Safely audit and remediate dependency vulnerabilities (npm/pip). Performs state-check before updates, parses JSON-only reports, and ensures zero-breaking changes by validating SemVer and running tests. Use when the user wants to "fix security issues" or "update packages safely".