/evidence-patterns.md) | evidence-pattern | scanner reachability provenance license SBOM or exception claims need fresh proof | no package-risk claim is being accepted | analysis-agent, task-agent, review-agent | evidence-record, proof-limit, residual-risk |
Files in this skill
- SKILL.md
- examples/example-output.md
- references/benchmarks-and-patterns.md
- references/checklist.md
- references/evidence-patterns.md
Attribution
Comments
Loading comments…