Cargo Auditor — Security agent for Claude Code
Audits the dependency tree for security advisories, license issues, and bloat.
How to install Cargo Auditor
Installs to ~/.claude/agents/luishsr-rust-ai-template-cargo-auditor.md
mkdir -p ~/.claude/agents && curl -fsSL https://raw.githubusercontent.com/luishsr/rust-ai-template/HEAD/.claude/agents/cargo-auditor.md -o ~/.claude/agents/luishsr-rust-ai-template-cargo-auditor.md Restart Claude Code, or start a new session, for it to be picked up.
What Cargo Auditor does
name: cargo-auditor description: Audits the dependency tree for security advisories, license issues, and bloat. Use before releases and after any `cargo add` / `Cargo.toml` change. tools: Read, Grep, Glob, Bash model: sonnet
You are a supply-chain security auditor for a Rust project.
Checks to perform
cargo audit— report every advisory with severity and fix version.cargo tree --duplicates— flag duplicate versions of crates; large trees often indicate dep churn.- `c
Alternatives in Security
- Deps Audit — You are a dependency security expert specializing in vulnerability scanning, license compliance, and 31.9k ★
- Security Code Reviewer — Use this agent when you need to review code for security vulnerabilities, input validation issues, or authenti 2.8k ★
- Genblaze Maintainer — The Genblaze Maintainer — autonomous guardian of the Genblaze repo 560 ★
Full documentation available on GitHub
View Source RepositoryRelated Agents
Dependency Auditor
Audit dependencies for vulnerabilities, outdated versions, and deprecations. C#/.NET first (dotnet list packag
Dependency Audit
Analyze project dependencies for security, maintenance, and bloat. Output to .claude/audits/AUDIT_DEPS.md.
Dep Cve Auditor
Audits dependency manifests for CVEs (npm/pip/cargo/govulncheck) to disk. Manifests only — security-audit-work
Hatch3r Dependency Drafter
Dependency-analysis specialist who drafts version-bump and dependency-change proposals — assesses upgrade impa
Dep Auditor
Use to audit project dependencies for known CVEs, abandoned packages, license incompatibility, and significant
Portfolio Audit
Audits a project against the global portfolio standards (author signature, gitignore, no secrets, no dead code
Related Skills
Agentic Product Page Auditor
Audits whether an AI shopping agent can read and buy from a product page. Reconstructs the product graph an ag
Dep Auditor
Run a dependency health audit for actual-mcp-server and create GitHub issues for any findings.
Release Patch
Cut a patch / minor release for mori-desktop — bump version in Cargo.toml / tauri.conf.json / package.json, ap