Agent skill

dependency-check

Scan project dependencies for known vulnerabilities and CVEs. Use when auditing third-party packages, before releases, after `npm install`/lockfile changes, or when investigating reported CVE advisories.

rUv72,748★ · +654/wk · 4 repos on radarProfile →
claude-codecodexread-onlyMIT
Install
npx skills add ruvnet/ruflo --skill dependency-check --agent claude-code

Same command for any agent — swap --agent for codex, cursor, copilot.

Facts
Files in the skill folder: 1
SKILL.md size: 1 KB
Bundled scripts: none
Allowed tools: Bash(npx*npm*)mcp__plugin_ruflo-core_ruflo__memory_storeRead
Path: plugins/ruflo-security-audit/skills/dependency-check/SKILL.md
Open the folder on GitHub →
Where it comes from
Source: ruvnet/ruflo
Stars: 67,015 · +629 this week
Language: TypeScript
Read our review of the source →

Weekly change comes from our own snapshots, not the repository page — it measures attention, not adoption.

From the SKILL.md

Check dependencies for CVEs and outdated packages: ```bash npx @claude-flow/cli@latest security cve --list npx @claude-flow/cli@latest security cve --severity critical npx @claude-flow/cli@latest security scan --type deps --depth deep npm audit --json ``` | Severity | Action | |----------|--------| | critical | Block deployment, fix immediately | | high | Fix before next release | | moderate | Schedule fix within sprint | | low | Track in backlog | Auto-fix via the scan command: `npx @claude-flow/cli@latest security scan --type deps --fix` For continuous monitoring, dispatch via MCP: `mcp__plugin_ruflo-core_ruflo__hooks_worker-dispatch({ trigger: "audit" })`

What's inside
Commands it runs
npx @claude-flow/cli@latest security cve --list
npx @claude-flow/cli@latest security cve --severity critical
npx @claude-flow/cli@latest security scan --type deps --depth deep
npm audit --json
More from ruflo
All skills →
About this skill
What does the dependency-check skill do?

Scan project dependencies for known vulnerabilities and CVEs. Use when auditing third-party packages, before releases, after `npm install`/lockfile changes, or when investigating reported CVE advisories.

How do I install it?

Run `npx skills add ruvnet/ruflo --skill dependency-check --agent claude-code` — it drops the skill into your project so the agent can pick it up. Swap the --agent value for codex, cursor or copilot if you use one of those.

Where does this skill come from?

From ruvnet/ruflo, a repository with 67,015 stars. We read it straight from the repository tree rather than a submitted listing, so what you see here is what is actually published.

Is a popular skill a good skill?

Not necessarily. Stars measure attention, not adoption — a repository can trend for a week and be abandoned. That is why we show the weekly change from our own snapshots next to the total, instead of a single flattering number.

Keep going