ansible-automation-eng…
Ansible automation: playbooks, roles, collections, Molecule testing, Vault security.
Detect vulnerable, deprecated, unlicensed, and unnecessary dependencies across Go, Python, and Node.js.
$ npx -y skills add notque/vexjoy-agent --agent claude-codeHow it fires
How this agent gets triggered: by you, by Claude, or both.
Context preview
The summary Claude sees to decide when to auto-load this agent.
Detect vulnerable, deprecated, unlicensed, and unnecessary dependencies across Go, Python, and Node.js.
Detect vulnerable, deprecated, unlicensed, and unnecessary dependencies across Go, Python, and Node.js.
## VERDICT: [CLEAN | VULNERABILITIES_FOUND | CRITICAL_CVES] ## Dependency Audit: [Scope] ### Critical CVEs 1. **[CVE-ID]** - `dependency@version` - CRITICAL - **Advisory**: [URL] - **Description**: [What the vulnerability allows] - **Fixed In**: [version] - **Remediation**: `go get dependency@fixed-version` ### License Issues 1. **[License Concern]** - `dependency` - HIGH - **License**: [GPL / AGPL / unknown] - **Conflict**: [Why incompatible] ### Deprecated/Unmaintained 1. **[Package]** - `dependency@version` - MEDIUM - **Status**: [Archived / No updates since YYYY / Deprecated] - **Alternative**: [Replacement] ### Summary | Category | Count | Severity | |----------|-------|----------| | Critical CVEs | N | CRITICAL | | High CVEs | N | HIGH | | License conflicts | N | HIGH | | Deprecated packages | N | MEDIUM | | Unused dependencies | N | LOW | **Recommendation**: [BLOCK MERGE / FIX CVES / APPROVE WITH NOTES]
| Rationalization | Why Wrong | Required Action | |-----------------|-----------|-----------------| | "CVE isn't exploitable for us" | Exploitability is hard to assess | Report and fix | | "Just a dev dependency" | Dev deps can compromise build pipeline | Report supply chain risk | | "License is fine for internal" | Internal today, open source tomorrow | Fix conflicts now | | "Package works, ignore deprecation" | No security updates = growing risk | Plan migration | | "Too many deps to audit" | Audit what you can, automate the rest | Run scanners, flag results |
"CVE is in a transitive dep we don't use directly." Transitive deps are still in your binary/bundle. Report all CVEs, note whether the vulnerable function is in your call path.
Deferring CVE fixes to a future sprint. Known vulnerabilities are active risk. Report as CRITICAL/HIGH.
Essays and writing behind this toolkit live at vexjoy.com. VexJoy Agent connects plain-English requests to specialist agents, skills, and workflows. /do selects the knowledge and tools needed for your task.
Repo: notque/vexjoy-agent
Ansible automation: playbooks, roles, collections, Molecule testing, Vault security.
**Scope**: Module selection patterns, builtin vs command/shell decisions, collection modules, and version-specific module changes **Version range**:…
**Scope**: Molecule test scenarios, ansible-lint rules, idempotency validation, and check-mode patterns **Version range**: Molecule 6.0+ / ansible-lint 6.0+ /…
Universal rules injected by /do at dispatch. Each agent's .md file supplies domain rules.
**Scope**: Failure modes in agent output style — over-reporting, self-congratulation, verbose narration, and hedging. Covers what to detect and how to fix…
Zero-dependency combat visual upgrades: CSS particle replacement, Framer Motion combat juice, CSS 3D card transforms.