depguardScan project dependencies for vulnerabilities, license compliance, and generate security or compliance reports using native package manager audits.
Install via ClawdBot CLI:
clawdbot install suhteevah/depguardGrade Good — based on market validation, documentation quality, package completeness, maintenance status, and authenticity signals.
Sends data to undocumented external endpoint (potential exfiltration)
Report → https://depguard.pages.devCalls external URL not in known-safe list
https://depguard.pages.devAI Analysis
The skill's primary external call is to its own homepage (depguard.pages.dev), which is consistent with its stated purpose of providing a service and likely for reporting or license validation. There is no evidence of unauthorized data exfiltration, credential harvesting, hidden instructions, or obfuscated malicious behavior in the provided definition.
Audited Apr 16, 2026 · audit v1.0
Generated Mar 21, 2026
Maintainers of open-source software use DepGuard to ensure their dependencies are free from known vulnerabilities and have permissive licenses, preventing legal issues. It helps automate security checks during development and before releases, maintaining project health and trust.
Large organizations use DepGuard to enforce internal license policies, such as blocking GPL dependencies, and generate compliance reports for auditors. It integrates into CI/CD pipelines to continuously monitor for vulnerabilities, ensuring regulatory and security standards are met.
Early-stage startups adopt DepGuard to quickly scan their codebases for dependency vulnerabilities without upfront costs, using the free tier. As they grow, they upgrade to Pro for automated git hooks that prevent insecure commits, scaling security with minimal overhead.
DevOps teams integrate DepGuard into their build processes to automatically generate SBOMs and vulnerability reports for each release. This supports supply chain security initiatives and helps meet industry standards like NIST or ISO 27001.
Universities and coding bootcamps use DepGuard to teach students about dependency management and security best practices. Instructors run scans on student projects to highlight vulnerabilities and license issues, fostering awareness in software development courses.
DepGuard offers a free tier for basic vulnerability and license scanning, attracting individual developers and small teams. Revenue is generated through paid Pro and Team tiers, which include advanced features like continuous monitoring, policy enforcement, and compliance reporting.
Targets larger organizations with custom pricing for volume licenses, dedicated support, and on-premise deployment options. This model focuses on compliance and security needs, offering tailored solutions for regulated industries like finance or healthcare.
Generates revenue by partnering with CI/CD platforms, package managers, and security tools to offer DepGuard as an integrated service. This includes revenue sharing, referral fees, or white-labeling for broader market reach and enhanced user acquisition.
💬 Integration Tip
Start with the free scan command to test basic functionality, then configure the openclaw.json file for automated checks and set up git hooks with a Pro license for continuous monitoring.
Scored Jun 19, 2026
Security-first skill vetting for AI agents. Use before installing any skill from ClawdHub, GitHub, or other sources. Checks for red flags, permission scope,...
Security scanner for AI agent skills. 9 built-in detection signatures. Identifies secrets, unsafe execution patterns, and prompt injection. Sub-50ms results.
Wallet anti-theft guard. One-click scan for high-risk wallet approvals to protect user assets. Use when a user asks for a wallet security check, wallet healt...
Comprehensive security audit for an agent's full skill stack. Chains scanner, differ, trust-verifier, and health-monitor into a single assessment with priori...
GEO Audit — AI Search Visibility Checker for ChatGPT, Perplexity, Claude & Gemini. 29-point GEO readiness checklist: robots.txt AI crawler access, Index...
Audit and analyze Solidity smart contracts for security vulnerabilities. Use when reviewing, auditing, or analyzing smart contracts, Solidity code, DeFi prot...