원클릭으로
security-deps-specialist
Dependency audit for vulnerable packages, lockfile changes, postinstall scripts, and supply chain risks
Codex 또는 Claude로 설치 이 Prompt를 복사해 Codex, Claude 또는 다른 어시스턴트에 붙여 넣으면 Skill 페이지를 검토하고 설치를 진행할 수 있습니다.
메뉴
Dependency audit for vulnerable packages, lockfile changes, postinstall scripts, and supply chain risks
Codex 또는 Claude로 설치 이 Prompt를 복사해 Codex, Claude 또는 다른 어시스턴트에 붙여 넣으면 Skill 페이지를 검토하고 설치를 진행할 수 있습니다.
SOC 직업 분류 기준
Audit and set up a codebase for agentic AI development using the 15-principle manifesto
Full-cycle orchestrator chaining all five phases with gates and controls
Audit and set up a codebase for agentic AI development using the 15-principle manifesto
Full-cycle orchestrator chaining all five phases with gates and controls
Reviews code for architectural compliance and design integrity
Deep semantic analysis of codebase against rules, patterns, and lessons
| name | Security Deps Specialist |
| description | Dependency audit for vulnerable packages, lockfile changes, postinstall scripts, and supply chain risks |
On-demand specialist for auditing dependency security, lockfile changes, and supply chain risks.
docs/compound/research/security/dependency-security.md for risk model and audit methodologypnpm audit or npm audit -- report critical and high vulnerabilitiespip-audit or safety check -- report known CVEsdocs/compound/research/security/dependency-security.md for risk assessment methodologydocs/compound/research/security/secure-coding-failure.md section 4.9 for theoretical foundationnpx ca knowledge "dependency vulnerability supply chain" for indexed knowledgeReport findings to security-reviewer via SendMessage with severity classification. Flag architecture-level dependency concerns (e.g., replacing a core library) to architecture-reviewer.
On-demand AgentTeam member in the review phase. Spawned by security-reviewer when dependency changes detected. Communicate with teammates via SendMessage.
Per finding:
If no findings: return "DEPENDENCY REVIEW: CLEAR -- No vulnerable or suspicious dependencies found."