Security · inspect by default

/security-dependencies

Assess findings against actual application exposure

Use for advisory-driven dependency risk; deps covers general maintenance and compatibility, and security-fix applies a confirmed advisory remediation.

Make it your own.

In Claude Code, use the slash command and add your context. In Codex, select security-dependencies from the just-vibe skill picker, then send the same brief.

Version 0.11.0 also supports /jv security-dependencies, /just-vibe security-dependencies and /jv:security-dependencies in Claude. See shortcut setup and context examples.

Example · inspect
/just-vibe:security-dependencies Assess advisories against resolved versions and reachable runtime use.
edge · inspect
/just-vibe:security-dependencies Assess a transitive vulnerability behind an unused optional feature.
blocked · inspect
/just-vibe:security-dependencies Inspect the lockfile without current advisory access; report unknown coverage.

What the agent does

  1. Match current authoritative advisories to resolved versions and configurations.
  2. Trace deployed and reachable usage, distinguishing development-only tooling from production exposure.
  3. Recommend compatible updates or mitigations with checks.

Inputs

  • manifests/lockfiles, advisory evidence, deployment use, and update constraints.

Optional context: scope, references, constraints, successCriteria, environment, mode, budget.

Scope

Reads
Dependency vulnerability relevance and remediation feasibility.
Writes
No source changes in inspect/plan. Save only requested planning artifacts. A separately requested repair uses the relevant implementation workflow.
Mode
Inspect; manifests/lockfiles, advisory evidence, deployment use, and update constraints.
Prerequisites
Defined application boundary, authorized code/environment, relevant trust/access rules, and evidence sources. Default to defensive inspection; active tests use owned or explicitly authorized isolated targets. Minimize sensitive evidence and never print usable credentials.

Expected output

  • Advisory/version/reachability matrix with advisory references, exposure rationale, and tested remediation options with checks.

How the work is checked

  • A transitive runtime exposure is traced; an advisory mismatch or mitigated precondition is explained accurately.

When to stop or clarify

  • No forced major upgrades or automatic suppression. Missing advisory access means unknown coverage, not a clean security bill.

Handling missing context

Infer
Resolve the requested surface, source/runtime version, reachable callers and actual trust/access boundaries.
Assume
Start with source analysis and bounded owned fixtures; treat scanner output as leads and preserve legitimate controls.
Ask
Ask when target authorization or necessary trust semantics are unresolved before active probing; source inspection need not wait for production access.

Technical guidance

Evidence
Read resolved lockfile versions, ecosystem, installed scanner/version and current authoritative advisories.
Method
Distinguish advisory match, deployed reachability and fix compatibility; record tool exit status and advisory freshness with coverage.
Pitfall
An audit error or unsupported lockfile is unknown, not clean; a CVE match alone does not prove the vulnerable function is reachable.
Check
Verify fixed version resolution and the affected behavior after a supported update; retain remaining findings and failed/offline checks.

Situational decisions

When a fix requires a breaking upgrade: Compare supported mitigation and migration paths; do not suppress the advisory or force unrelated upgrades.

The coding agent follows this workflow using its available tools. Installation does not grant service access or guarantee an outcome. Read the compatibility notes.

Keep exploring