Install any skill in seconds. Free to start, no credit card required.
Get Started Free →Scan project dependencies for known vulnerabilities and CVEs. Use when auditing third-party packages, before releases, after `npm install`/lockfile changes, or when investigating reported CVE advisories.
| Test case | Without → With | Effect | Δ tokens | Δ turns |
|---|---|---|---|---|
| case-04 | ✗→✓ | ▲ Improved | -44% | 0% |
| case-07 | ✗→✓ | ▲ Improved | -28% | 0% |
| case-09 | ✗→✓ | ▲ Improved | -66% | 0% |
| case-10 | ✗→✓ | ▲ Improved | -66% | 0% |
| case-12 | ✗→✓ | ▲ Improved | -63% | 0% |
Check dependencies for CVEs and outdated packages:
bashnpx @claude-flow/cli@latest security cve --list npx @claude-flow/cli@latest security cve --severity critical npx @claude-flow/cli@latest security scan --type deps --depth deep npm audit --json
| Severity | Action | |----------|--------| | critical | Block deployment, fix immediately | | high | Fix before next release | | moderate | Schedule fix within sprint | | low | Track in backlog |
Auto-fix via the scan command: npx @claude-flow/cli@latest security scan --type deps --fix
For continuous monitoring, dispatch via MCP: mcp__plugin_ruflo-core_ruflo__hooks_worker-dispatch({ trigger: "audit" })
Other measured skills in the registry, with their headline benchmark lift.