Skip to main content

dependency-check

Scan project dependencies for known vulnerabilities and CVEs. Use when auditing third-party packages, before releases, after `npm install`/lockfile changes, or when investigating reported CVE advisories.

跳到安装

来源信息

仓库
ruvnet/ruflo
最近来源活动
2026年7月17日 03:06
检测到的 SKILL.md 语言
英语
星标
73,010
分支
8,665

安装方式

默认使用会先检查来源的 Prompt;你也可以切换为直接命令,或下载本地副本。

检查来源文件

决定是否安装前,请先阅读 SKILL.md,以及 SkillsMP 当前展示的配套文件。

正在显示 SKILL.md

SKILL.md
来源说明 · 只读预览
name
dependency-check
description
Scan project dependencies for known vulnerabilities and CVEs. Use when auditing third-party packages, before releases, after `npm install`/lockfile changes, or when investigating reported CVE advisories.
argument-hint
[--path PATH]
allowed-tools
Bash(npx * npm *) mcp__plugin_ruflo-core_ruflo__memory_store Read
Check dependencies for CVEs and outdated packages: ```bash npx @claude-flow/cli@latest security cve --list npx @claude-flow/cli@latest security cve --severity critical npx @claude-flow/cli@latest security scan --type deps --depth deep npm audit --json ``` | Severity | Action | |----------|--------| | critical | Block deployment, fix immediately | | high | Fix before next release | | moderate | Schedule fix within sprint | | low | Track in backlog | Auto-fix via the scan command: `npx @claude-flow/cli@latest security scan --type deps --fix` For continuous monitoring, dispatch via MCP: `mcp__plugin_ruflo-core_ruflo__hooks_worker-dispatch({ trigger: "audit" })`
在 GitHub 查看