---
title: "dependency-checker"
description: "Static multi-ecosystem dependency evidence, security, SBOM, and update-impact analysis for coding agents."
canonical: https://agentpluginsdirectory.com/plugins/dependency-checker
last-updated: 2026-10-02
---

# dependency-checker
Static multi-ecosystem dependency evidence, security, SBOM, and update-impact analysis for coding agents.
- Slug: dependency-checker
- Publisher: Steven Yang
- Repository: https://github.com/steventimes/dependency-checker
- Manifest: plugin.json
- Version: 0.4.0
- License: Apache-2.0
- Category (editorial): security
- Skills: 1 (check-dependencies)
- MCP servers: 1 (depcheck)
- Stars: 0
- Repository created: 2025-11-19
- Repository last pushed: 2026-10-01
- Publisher type: User
- Listing: https://agentpluginsdirectory.com/plugins/dependency-checker
- Schema: https://agent-plugins.org/schemas/1.0.0/plugin.schema.json

## What dependency-checker does, in the publisher's words

depcheck is a static dependency-evidence scanner for repositories and coding agents. It correlates declarations, exact resolutions, source usage, security results, and policy findings without importing project code or running package managers.

- One qualified identity for every component: (project_id, ecosystem, package, version, instance).
- Missing, unused, unpinned, conflicting, and scope-mismatched dependency findings, gated by evidence confidence.
- Exact-version OSV queries for PyPI, npm, Go, and Maven.
- Python compatibility analysis backed by PyPI metadata when explicitly enabled.
- Text, depcheck.scan.v1 JSON, SARIF 2.1.0, and CycloneDX 1.7 output.
- A rebuildable depcheck.index.v3 SQLite evidence index.

A scan distinguishes findings from incomplete analysis. A skipped, unsupported, or failed capability never becomes a clean result.

Dynamic or ambiguous syntax is reported as incomplete evidence. Conan and vcpkg currently emit a security.ecosystem-unsupported diagnostic and keep security incomplete because depcheck cannot produce safe OSV coordinates for them.

From the project README, punctuation lightly normalized. Full text: https://raw.githubusercontent.com/steventimes/dependency-checker/HEAD/README.md

## Skills

- check-dependencies: Index and audit static multi-ecosystem dependency evidence, explain qualified package identities and impact, inspect security findings, and preview supported manifest updates. Use when reviewing dependency health, investigating unused or missing packages, preparing upgrades, generating SBOM context…

Descriptions come from the frontmatter of each SKILL.md, punctuation lightly normalized.

## MCP servers

- depcheck: transport: stdio; command: uv run --project . --extra agent --frozen depcheck-mcp

Read from the plugin's own mcp.json. Environment variable names only, never values.
