ワンクリックで
compound-agent-security-deps
Dependency audit for vulnerable packages, lockfile changes, postinstall scripts, and supply chain risks
Codex または Claude でインストール この Prompt をコピーして Codex、Claude、または他のアシスタントに貼り付けると、Skill ページを確認してインストールできます。
メニュー
Dependency audit for vulnerable packages, lockfile changes, postinstall scripts, and supply chain risks
Codex または Claude でインストール この Prompt をコピーして Codex、Claude、または他のアシスタントに貼り付けると、Skill ページを確認してインストールできます。
Decompose a large system specification into cook-it-ready epic beads via DDD bounded contexts
Reference for configuring, launching, and monitoring infinity loops and polish loops
Decompose a large system specification into cook-it-ready epic beads via DDD bounded contexts
Reflect on the cycle and capture high-quality lessons for future sessions
Full-cycle orchestrator chaining all five phases with gates and controls
Decompose work into small testable tasks with clear dependencies
SOC 職業分類に基づく
| name | compound-agent-security-deps |
| description | Dependency audit for vulnerable packages, lockfile changes, postinstall scripts, and supply chain risks |
On-demand specialist for auditing dependency security, lockfile changes, and supply chain risks.
docs/compound/research/security/dependency-security.md for risk model and audit methodologypnpm audit or npm audit -- report critical and high vulnerabilitiespip-audit or safety check -- report known CVEsdocs/compound/research/security/dependency-security.md for risk assessment methodologydocs/compound/research/security/secure-coding-failure.md section 4.9 for theoretical foundationca knowledge "dependency vulnerability supply chain" for indexed knowledgeReport findings to security-reviewer via SendMessage with severity classification. Flag architecture-level dependency concerns (e.g., replacing a core library) to architecture-reviewer.
On-demand AgentTeam member in the review phase. Spawned by security-reviewer when dependency changes detected. Communicate with teammates via SendMessage.
Per finding:
If no findings: return "DEPENDENCY REVIEW: CLEAR -- No vulnerable or suspicious dependencies found."