Check for known-vulnerable dependencies and supply-chain risk across the Python (pip/requirements or pyproject) backend and npm/Vite frontend. Use when the user asks to check for vulnerable packages, outdated dependencies, "is it safe to upgrade X," or before a viva/demo where a reviewer might ask about dependency hygiene. Trigger this periodically as a housekeeping check, not just on explicit request, if a long stretch has passed without one.