All skills
dependency-vulnerability-scanning
FoundationJIT onlyDependency graph vulnerability, provenance, license, or exception risk.
- Group
- Security & privacy
- Supported roles
- MainAnalysisTaskReview
- Source
- SKILL.md
Use when
Trigger signals that make this skill the right owner
- dependency changes or advisories need vulnerability reachability, malicious-package, license, provenance, install-time execution, or exception review
Do not use when
Anti-triggers — as binding as the triggers above
- only package-manager mechanics or version selection changes and no package-risk acceptance is required
Required inputs
What must be supplied before this skill can decide anything
- current task contract
- selected primary Professional Skill
- task-local trigger evidence
Output contract
What this skill owes the next role
- Return a dependency-risk decision: state graph delta, reachability, execution origin, license evidence, remediation, bounded exceptions, and proof limits
Escalation signals
When this skill must hand the decision back
- Unreviewed dependencies can introduce exploitable or unsupported code paths
Loaded by
This skill never owns a task. These professionals may pull it in as Layer 3.
Targeted references
Each reference carries its own load condition. None of them enter context by default.
| Reference | Load when | Do not load when | Required by |
|---|---|---|---|
| benchmarks-and-patterns.mdbenchmark-pattern | vulnerability origin license remediation or exception signals compete | one current graph and policy path resolves package risk without comparison | AnalysisTaskReview |
| checklist.mddecision-checklist | resolved graph delta needs reachability execution origin license remediation and exception closure | no dependency graph or package-risk acceptance changes | AnalysisTaskReview |
| evidence-patterns.mdevidence-pattern | scanner reachability provenance license SBOM or exception claims need fresh proof | no package-risk claim is being accepted | AnalysisTaskReview |