Audits project dependencies for outdated versions, known CVEs, unused packages, license conflicts, and supply-chain risks. Use whenever the user mentions "audit", "vulnerabilities", "CVE", "outdated packages", "npm audit", "pip audit", "dependency review", "supply chain", "should I upgrade X", "is X safe", or shares a package.json / requirements.txt / pyproject.toml / Cargo.toml / go.mod and asks about its health. Produces prioritized findings with concrete upgrade or removal actions.