vdb_scan_lockfile
Scan lockfiles for transitive dependency vulnerabilities before merging. Get a REFUSE action to block risky merges.
Instructions
BEFORE merging, scan the resolved lockfile. Checking the packages someone chose misses the transitive ones nobody did — which is usually where the risk is. Pass the file contents (package-lock.json, requirements.txt, uv.lock, go.sum, Cargo.lock, a CycloneDX SBOM, …). Returns agent_action: REFUSE means do not merge.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| path | No | Local runs only (uvx vdb-mcp): read the file here instead of passing content. | |
| content | No | The file's text. | |
| filename | Yes | e.g. 'package-lock.json' — the format is detected from it |