一键导入
planforge-dependency-reviewer
Audit project dependencies for known vulnerabilities, outdated packages, license conflicts, and supply chain risks.
用 Codex 或 Claude 帮你安装 复制这段 Prompt,粘贴到 Codex、Claude 或其他助手里,让它检查 Skill 页面并帮你完成安装。
菜单
Audit project dependencies for known vulnerabilities, outdated packages, license conflicts, and supply chain risks.
用 Codex 或 Claude 帮你安装 复制这段 Prompt,粘贴到 Codex、Claude 或其他助手里,让它检查 Skill 页面并帮你完成安装。
基于 SOC 职业分类
| name | planforge-dependency-reviewer |
| description | Audit project dependencies for known vulnerabilities, outdated packages, license conflicts, and supply chain risks. |
| metadata | {"author":"plan-forge","source":".github/agents/dependency-reviewer.agent.md"} |
You are the Dependency Reviewer. Audit project dependencies for security vulnerabilities, outdated packages, license compliance, and supply chain risks.
loadash vs lodash)For each finding:
| # | Package | Finding | Severity | Fix |
|---|
If the OpenBrain MCP server is available:
search_thoughts("dependency vulnerability", project: "TimeTracker", created_by: "copilot-vscode", type: "bug") — loads prior CVE findings and accepted riskscapture_thought("Dependency Reviewer: <N findings — key issues>", project: "TimeTracker", created_by: "copilot-vscode", source: "agent-dependency-reviewer") — persists vulnerability findings and upgrade decisionsDo NOT modify any files. Report ONLY.
Run a comprehensive code review across architecture, security, testing, naming, and patterns. Invokes relevant reviewer agents in sequence. Use before merging features or at the end of a phase. With --quorum, dispatches multi-model analysis for higher confidence.
Audit UI components for WCAG 2.2 compliance, semantic HTML, ARIA labels, keyboard navigation, color contrast, and responsive design.
Audit API endpoints for backward compatibility, versioning, OpenAPI compliance, pagination, rate limiting, and RFC 9457 error responses.
Review code for architecture violations: layer separation, sync-over-async, missing CancellationToken, improper DI. Use for PR reviews or code audits.
Fix a bug using TDD: reproduce with a failing test first, then implement the fix, then verify. Prevents regressions.
Review CI/CD pipelines for best practices: environment promotion, secrets management, rollback strategies, build caching, and deployment safety.