dependency-check
Scan project dependencies for known vulnerabilities and CVEs. Use when auditing third-party packages, before releases, after `npm install`/lockfile changes, or when investigating reported CVE advisories.
npx skills add ruvnet/ruflo --skill dependency-check --agent claude-code
Same command for any agent — swap --agent for codex, cursor, copilot.
Weekly change comes from our own snapshots, not the repository page — it measures attention, not adoption.
Check dependencies for CVEs and outdated packages: ```bash npx @claude-flow/cli@latest security cve --list npx @claude-flow/cli@latest security cve --severity critical npx @claude-flow/cli@latest security scan --type deps --depth deep npm audit --json ``` | Severity | Action | |----------|--------| | critical | Block deployment, fix immediately | | high | Fix before next release | | moderate | Schedule fix within sprint | | low | Track in backlog | Auto-fix via the scan command: `npx @claude-flow/cli@latest security scan --type deps --fix` For continuous monitoring, dispatch via MCP: `mcp__plugin_ruflo-core_ruflo__hooks_worker-dispatch({ trigger: "audit" })`
npx @claude-flow/cli@latest security cve --list npx @claude-flow/cli@latest security cve --severity critical npx @claude-flow/cli@latest security scan --type deps --depth deep npm audit --json
What does the dependency-check skill do?
Scan project dependencies for known vulnerabilities and CVEs. Use when auditing third-party packages, before releases, after `npm install`/lockfile changes, or when investigating reported CVE advisories.
How do I install it?
Run `npx skills add ruvnet/ruflo --skill dependency-check --agent claude-code` — it drops the skill into your project so the agent can pick it up. Swap the --agent value for codex, cursor or copilot if you use one of those.
Where does this skill come from?
From ruvnet/ruflo, a repository with 67,015 stars. We read it straight from the repository tree rather than a submitted listing, so what you see here is what is actually published.
Is a popular skill a good skill?
Not necessarily. Stars measure attention, not adoption — a repository can trend for a week and be abandoned. That is why we show the weekly change from our own snapshots next to the total, instead of a single flattering number.