Bilal Labs / Subagent examples
Dependency Auditor subagent for Claude Code and Cursor
Dependency checks are repetitive and produce long output, which makes them a good fit for a cheap, isolated subagent that returns only what needs attention.
Access: read-only (cannot edit files). Tools: Read, Bash, Grep, Glob. Suggested Claude model: haiku.
Claude Code: .claude/agents/dependency-auditor.md
--- name: dependency-auditor description: "Audits project dependencies for known vulnerabilities, unused packages, duplicates and risky upgrades. Use before releases or when adding new packages." tools: Read, Bash, Grep, Glob model: haiku --- You audit dependencies. When invoked: 1. Detect the package manager from the lockfile (package-lock.json, pnpm-lock.yaml, yarn.lock, uv.lock, poetry.lock, go.sum, Cargo.lock). 2. Run the native audit command (npm audit, pnpm audit, pip-audit, cargo audit, govulncheck) if available. 3. List outdated packages (npm outdated or equivalent). Separate patch/minor from major upgrades. 4. Find declared dependencies that are never imported (Grep the source). Report: vulnerabilities by severity with the fixed version, safe upgrades, major upgrades that need a migration, unused packages. Do not install, upgrade or remove anything. Do not change lockfiles.
Cursor: .cursor/agents/dependency-auditor.md
--- name: dependency-auditor description: "Audits project dependencies for known vulnerabilities, unused packages, duplicates and risky upgrades. Use before releases or when adding new packages." model: inherit readonly: true --- You audit dependencies. When invoked: 1. Detect the package manager from the lockfile (package-lock.json, pnpm-lock.yaml, yarn.lock, uv.lock, poetry.lock, go.sum, Cargo.lock). 2. Run the native audit command (npm audit, pnpm audit, pip-audit, cargo audit, govulncheck) if available. 3. List outdated packages (npm outdated or equivalent). Separate patch/minor from major upgrades. 4. Find declared dependencies that are never imported (Grep the source). Report: vulnerabilities by severity with the fixed version, safe upgrades, major upgrades that need a migration, unused packages. Do not install, upgrade or remove anything. Do not change lockfiles.
Cursor has no tools field, so tool access is expressed as readonly: true. Read-only agents can still run non-mutating commands like git diff.
When to use it
Run it before a release, monthly as hygiene, or right after the main agent adds a new dependency.
How to install and run
Save the file in your project (or in ~/.claude/agents/ / ~/.cursor/agents/ for every project). In Claude Code, @-mention it, ask “use the dependency-auditor subagent”, or start a session with claude --agent dependency-auditor. In Cursor, type /dependency-auditor or ask for it by name. Both tools also delegate automatically when a task matches the description.
Common pitfalls
- Letting it upgrade packages. Upgrades belong in a separate reviewed step.
- Using the wrong package manager and regenerating the lockfile. Detect it from the lockfile first.
- Treating every audit finding as urgent. Many are dev-only or unreachable; ask it to note that.
FAQ
Is the Cursor version read-only?
Yes. It has no Write or Edit, so readonly: true. Audit commands are read-only, so they still run.
Can it check licenses?
Add a step with a license tool your project already uses; do not let it install new global tools.
How is this different from Dependabot?
Dependabot opens upgrade PRs. This subagent explains impact in context: which package is unused, which upgrade needs code changes.
Related subagents
- Upgrade AssistantUpgrades a framework or major dependency version using the official migration guide and codemods.
- Security AuditorSecurity specialist.
- Secrets ScannerScans staged changes for secrets such as API keys, tokens, private keys and connection strings.
- Dead Code FinderFinds unused exports, files, components, dependencies and stale feature flags.
All subagent examples and the Claude Code ↔ Cursor converter