dependency-reviewer¶
Review dependency-manifest and license changes in a code diff — added/removed/upgraded packages, license shifts, version-pinning risks, and supply-chain signals like typosquatting. It reviews the diff only (no network, no install) and reports high-confidence findings.
At a glance¶
| Model | inherits the session's |
| Tools | Read Grep Glob Bash |
| Author | navjyotnishant |
| Source | agents/dependency-reviewer.md |
Returns content — does not write files
Like all but two of the agents, this one returns its output to the skill that spawned it, and the skill writes the file. It holds no write tools, so it cannot modify the repo even if asked to.
When it runs¶
The diff changes package.json and the user wants a governance check before pushing.
review my dependency changes before I push
/review-dependencies (or the pre-push-review umbrella) spawns this agent with the manifest changes to flag risky additions and license shifts.
What it returns¶
- A concise change table: package · added/removed/upgraded · old→new · license (if known).
- Dimension verdict:
BLOCK(typosquat, strong-copyleft entering a permissive codebase unacknowledged, removed-but-still-used, integrity red flag),WARN(major bump, floating range, unknown license to confirm),PASS(clean),SKIP(no manifest changes). - Each finding: Severity, Location (
file:line), What, Risk / who should act, Fix.
Spawned by¶
Derived, not declared
No agent file records which skills call it — this list is recovered from the skill definitions at build time, so it cannot go stale.
See the /deps-upgrade pipeline for where this fits in the whole run.
See the /pre-push-review pipeline for where this fits in the whole run.