๐Ÿ›ก๏ธ
QualityRust

OSV Dependency Scan

by deonmenezes

OSV Dependency Scan is a Quality skill for Claude Code, published by deonmenezes in mantishack.

490 stars73 forkson deonmenezes/mantishackAdded 2026/08/26Repository updated 2026/08/11
agent-harnessai-agentsautonomous-agentsbug-bountyclaude-codemantismcpoffensive-securitysecurity
Install in seconds
Install OSV Dependency Scan
Copy OSV Dependency Scan into your Claude Code skills folder. Run the command in your terminal, or review the source on GitHub before installing.
terminal
npx degit https://github.com/deonmenezes/mantishack/tree/main/.codex/skills/osv-dependency-scan ~/.claude/skills/osv-dependency-scan

Requires Node.js. Downloads this skill only โ€” not the rest of the repository โ€” into your Claude Code skills folder.

Without Node.js

git clone https://github.com/deonmenezes/mantishack.git

Clones the whole repository, then copy the skillโ€™s own directory into your skills folder yourself.

In this catalog

Source file
.codex/skills/osv-dependency-scan/SKILL.md in deonmenezes/mantishack
Installs to
~/.claude/skills/osv-dependency-scan
Collection
One of 25 skills cataloged from this repository
Category
Quality โ€” 1354 skills

What OSV Dependency Scan does

OSV Dependency Scan runs osv-scanner through the mantis_osv_scanner MCP server to find known vulnerable dependencies in manifests and lockfiles. Use it during the Detect stage and verify whether flagged code is actually reached before rejecting or accepting a finding.

OSV Dependency Scan is cataloged under Quality on DirSkills. OSV Dependency Scan comes from a repository tagged agent-harness, ai-agents, autonomous-agents, bug-bounty and claude-code.

Documentation

README

Use osv_scan({ path }) (mantis_osv_scanner MCP server) for the Detect stage's SCA coverage: known-vulnerable dependencies matched against the OSV database, recursively across manifests/lockfiles under path.

This is the opening of the README. Read the full README on GitHub.

Frequently asked about OSV Dependency Scan

  • What else does deonmenezes publish alongside OSV Dependency Scan?

    OSV Dependency Scan is one of 25 skills that DirSkills catalogs from deonmenezes/mantishack, the repository it ships in. Its siblings there include Canary Tripwire Response, Code Breaking Changes and Code Review. Each one is a separate skill with its own page in this directory, installs the same way OSV Dependency Scan does, and is maintained by deonmenezes in that same repository. The rest of the collection is listed on the deonmenezes/mantishack page.

  • How does OSV Dependency Scan compare to other Quality skills?

    OSV Dependency Scan ranks #1248 by stars among the 1354 Quality skills in this catalog. The most-starred ones next to it are Benchmark, Benchmark Optimization Loop and API Design Patterns. DirSkills ranks by the star count of the repository each skill ships in, so that order reflects how popular those repositories are rather than any review of OSV Dependency Scan against them. Open each page to compare what they document and how they install.

More from deonmenezes/mantishack

OSV Dependency Scan is one of 25 skills cataloged on DirSkills from deonmenezes/mantishack.

See all 25 skills โ†’
๐Ÿšจ
5d ago

Canary Tripwire Response

Canary Tripwire Response tells you how to react if a mantis_canary decoy tool is mentioned or called. It treats the event as a security incident, preserves evidence, and stops normal execution.
AI Engineering
49073
โš ๏ธ
5d ago

Code Breaking Changes

Code Breaking Changes searches external integration surfaces for breaking changes in app-server APIs, CLI parameters, configuration loading, and session resuming. Use it when reviewing changes for compatibility risks across these interfaces.
Quality
49073
๐Ÿ”Ž
5d ago

Code Review

Code Review runs a final review on a pull request by delegating to other code-review subagents and collecting their findings. Use it to surface every issue with file paths and line numbers before merging.
Quality
49073
๐Ÿงฉ
5d ago

Code Review Change Size

Code Review Change Size sets limits for how many lines a change should touch and asks for staged delivery when a diff is too large. Use it to judge whether a change is reviewable in one pass or should be split.
Quality
49073
๐Ÿงฉ
5d ago

Code Review Context

Code Review Context defines constraints for building model context incrementally, with bounded fragments and hard caps. Use it when reviewing changes that inject visible context into Codex requests.
Quality
49073
๐Ÿงช
5d ago

Code Review Testing

Code Review Testing gives guidance for authoring tests for agent changes, with a preference for integration tests in core/suite. It is used when changes affect agent logic and need readable, maintainable test coverage.
Quality
49073