# Dependency Vulnerability Scan

> 在新增、升级或审查依赖时检查安全漏洞、维护状态、许可证风险、供应链风险和替代方案。

- **Type:** Skill
- **Install:** `agentstack add skill-ligydt-ai-ide-init-template-dependency-vulnerability-scan`
- **Verified:** Yes — security-reviewed for prompt injection and unsafe behavior
- **Seller:** [ligyDt](https://agentstack.voostack.com/s/ligydt)
- **Installs:** 0
- **Category:** [Security](https://agentstack.voostack.com/c/security)
- **Latest version:** 0.1.0
- **License:** MIT
- **Upstream author:** [ligyDt](https://github.com/ligyDt)
- **Source:** https://github.com/ligyDt/ai-ide-init-template/tree/main/cursor/.cursor/skills/dependency-vulnerability-scan

## Install

```sh
agentstack add skill-ligydt-ai-ide-init-template-dependency-vulnerability-scan
```

Requires the [AgentStack CLI](https://agentstack.voostack.com/docs/cli). Works with Claude Code, Cursor, and any MCP-compatible agent.

## About

# 依赖漏洞与许可证扫描

## 流程

1. 识别包管理器、锁文件、直接依赖、间接依赖和运行环境。
2. 优先使用项目已有 audit、SCA、许可证检查和 CI 命令。
3. 对 High/Critical 漏洞、未知许可证、GPL/AGPL、废弃包和低维护依赖列为阻断或需人工确认。
4. 给出替代依赖、版本固定、隔离使用或延后接入建议。
5. 输出不会包含私有 registry token、许可证密钥或内部仓库凭据。

## 输出

- 依赖清单与风险级别
- 漏洞和许可证结论
- 推荐处理方案
- 需人工确认事项

## 停止条件

缺少目标、范围、运行环境或高风险授权时，先澄清或输出待确认事项，不擅自接入外部写入、支付、部署或生产资源。

## Source & license

This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.

- **Author:** [ligyDt](https://github.com/ligyDt)
- **Source:** [ligyDt/ai-ide-init-template](https://github.com/ligyDt/ai-ide-init-template)
- **License:** MIT

Install and usage instructions live in the source repository linked above.

## Pricing

- **Free** — Free

## Security capabilities

Automated source analysis of v0.1.0 — what this tool can access:

- **Network access:** no
- **Filesystem access:** no
- **Shell / process execution:** no
- **Environment & secrets:** no
- **Dynamic code execution:** no

*"Yes" means the capability is present in the source — more access means more to trust, not that it is unsafe.*


## Versions

- **0.1.0** — security scan: passed — Imported from the upstream source.

## Links

- Listing page: https://agentstack.voostack.com/l/skill-ligydt-ai-ide-init-template-dependency-vulnerability-scan
- Seller: https://agentstack.voostack.com/s/ligydt
- Browse the marketplace: https://agentstack.voostack.com/browse

---
Listed on AgentStack — the marketplace for AI agent skills and MCP servers. Every listing is security-reviewed. Creators keep 70%.
