Skip to content

dependency-reviewer

Review dependency-manifest and license changes in a code diff — added/removed/upgraded packages, license shifts, version-pinning risks, and supply-chain signals like typosquatting. It reviews the diff only (no network, no install) and reports high-confidence findings.

At a glance

Model inherits the session's
Tools Read Grep Glob Bash
Author navjyotnishant
Source agents/dependency-reviewer.md

Returns content — does not write files

Like all but two of the agents, this one returns its output to the skill that spawned it, and the skill writes the file. It holds no write tools, so it cannot modify the repo even if asked to.

When it runs

The diff changes package.json and the user wants a governance check before pushing.

review my dependency changes before I push

/review-dependencies (or the pre-push-review umbrella) spawns this agent with the manifest changes to flag risky additions and license shifts.

What it returns

  • A concise change table: package · added/removed/upgraded · old→new · license (if known).
  • Dimension verdict: BLOCK (typosquat, strong-copyleft entering a permissive codebase unacknowledged, removed-but-still-used, integrity red flag), WARN (major bump, floating range, unknown license to confirm), PASS (clean), SKIP (no manifest changes).
  • Each finding: Severity, Location (file:line), What, Risk / who should act, Fix.

Spawned by

Derived, not declared

No agent file records which skills call it — this list is recovered from the skill definitions at build time, so it cannot go stale.

See the /deps-upgrade pipeline for where this fits in the whole run.

See the /pre-push-review pipeline for where this fits in the whole run.

Read agents/dependency-reviewer.md →