What it does
Goes beyond `npm audit` — correlates CVEs with your actual code paths to separate real threats from noise.
Why you need it
Most dependency audits produce 100 warnings and 95 are false positives. This skill checks whether you actually USE the vulnerable code path, so you fix what matters.
Key capabilities
- npm, pip, gem, and cargo support
- Usage-path correlation to reduce false positives
- Fix suggestions with compatibility checks
- Auto-PR generation for patches
- SBOM (Software Bill of Materials) generation
Category
security
Tier
Pro
Version
v1.0.0
Installs
31
Latest: v1.0.0
Initial release
Apr 13, 2026
Related Skills
security
Free
Secret Scanner
Detect leaked API keys, tokens, and credentials in your codebase
No ratings yet
50 installs
#secrets#credentials#scanning+1
security
Pro
GitHub PR Reviewer
Automated pull request review with inline comments and approval logic
No ratings yet
37 installs
#github#pull-request#code-review+2