Dependency Auditor — Security agent for Claude Code
Audit dependencies for vulnerabilities, outdated versions, and deprecations.
How to install Dependency Auditor
Installs to ~/.claude/agents/rjmurillo-ai-agents-dependency-auditor.md
mkdir -p ~/.claude/agents && curl -fsSL https://raw.githubusercontent.com/rjmurillo/ai-agents/HEAD/.claude/agents/dependency-auditor.md -o ~/.claude/agents/rjmurillo-ai-agents-dependency-auditor.md Restart Claude Code, or start a new session, for it to be picked up.
What Dependency Auditor does
name: dependency-auditor description: Audit dependencies for vulnerabilities, outdated versions, and deprecations. C#/.NET first (dotnet list package), with extensible patterns for npm, pip, and cargo. Use on a schedule or before releases to surface supply-chain risk before it reaches production. model: sonnet role: executor argument-hint: Specify the solution/project path or language ecosystem to audit (e.g. "src/MyApp.sln" or "npm")
Dependency Auditor
**Autonomy Guardrail**: Apply
Alternatives in Security
- Mathodology Submission Packager — Use for final contest package assembly, file checks, reproducibility README, AI-use statement, and submission 137 ★
- Audit Trail Verifier — Create an immutable evidence chain linking requirements, code, tests, scans, and releases 108 ★
- Dependency Doctor — Dependency health management — outdated packages, vulnerabilities (CVE), breaking change risk for major bumps 85 ★
Full documentation available on GitHub
View Source RepositoryRelated Agents
What Skeletons Are Hiding In Node Modules?
npm audit --json 2>/dev/null true cargo audit 2>/dev/null true pip-audit 2>/dev/null true grep -rn "password\
Dep Cve Auditor
Audits dependency manifests for CVEs (npm/pip/cargo/govulncheck) to disk. Manifests only — security-audit-work
View Dependency Tree
npm ls yarn list pnpm list npm outdated yarn outdated npm audit yarn audit npx depcheck npx webpack-bundle-ana
Cargo Auditor
Audits the dependency tree for security advisories, license issues, and bloat. Use before releases and after a
Dotnet Aspnetcore Specialist
WHEN analyzing ASP.NET Core middleware, request pipelines, minimal API design, DI lifetime selection, or diagn
Dotnet Security Reviewer
WHEN reviewing .NET code for security vulnerabilities, OWASP compliance, secrets exposure, or cryptographic mi
Related Skills
Zsh Pkg Update Nag
Session-start nag that checks Homebrew, npm, pnpm, uv, RubyGems, and cargo globals for outdated packages and o
Vecmindb SDK
Self-hosted, sovereign memory layer for AI coding agents. MCP-ready, local BGE-M3 ONNX embeddings, zero extern
Dotnet Artisan
Comprehensive .NET development skills for modern C# and .NET