Security · inspect by default
/security-dependencies
Assess findings against actual application exposure
Use for advisory-driven dependency risk; deps covers general maintenance and compatibility, and security-fix applies a confirmed advisory remediation.
Make it your own.
In Claude Code, use the slash command and add your context. In Codex, select security-dependencies from the just-vibe skill picker, then send the same brief.
Version 0.11.0 also supports /jv security-dependencies, /just-vibe security-dependencies and /jv:security-dependencies in Claude. See shortcut setup and context examples.
/just-vibe:security-dependencies Assess advisories against resolved versions and reachable runtime use./just-vibe:security-dependencies Assess a transitive vulnerability behind an unused optional feature./just-vibe:security-dependencies Inspect the lockfile without current advisory access; report unknown coverage.What the agent does
- Match current authoritative advisories to resolved versions and configurations.
- Trace deployed and reachable usage, distinguishing development-only tooling from production exposure.
- Recommend compatible updates or mitigations with checks.
Inputs
- manifests/lockfiles, advisory evidence, deployment use, and update constraints.
Optional context: scope, references, constraints, successCriteria, environment, mode, budget.
Scope
- Reads
- Dependency vulnerability relevance and remediation feasibility.
- Writes
- No source changes in inspect/plan. Save only requested planning artifacts. A separately requested repair uses the relevant implementation workflow.
- Mode
- Inspect; manifests/lockfiles, advisory evidence, deployment use, and update constraints.
- Prerequisites
- Defined application boundary, authorized code/environment, relevant trust/access rules, and evidence sources. Default to defensive inspection; active tests use owned or explicitly authorized isolated targets. Minimize sensitive evidence and never print usable credentials.
Expected output
- Advisory/version/reachability matrix with advisory references, exposure rationale, and tested remediation options with checks.
How the work is checked
- A transitive runtime exposure is traced; an advisory mismatch or mitigated precondition is explained accurately.
When to stop or clarify
- No forced major upgrades or automatic suppression. Missing advisory access means unknown coverage, not a clean security bill.
Handling missing context
- Infer
- Resolve the requested surface, source/runtime version, reachable callers and actual trust/access boundaries.
- Assume
- Start with source analysis and bounded owned fixtures; treat scanner output as leads and preserve legitimate controls.
- Ask
- Ask when target authorization or necessary trust semantics are unresolved before active probing; source inspection need not wait for production access.
Technical guidance
- Evidence
- Read resolved lockfile versions, ecosystem, installed scanner/version and current authoritative advisories.
- Method
- Distinguish advisory match, deployed reachability and fix compatibility; record tool exit status and advisory freshness with coverage.
- Pitfall
- An audit error or unsupported lockfile is unknown, not clean; a CVE match alone does not prove the vulnerable function is reachable.
- Check
- Verify fixed version resolution and the affected behavior after a supported update; retain remaining findings and failed/offline checks.
Situational decisions
When a fix requires a breaking upgrade: Compare supported mitigation and migration paths; do not suppress the advisory or force unrelated upgrades.
The coding agent follows this workflow using its available tools. Installation does not grant service access or guarantee an outcome. Read the compatibility notes.