Borrowing it
Nothing to install: this file belongs to arvindand/maven-tools-mcp. Take a copy, put it at the same path in your own repository, and replace the rules that are about this project with yours.
curl -O https://raw.githubusercontent.com/arvindand/maven-tools-mcp/main/.claude/commands/deps-health.mdgit clone --depth 1 https://github.com/arvindand/maven-tools-mcpWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/commands/arvindand/maven-tools-mcp/deps-health)<a href="https://agentmods.dev/commands/arvindand/maven-tools-mcp/deps-health"><img src="https://agentmods.dev/badge/commands/arvindand/maven-tools-mcp/deps-health/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/commands/arvindand/maven-tools-mcp/deps-health"><img src="https://agentmods.dev/badge/commands/arvindand/maven-tools-mcp/deps-health.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00010 | $0.00328 |
| Opus 5 | $0.00005 | $0.00164 |
| Sonnet 5 | $0.00002 | $0.00066 |
| Haiku 4.5 | $0.00001 | $0.00033 |
Grade A, and why
deps-health scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 3d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
What it actually says
Perform a full dependency health analysis using the maven-tools-mcp MCP server.
Dependencies to analyze: $ARGUMENTS
If no dependencies are specified, extract them from the project's build file (pom.xml or build.gradle).
Analysis Steps:
-
Call
analyze_project_healthwith:includeSecurityScan: true- Check for CVE vulnerabilities via OSV.devincludeLicenseScan: true- Detect license types and compliance issuesstabilityFilter: PREFER_STABLE- Focus on production-ready versions
-
Summarize findings in these sections:
Health Score Overview:
- Per-dependency
healthScorevalues (0-100); label any calculated average as client-derived - Do not interpret the 3.2.2
analysis_datevalue as a date: it currently contains a health label - Dependency age breakdown (fresh/current/aging/stale counts)
Security Findings:
- Total vulnerabilities found
- Critical/High severity issues requiring immediate action
- Dependencies with known CVEs
License Compliance:
- License type distribution (permissive/copyleft/unknown)
- Any licenses requiring legal review
Recommendations:
- Prioritized list of dependencies to upgrade
- Flag dependencies that likely need documentation review before a major upgrade
- If the user wants a concrete upgrade path after the audit, suggest
compare_dependency_versionsas a follow-up step
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 3d ago Changed · +1 lines d6e4de5f4124
- 11d ago First seen · 41 lines · 10 tokens per session scan A 447cfc0468b9
deps-health is a command published in the GitHub repository arvindand/maven-tools-mcp (32 stars, last pushed 4d ago), licensed MIT. It adds 10 tokens to every session and 328 once invoked, about $0.0001 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other commands, from other repositories
statusbar-style
Switch the status-bar style (classic / capsule / hairline).
statusbar
Show current status-bar config and list available styles + themes.
fest-commit
Commit changes with festival traceability metadata.
superpowers-execute
Execute the current GSD phase plan with Superpowers instead of gsd-execute-phase.
release
Generate changelog, bump version, and create git tag.
role-ops
Reliability and operations lens. Blast radius, failure, recovery.