ワンクリックで
security-deps-specialist
Dependency audit for vulnerable packages, lockfile changes, postinstall scripts, and supply chain risks
Codex または Claude でインストール この Prompt をコピーして Codex、Claude、または他のアシスタントに貼り付けると、Skill ページを確認してインストールできます。
メニュー
Dependency audit for vulnerable packages, lockfile changes, postinstall scripts, and supply chain risks
Codex または Claude でインストール この Prompt をコピーして Codex、Claude、または他のアシスタントに貼り付けると、Skill ページを確認してインストールできます。
SOC 職業分類に基づく
Audit and set up a codebase for agentic AI development using the 15-principle manifesto
Full-cycle orchestrator chaining all five phases with gates and controls
Audit and set up a codebase for agentic AI development using the 15-principle manifesto
Full-cycle orchestrator chaining all five phases with gates and controls
Reviews code for architectural compliance and design integrity
Deep semantic analysis of codebase against rules, patterns, and lessons
| name | Security Deps Specialist |
| description | Dependency audit for vulnerable packages, lockfile changes, postinstall scripts, and supply chain risks |
On-demand specialist for auditing dependency security, lockfile changes, and supply chain risks.
docs/compound/research/security/dependency-security.md for risk model and audit methodologypnpm audit or npm audit -- report critical and high vulnerabilitiespip-audit or safety check -- report known CVEsdocs/compound/research/security/dependency-security.md for risk assessment methodologydocs/compound/research/security/secure-coding-failure.md section 4.9 for theoretical foundationnpx ca knowledge "dependency vulnerability supply chain" for indexed knowledgeReport findings to security-reviewer via SendMessage with severity classification. Flag architecture-level dependency concerns (e.g., replacing a core library) to architecture-reviewer.
On-demand AgentTeam member in the review phase. Spawned by security-reviewer when dependency changes detected. Communicate with teammates via SendMessage.
Per finding:
If no findings: return "DEPENDENCY REVIEW: CLEAR -- No vulnerable or suspicious dependencies found."