一键导入
compound-agent-security-deps
Dependency audit for vulnerable packages, lockfile changes, postinstall scripts, and supply chain risks
用 Codex 或 Claude 帮你安装 复制这段 Prompt,粘贴到 Codex、Claude 或其他助手里,让它检查 Skill 页面并帮你完成安装。
菜单
Dependency audit for vulnerable packages, lockfile changes, postinstall scripts, and supply chain risks
用 Codex 或 Claude 帮你安装 复制这段 Prompt,粘贴到 Codex、Claude 或其他助手里,让它检查 Skill 页面并帮你完成安装。
基于 SOC 职业分类
Decompose a large system specification into cook-it-ready epic beads via DDD bounded contexts
Reference for configuring, launching, and monitoring infinity loops and polish loops
Decompose a large system specification into cook-it-ready epic beads via DDD bounded contexts
Reflect on the cycle and capture high-quality lessons for future sessions
Full-cycle orchestrator chaining all five phases with gates and controls
Decompose work into small testable tasks with clear dependencies
| name | compound-agent-security-deps |
| description | Dependency audit for vulnerable packages, lockfile changes, postinstall scripts, and supply chain risks |
On-demand specialist for auditing dependency security, lockfile changes, and supply chain risks.
docs/compound/research/security/dependency-security.md for risk model and audit methodologypnpm audit or npm audit -- report critical and high vulnerabilitiespip-audit or safety check -- report known CVEsdocs/compound/research/security/dependency-security.md for risk assessment methodologydocs/compound/research/security/secure-coding-failure.md section 4.9 for theoretical foundationca knowledge "dependency vulnerability supply chain" for indexed knowledgeReport findings to security-reviewer via SendMessage with severity classification. Flag architecture-level dependency concerns (e.g., replacing a core library) to architecture-reviewer.
On-demand AgentTeam member in the review phase. Spawned by security-reviewer when dependency changes detected. Communicate with teammates via SendMessage.
Per finding:
If no findings: return "DEPENDENCY REVIEW: CLEAR -- No vulnerable or suspicious dependencies found."