CustomAgent.app
MCP
A2A
LangChain
Software Development

Dependency Vulnerability Scanner

Audits npm/pip/cargo dependencies for CVEs, deprecated packages, and license conflicts daily

4.7(91 reviews)
1,987 installs
by DepGuard.io
v1.0.0
FREEopen source
Install AgentPick your IDE or clone directly

Install as a GitHub Copilot agent via the gh CLI extension, or drop the .agent.md file into your repository.

gh extension install customagent/dependency-scanner

Or manually copy the agent file into .github/agents/dependency-scanner.agent.md

agent.md

About This Agent

Dependency Vulnerability Scanner is a free, open-source AI agent designed to automate development workflows. Built on the langchain framework, it handles the repetitive, time-consuming tasks so your team can focus on high-value work.

The agent integrates with your existing tools and data sources, requiring minimal configuration to get started. Once deployed, it runs autonomously — processing inputs, making decisions based on your rules, and delivering structured outputs you can act on immediately.

Fully open-source and community-driven. Fork it, extend it, contribute back. No vendor lock-in, no usage limits, no credit card required.

Example Prompts

Help me get started with Dependency Vulnerability Scanner
What can Dependency Vulnerability Scanner do for my development team?
Show me an example workflow using Dependency Vulnerability Scanner

Capability Matrix

Code review
Bug detection
Test generation
Documentation
Security scanning
Auto PR merge

LLM Compatibility

GPT-4oClaude 3.7 SonnetGemini 2.0 FlashOllama (local)

Setup Complexity

Easy — 15-minute setup

Reviews (91)

4.7
91 reviews
Overall
4.7
Setup
NaN
Documentation
NaN
Support
NaN
FREEOpen Source

MIT License — use commercially, fork, contribute

MIT License — free forever
1,987 community installs
Under 15 min setup
Community support on GitHub
D
DepGuard.io
Verified Creator

DepGuard.io builds open-source AI agents for the community.

License: MIT Open Source

  • Free for commercial use
  • Modify and redistribute
  • No attribution required
  • Fork for your own products