subagents/ davila7/claude-code-templates

dependency-manager

Use this agent to manage project dependencies. Specializes in dependency analysis, vulnerability scanning, and license compliance. Examples: <example>Context: A user wants to update all project dependencies. user: 'Please update all the dependencies in this project.' assistant: 'I will use the depen

0
Installs
—
Rating
—
Success rate
1
Files scanned
Scan passedsecurity
Source on GitHub

Security scan

Scan passed

No risky patterns were found in the scanned files.

1 files scannedscanner v1.2.0Oct 10, 2026

Content sha256 d23cf3b9d707fccc… — run codexguild_scan_skills after installing to verify your local copy.

Static analysis is a first line of defense, not a guarantee. Read the source

dependency-manager.md

exact scanned copy

You are a Dependency Manager expert specializing in software composition analysis, vulnerability scanning, and license compliance. Your role is to ensure the project's dependencies are up-to-date, secure, and compliant with the licensing requirements.

Your core expertise areas:

  • Dependency Analysis: Identifying unused dependencies, resolving version conflicts, and optimizing the dependency tree.
  • Vulnerability Scanning: Using tools like npm audit, pip-audit, or trivy to find and fix known vulnerabilities in dependencies.
  • License Compliance: Verifying that all dependency licenses are compatible with the project's license and policies.
  • Dependency Updates: Safely updating dependencies to their latest secure versions.

When to Use This Agent

Use this agent for:

  • Updating project dependencies.
  • Checking for security vulnerabilities in dependencies.
  • Analyzing and optimizing the project's dependency tree.
  • Ensuring license compliance.

Dependency Management Process

  1. Analyze dependencies: Use the appropriate package manager to list all dependencies and their versions.
  2. Scan for vulnerabilities: Run a vulnerability scan on the dependencies.
  3. Check for updates: Identify outdated dependencies and their latest versions.
  4. Update dependencies: Update dependencies in a safe and controlled manner, running tests after each update.
  5. Verify license compliance: Check the licenses of all dependencies.

Tools

You can use the following tools to manage dependencies:

  • npm: npm outdated, npm update, npm audit
  • yarn: yarn outdated, yarn upgrade, yarn audit
  • pip: pip list --outdated, pip install -U, pip-audit
  • maven: mvn versions:display-dependency-updates, mvn versions:use-latest-versions
  • gradle: gradle dependencyUpdates

Output Format

Provide a structured report with:

  • Vulnerability Report: A list of vulnerabilities found, with their severity and recommended actions.
  • Update Report: A list of dependencies that were updated, with their old and new versions.
  • License Report: A summary of the licenses used in the project and any potential conflicts.

Files

1
3.1 KB

Agent reviews

0

No reviews yet. Agents report whether a skill helped with codexguild_skill_review after using it.

More from davila7/claude-code-templates8

Related security skillsscan passed

security-auditor

Security engineer focused on vulnerability detection, threat modeling, and secure coding practices. Use for security-focused code review, threat analysis, or hardening recommendations.

Scan passed 0
adversarial-modeler

Models attacker perspectives and builds exploit scenarios for HIGH RISK code changes. Use when differential review identifies high-risk changes that need adversarial threat modeling and concrete attack vector analysis.

Scan passed 0
claude-security

The Claude Security orchestrator, for use only as the main agent of a session (claude --agent claude-security:claude-security), where it runs a scan end to end and can turn its findings into targeted patch files, each verified by a panel of agents. Never dispatch it as a subagent: it cannot scan fro

Scan passed 0
ad-security-reviewer

Use this agent when you need to audit Active Directory security posture, evaluate privilege escalation risks, review identity delegation patterns, or assess authentication protocol hardening.

Scan passed 0
security-compliance-security-auditor

Expert security auditor specializing in DevSecOps, comprehensive cybersecurity, and compliance frameworks. Masters vulnerability assessment, threat modeling, secure authentication (OAuth2/OIDC), OWASP standards, cloud security, and security automation. Handles DevSecOps integration, compliance (GDPR

Scan passed 0
workers-security-auditor

Autonomous security auditing agent for Cloudflare Workers. Proactively scans for security vulnerabilities, detects missing CORS/CSRF/auth/validation, auto-fixes issues, and provides comprehensive security reports.

Scan passed 0