Dep Cve Auditor — Security agent for Claude Code
Audits dependency manifests for CVEs (npm/pip/cargo/govulncheck) to disk.
How to install Dep Cve Auditor
Installs to ~/.claude/agents/dbc-oduffy-coordinator-claude-dep-cve-auditor.md
mkdir -p ~/.claude/agents && curl -fsSL https://raw.githubusercontent.com/dbc-oduffy/coordinator-claude/HEAD/agents/dep-cve-auditor.md -o ~/.claude/agents/dbc-oduffy-coordinator-claude-dep-cve-auditor.md Restart Claude Code, or start a new session, for it to be picked up.
What Dep Cve Auditor does
name: dep-cve-auditor description: "Audits dependency manifests for CVEs (npm/pip/cargo/govulncheck) to disk. Manifests only — security-audit-worker scans source instead." model: sonnet effort: low color: yellow access-mode: read-write tools: ["Bash", "PowerShell", "Read", "Edit"]
Dependency CVE Auditor
Identity
Mechanical worker: read dependency manifests, run the CVE audit tool per detected language, normalize output, return a
Alternatives in Security
- Token Auditor — Scans ui/src/ for hardcoded visual values, duplicate components, and shadcn replacement candidates; produces d 79.4k ★
- Ark Security Patcher — Fix security vulnerabilities in Ark by researching CVEs, analyzing impact, proposing mitigations, implementing 419 ★
- Audit Deep — Deep single-subsystem audit that reasons about state over time (caches, upserts, migrations, concurrent scans) 335 ★
Full documentation available on GitHub
View Source RepositoryRelated Agents
Dependency Auditor
Audit dependencies for vulnerabilities, outdated versions, and deprecations. C#/.NET first (dotnet list packag
What Skeletons Are Hiding In Node Modules?
npm audit --json 2>/dev/null true cargo audit 2>/dev/null true pip-audit 2>/dev/null true grep -rn "password\
Supply Chain Analyst
Software supply-chain security expert. Deep on Socket.dev (behavioral package analysis), Syft (SBOM generation
Oficial De Seguranca
Workbench security with dual role — (a) AUDITS every external dep/repo/AI brought by the Recruiter before adop
Dep Auditor
Use to audit project dependencies for known CVEs, abandoned packages, license incompatibility, and significant
Dep Purist
The relentless auditor of project dependencies. Use this agent to find outdated, vulnerable, duplicate, unused
Related Skills
Dep Cve
🔒 Dep Cve
Cc Statusline Tui
Customize Claude Code statusline TUI with multi-language support and simple install options for npm, Cargo, an
Dep Auditor
Run a dependency health audit for actual-mcp-server and create GitHub issues for any findings.