Skip to content
Back to skills

Dependency Vulnerability Scanning

ASecurity

Dependency graph vulnerability, provenance, license, or exception risk.

  • 7 stars
  • 0 votes
  • 0 copies
  • 1 view
  • Added September 8, 2026
security

Security analysis

A100/100

Pro scans all 5 files and shows the line behind each finding

Scanned September 22, 2026

npx -y skills add machenjie/rd-skills --skill dependency-vulnerability-scanning --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Dependency Vulnerability Scanning?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Dependency Vulnerability Scanning
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/machenjie-dependency-vulnerability-scanning/badge)](https://www.skillsdirectory.com/skills/machenjie-dependency-vulnerability-scanning)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: dependency-vulnerability-scanning
description: "Dependency graph vulnerability, provenance, license, or exception risk."
---

# dependency-vulnerability-scanning

## Registry Trigger

**Use when**

- dependency/advisory reachability, origin, license, install-time, or exception risk

**Do not use when**

- mechanics/version only, without risk acceptance

## Skill Role

Own graph risk; `package-dependency-management` owns mechanics.

## High-Value Rules

- Resolve graph/origin/license/remediation/exception/artifact scope; labels do not decide risk.
- Bind remediation and exception decisions to the reachable graph and current authority.
- Preserve graph and artifact reachability when judging supply-chain risk.

## Anti-Patterns

- Clean scans and “dev-only/not reachable” do not close supply-chain risk.

## Stop Conditions

- Stop on unresolved evidence/authority, sensitive hooks, or uncontained material risk.

## Output Contract

- Return a dependency-risk decision: state graph delta, reachability, execution origin, license evidence, remediation, bounded exceptions, and proof limits

## Targeted References

| Path | Type | Load when | Do not load when | Required by | Required output |
|---|---|---|---|---|---|
| [benchmarks and patterns](references/benchmarks-and-patterns.md) | benchmark-pattern | vulnerability origin license remediation or exception signals compete | one current graph and policy path resolves package risk without comparison | analysis-agent, task-agent, review-agent | option-comparison, selected-approach |
| [checklist](references/checklist.md) | decision-checklist | resolved graph delta needs reachability execution origin license remediation and exception closure | no dependency graph or package-risk acceptance changes | analysis-agent, task-agent, review-agent | checklist-result, residual-risk |
| [evidence patterns](references/evidence-patterns.md) | evidence-pattern | scanner reachability provenance license SBOM or exception claims need fresh proof | no package-risk claim is being accepted | analysis-agent, task-agent, review-agent | evidence-record, proof-limit, residual-risk |

Files in this skill

  • SKILL.md4 KB
  • examples/example-output.md678 B
  • references/benchmarks-and-patterns.md2.4 KB
  • references/checklist.md1.3 KB
  • references/evidence-patterns.md3.9 KB

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…