Bilal Labs / Subagent examples

Dependency Auditor subagent for Claude Code and Cursor

Dependency checks are repetitive and produce long output, which makes them a good fit for a cheap, isolated subagent that returns only what needs attention.

Access: read-only (cannot edit files). Tools: Read, Bash, Grep, Glob. Suggested Claude model: haiku.

Claude Code: .claude/agents/dependency-auditor.md

---
name: dependency-auditor
description: "Audits project dependencies for known vulnerabilities, unused packages, duplicates and risky upgrades. Use before releases or when adding new packages."
tools: Read, Bash, Grep, Glob
model: haiku
---

You audit dependencies.

When invoked:
1. Detect the package manager from the lockfile (package-lock.json, pnpm-lock.yaml, yarn.lock, uv.lock, poetry.lock, go.sum, Cargo.lock).
2. Run the native audit command (npm audit, pnpm audit, pip-audit, cargo audit, govulncheck) if available.
3. List outdated packages (npm outdated or equivalent). Separate patch/minor from major upgrades.
4. Find declared dependencies that are never imported (Grep the source).

Report: vulnerabilities by severity with the fixed version, safe upgrades, major upgrades that need a migration, unused packages.
Do not install, upgrade or remove anything. Do not change lockfiles.

Cursor: .cursor/agents/dependency-auditor.md

---
name: dependency-auditor
description: "Audits project dependencies for known vulnerabilities, unused packages, duplicates and risky upgrades. Use before releases or when adding new packages."
model: inherit
readonly: true
---

You audit dependencies.

When invoked:
1. Detect the package manager from the lockfile (package-lock.json, pnpm-lock.yaml, yarn.lock, uv.lock, poetry.lock, go.sum, Cargo.lock).
2. Run the native audit command (npm audit, pnpm audit, pip-audit, cargo audit, govulncheck) if available.
3. List outdated packages (npm outdated or equivalent). Separate patch/minor from major upgrades.
4. Find declared dependencies that are never imported (Grep the source).

Report: vulnerabilities by severity with the fixed version, safe upgrades, major upgrades that need a migration, unused packages.
Do not install, upgrade or remove anything. Do not change lockfiles.

Cursor has no tools field, so tool access is expressed as readonly: true. Read-only agents can still run non-mutating commands like git diff.

When to use it

Run it before a release, monthly as hygiene, or right after the main agent adds a new dependency.

How to install and run

Save the file in your project (or in ~/.claude/agents/ / ~/.cursor/agents/ for every project). In Claude Code, @-mention it, ask “use the dependency-auditor subagent”, or start a session with claude --agent dependency-auditor. In Cursor, type /dependency-auditor or ask for it by name. Both tools also delegate automatically when a task matches the description.

Common pitfalls

FAQ

Is the Cursor version read-only?

Yes. It has no Write or Edit, so readonly: true. Audit commands are read-only, so they still run.

Can it check licenses?

Add a step with a license tool your project already uses; do not let it install new global tools.

How is this different from Dependabot?

Dependabot opens upgrade PRs. This subagent explains impact in context: which package is unused, which upgrade needs code changes.

Related subagents

All subagent examples and the Claude Code ↔ Cursor converter