sourjya

Review Dependency Risk — Security skill for Claude Code

Security community

Audit dependency manifests for supply-chain risk: unmaintained or typosquatted packages, license conflicts, unpinned versions, and known vulnerabilities.

How to install Review Dependency Risk

Installs to ~/.claude/commands/sourjya-kiro-rails-review-dependency-risk.md

Terminal
mkdir -p ~/.claude/commands && curl -fsSL https://raw.githubusercontent.com/sourjya/kiro-rails/HEAD/.claude/commands/review-dependency-risk.md -o ~/.claude/commands/sourjya-kiro-rails-review-dependency-risk.md

Restart Claude Code, or start a new session, for it to be picked up.

What Review Dependency Risk does


description: "Audit dependency manifests for supply-chain risk: unmaintained or typosquatted packages, license conflicts, unpinned versions, and known vulnerabilities."

Before scanning, read `docs/decisions/` ADRs if they exist. Use documented dependency decisions (accepted vendor lock-in, intentional SDK coupling) to distinguish intentional choices from accidental risk.

Act as a principal-level software engineer and supply chain security specialist performing a comprehensive dependen

Alternatives in Security

  • FastAPI Review — Review a FastAPI application for architecture, async correctness, dependency injection, Pydantic schemas, secu 243.5k ★
  • Agentseal — Security toolkit for AI agents 344 ★
  • Claude Leaked Files — Mirrored snapshot of Claude Code's source (exposed 2026-03-31) preserved for educational purposes, defensive s 256 ★

Full documentation available on GitHub

View Source Repository