Review Dependency Risk — Security skill for Claude Code
Audit dependency manifests for supply-chain risk: unmaintained or typosquatted packages, license conflicts, unpinned versions, and known vulnerabilities.
How to install Review Dependency Risk
Installs to ~/.claude/commands/sourjya-kiro-rails-review-dependency-risk.md
mkdir -p ~/.claude/commands && curl -fsSL https://raw.githubusercontent.com/sourjya/kiro-rails/HEAD/.claude/commands/review-dependency-risk.md -o ~/.claude/commands/sourjya-kiro-rails-review-dependency-risk.md Restart Claude Code, or start a new session, for it to be picked up.
What Review Dependency Risk does
description: "Audit dependency manifests for supply-chain risk: unmaintained or typosquatted packages, license conflicts, unpinned versions, and known vulnerabilities."
Before scanning, read `docs/decisions/` ADRs if they exist. Use documented dependency decisions (accepted vendor lock-in, intentional SDK coupling) to distinguish intentional choices from accidental risk.
Act as a principal-level software engineer and supply chain security specialist performing a comprehensive dependen
Alternatives in Security
- FastAPI Review — Review a FastAPI application for architecture, async correctness, dependency injection, Pydantic schemas, secu 243.5k ★
- Agentseal — Security toolkit for AI agents 344 ★
- Claude Leaked Files — Mirrored snapshot of Claude Code's source (exposed 2026-03-31) preserved for educational purposes, defensive s 256 ★
Full documentation available on GitHub
View Source RepositoryRelated Skills
Heeler Security Review
Perform a repository security review for the current project directory, including secrets exposure risk, depen
Bombastic
Claude skill to generate Software Bill of Materials (SBOM) with license tracking and supply chain security. Ge
Harden Deps
Deployment hardening step 3 — run ecosystem-native vulnerability audit (full tree AND production-only, so ship
Dependency Audit
Audit dependencies for security vulnerabilities, license compliance, and update recommendations
Fivem Security Audit
Find the money dupe, not just the malware. A Claude Code skill that reviews FiveM and RedM resources for dupes
Skillspector
Security scanner for AI agent skills. Detect vulnerabilities, malicious patterns, security risks, prompt injec
Related Agents
Chain
Supply chain security — SBOM generation, dependency scanning, third-party risk, license compliance
Cto Dep Health
CTO-grade dependency health review. Evaluates supply chain risk, version currency, license exposure, and wheth
Dependency Supply Chain Reviewer
Reviewer for dependencies and supply chain — outdated/vulnerable packages, lockfile hygiene, pinning, and prov