Agent skill

Dependency Check

by ruvnet in ruvnet/ruflo

Scan project dependencies for known vulnerabilities and CVEs.

MITAuto-check passedSecurity

Install Dependency Check

skills CLI
$ npx skills add ruvnet/ruflo --skill dependency-check -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install ruvnet/ruflo dependency-check --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/ruvnet/ruflo.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/ruflo-security-audit/skills/dependency-check .claude/skills/dependency-check && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
dependency-check
GitHub stars
74k
Token cost
~258 tokens
SKILL.md length
49 words
Files
1
Skills in repo
264
Repo updated
First seen
Licence
MIT

At a glance

Scan project dependencies for known vulnerabilities and CVEs.

  • Auditing third-party packages
  • Calls npx and npm
  • Before releases
  • After npm install/lockfile changes

What it does

Dependency Check is an agent skill from ruvnet/ruflo. Scan project dependencies for known vulnerabilities and CVEs. Use when auditing third-party packages, before releases, after npm install/lockfile changes, or when investigating reported CVE advisories.

Its SKILL.md is about 260 tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Security, covering Vulnerability scanning and Dependency management. It works with npm. The repository describes itself as: 🌊 The original agent harness. Deploy intelligent multi-player swarms, coordinate autonomous workflows, and build conversational AI systems. Features adaptive memory…. The licence is MIT.

When your agent uses it

  • Auditing third-party packages
  • Before releases
  • After npm install/lockfile changes
  • Investigating reported CVE advisories

Example prompts

  • “/dependency-check”

Requirements

  • Node.js
  • Pre-approved tools (allowed-tools): Bash(npx * npm *), mcp__plugin_ruflo-core_ruflo__memory_store, Read

What it can do on your machine

Read from SKILL.md and the folder at commit de590e1. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Bash(npx * npm *)
    • mcp__plugin_ruflo-core_ruflo__memory_store
    • Read

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • npx
    • npm

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use npx and npm, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Dependency Check loads about 258 tokens when it runs. Until then it costs about 55 tokens; SKILL.md has 49 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~55
When it runs · the whole SKILL.md, loaded when a task matches
~258

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from ruvnet/ruflo at commit de590e1, republished under its MIT licence (© ruvnet). 49 words, ~258 tokens.

Download SKILL.mdSave it as .claude/skills/dependency-check/SKILL.md (or your agent's skills folder).
name
dependency-check
description
Scan project dependencies for known vulnerabilities and CVEs. Use when auditing third-party packages, before releases, after `npm install`/lockfile changes, or when investigating reported CVE advisories.
allowed-tools
Bash(npx * npm *), mcp__plugin_ruflo-core_ruflo__memory_store, Read
argument-hint
[--path PATH]

Check dependencies for CVEs and outdated packages:

bash
npx @claude-flow/cli@latest security cve --list
npx @claude-flow/cli@latest security cve --severity critical
npx @claude-flow/cli@latest security scan --type deps --depth deep
npm audit --json
SeverityAction
criticalBlock deployment, fix immediately
highFix before next release
moderateSchedule fix within sprint
lowTrack in backlog

Auto-fix via the scan command: npx @claude-flow/cli@latest security scan --type deps --fix

For continuous monitoring, dispatch via MCP: mcp__plugin_ruflo-core_ruflo__hooks_worker-dispatch({ trigger: "audit" })

© ruvnet, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in plugins/ruflo-security-audit/skills/dependency-check of ruvnet/ruflo.

Open the folder on GitHubat commit de590e1

Compare with similar skills

Dependency Check next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Dependency Check compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Dependency Check this skillruvnet/ruflo74k—~258Automated safety check: PassMIT
Dependency Auditbriiirussell/cybersecurity-skills412—~3.2kAutomated safety check: WarnMIT
npm Supply Chain Checkmajiayu000/spellbook286—~1.5kAutomated safety check: PassMIT
Dependency Auditoralirezarezvani/claude-code-tresor777—~1.2kAutomated safety check: NotesMIT
Dep Securitytinyfish-io/tinyfish-cookbook2.2k—~2.4kAutomated safety check: PassMIT
Cve Scansoftspark/ai-toolkit179—~1.3kAutomated safety check: NotesApache-2.0

Similar skills

  • Dependency Audit

    briiirussell/cybersecurity-skills

    Audit project dependencies, frameworks, languages, and dev tools for known vulnerabilities, CVEs, and security anti-patterns.

    412 GitHub stars~3.2k tokensUpdated 4 mo ago
    SecurityAuto-check: warnings
  • npm Supply Chain Check

    majiayu000/spellbook

    Scans a repository, its lockfiles and node_modules for known malicious npm package versions and install-time indicators, using a read-only Python scanner.

    286 GitHub stars~1.5k tokensUpdated yesterday
    SecurityAuto-check passed
  • Dependency Auditor

    alirezarezvani/claude-code-tresor

    Check dependencies for known vulnerabilities using npm audit, pip-audit, etc.

