Dependency Risk Scan
A weekly security-debt baseline for your repo's dependencies: new serious vulnerabilities first (CVE, severity, upgrade available, direct or transitive), persistent ones counted with their age, resolved ones acknowledged. Silent when everything is clean — never silent on a failed audit.
Connectors
Skills · 1
dependency-audit
Load at every run. Carries the audit procedure (shallow fetch, ecosystem detection, the exact pip/npm audit commands with JSON parsing and fallbacks), the CVSS threshold rule, the new/still_open/resolved reconciliation cycle with the failed-audit rule in references/audit-procedure.md, and the two table schemas to recreate if a table is missing.
Scheduled tasks · 1
weekly dependency scan
At 06:00 AM, only on Thursday



