How to fix it
- Upgrade to the fixed version and run your tests.
- If no fix exists, check whether you use the vulnerable code path, or replace the package.
- Remove packages nothing imports.
Assistants add a package for every problem and pin the version they remember from training. Some of those versions have published vulnerabilities.
npx @neuralaxis/vibedoctor scan What it looks like
“npm install succeeded” says nothing about whether a version has a known exploit.
Unused packages still ship, still run install scripts, and still show up in advisories.
"astro": "5.18.2" → advisory fixed in 6.3.3 Example: A real finding on this website's own lockfile during its build.
What VibeDoctor reports
| Finding | Severity | Evidence | From |
|---|---|---|---|
| Advisory ID (for example GHSA-…) package@version, whether it is a runtime, dev, or transitive dependency, and the version that fixes it. | by advisory | verified | osv-scanner |
| Unused dependency knip for JavaScript and TypeScript. deptry reports unused and missing packages in Python. | low–medium | observed | knip / deptry |
Evidence grades say how sure the finding is. What verified, observed and heuristic mean →
How to fix it
What this check can’t see
Run it
npx @neuralaxis/vibedoctor scan
Runs locally on JavaScript, TypeScript and Python repos. Hand the result to Cursor,
Claude Code, Codex or Copilot with agent-plan.
Agent setup →