Audit a lockfile
check_lockfileAudit a whole lockfile or dependency file in one call, including transitive dependencies where the file records them. Paste the file content as-is: package-lock.json, npm-shrinkwrap.json, yarn.lock, pnpm-lock.yaml, requirements.txt (== pins), poetry.lock, uv.lock, Pipfile.lock, Cargo.lock, go.sum, go.mod, packages.lock.json (NuGet) or gradle.lockfile. Up to 3,000 packages are checked against OSV.dev. Returns a summary and only the packages with problems: malicious-package flags first, then vulnerabilities by severity with the minimum upgrade target. Use when the user pastes or attaches a lockfile, asks for a full or transitive dependency audit, or asks "is my project vulnerable?". Prefer this over check_dependencies when the user has the file itself.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| content | Yes | The full text of the lockfile or dependency file, pasted as-is | |
| filename | No | File name, e.g. package-lock.json, yarn.lock, Cargo.lock, go.sum, poetry.lock. Helps detect the format |