Dependency Risk Audit - Audit dependencies for security, license, and supply chain.
Audits third-party dependencies for exploitable CVEs, abandonment, license exposure, and supply-chain hygiene, delivering a ranked findings report.
Tags
Updated: 2026-09-18Capabilities
Typical Inputs
Typical Outputs
What this skill does
- Gather manifest and deployment context
- Triage CVEs for contextual reachability
- Evaluate dependency maintenance health
- Verify supply-chain hygiene and lockfiles
- Check licenses for copyleft risk
- Rank findings and deliver report
Inputs
- Manifests and lockfiles
- Deployment context
- License posture
Outputs
- Ranked findings report
- Remediation order
- License flag list
- Lockfile and CI hygiene verdict
Requirements
- Native ecosystem audit tools