    777 GitHub stars~1.2k tokensUpdated 3 mo ago
    DevOps & CloudAuto-check: notes
  • Dep Security

    tinyfish-io/tinyfish-cookbook

    Check every dependency in a package.json against live CVE databases and security advisories in real time — specifically targeting vulnerabilities disclosed in the last 48 hours, the window that…

    2.2k GitHub stars~2.4k tokensUpdated 6 days ago
    SecurityAuto-check passed
  • Cve Scan

    softspark/ai-toolkit

    Scans deps for known CVEs via native audit (npm, pip, composer, cargo, go, bundler, dart).

    179 GitHub stars~1.3k tokensUpdated today
    SecurityAuto-check: notes
  • Dependency Triage

    cobusgreyling/loop-engineering

    Scan package manifests and lockfiles for outdated and vulnerable dependencies.

    11k GitHub stars~206 tokensUpdated today
    SecurityAuto-check passed

More from ruvnet/ruflo

All 264 skills in this repo
  • Stores, searches, and retrieves successful patterns with HNSW-indexed semantic search so agents can reuse past solutions instead of relearning them.

    74k GitHub starsUsed in 2 repos~830 tokens
    Auto-check passed
  • Runs claude-flow CLI security scans for input validation, path traversal, SQL injection, XSS, hardcoded secrets and known CVEs, and writes an audit report.

    74k GitHub starsUsed in 2 repos~823 tokens
    Auto-check passed
  • Applies the SPARC method (specification, pseudocode, architecture, refinement, completion) with 17 specialized modes and multi-agent orchestration, from research to deployment.

    74k GitHub starsUsed in 2 repos~829 tokens
    Auto-check passed
  • Coordinates a hierarchical swarm of specialized agents through the claude-flow CLI for work that spans several files or modules at once.

    74k GitHub starsUsed in 2 repos~779 tokens
    Auto-check passed
  • Sets up and drives Ruflo, an npm-installed orchestration layer for multi-agent swarms, persistent memory, routing, hooks and its MCP tool catalog.

    74k GitHub starsUsed in 1 repo~975 tokens
    Auto-check passed
  • Agent Coordination

    ruvnet/ruflo

    Reference for spawning, listing, monitoring and stopping agents with claude-flow commands, with agent type families, routing codes and coordination tips.

    74k GitHub starsUsed in 2 repos~519 tokens
    Auto-check passed

Works with

Categories

Questions about Dependency Check

What does Dependency Check do?

Scan project dependencies for known vulnerabilities and CVEs. Dependency Check is an agent skill from ruvnet/ruflo. Scan project dependencies for known vulnerabilities and CVEs.

When should I use Dependency Check?

Dependency Check fits situations like: auditing third-party packages; before releases; after npm install/lockfile changes; investigating reported CVE advisories.

How do I install Dependency Check in Claude Code?

Run `npx skills add ruvnet/ruflo --skill dependency-check -a claude-code`. Or copy the skill folder (plugins/ruflo-security-audit/skills/dependency-check in ruvnet/ruflo) into .claude/skills/dependency-check in your project. Claude Code loads it when a task matches its description.

How do I install Dependency Check in Codex?

Run `npx skills add ruvnet/ruflo --skill dependency-check -a codex`. Or copy the skill folder (plugins/ruflo-security-audit/skills/dependency-check in ruvnet/ruflo) into .agents/skills/dependency-check in your project. Codex loads it when a task matches its description.

Can I use Dependency Check in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add ruvnet/ruflo --skill dependency-check -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/dependency-check, .gemini/skills/dependency-check, .github/skills/dependency-check and .opencode/skills/dependency-check in your project.

What does Dependency Check need to run?

Going by SKILL.md and its folder, Dependency Check needs the command-line tools its instructions call (npx and npm). Our summary lists: Node.js. Its frontmatter pre-approves these tools: Bash(npx * npm *), mcp__plugin_ruflo-core_ruflo__memory_store, Read.

Does Dependency Check access the network?

SKILL.md contains no URLs. Its commands use npx and npm, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Dependency Check safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Dependency Check use?

Dependency Check is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Dependency Check use?

About 258 tokens (SKILL.md is roughly 1k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Dependency Check?

Skills that share tags, products or a category with Dependency Check: Dependency Audit (briiirussell/cybersecurity-skills, 412 stars), npm Supply Chain Check (majiayu000/spellbook, 286 stars), Dependency Auditor (alirezarezvani/claude-code-tresor, 777 stars) and Dep Security (tinyfish-io/tinyfish-cookbook, 2.2k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Dependency Check?

ruvnet (a GitHub user) maintains it in ruvnet/ruflo, which has 74,012 GitHub stars. The repository holds 264 skills in this directory. The repository was last updated on October 7, 2026.

Source: ruvnet/ruflo on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.