add-dep command
Vet a new or changed third-party dependency for license, provenance, and supply-chain risk before any install runs.
/ca:add-dep$ca-add-dep/ca-add-depAvailability is read from each shipped host catalog. Preview-only commands are marked on the page.
What it does
Section titled “What it does”Gates a new or changed third-party dependency through review before anything installs. Naming the
package here — with a version if you have one, or without one to have the reviewer evaluate the
latest available — hands the decision to the dependency-reviewer agent, which reads
.codearbiter/security-controls.md for the allowed/denied license list and supply-chain policy,
and .codearbiter/tech-stack.md for stack fit and the project’s dependency manager.
Once the agent clears the package, the install command is surfaced for confirmation rather than run silently, and the resulting lock-file update ships in the same commit as the manifest edit, so the two never drift apart.
This gate is orchestrator-enforced, not hook-enforced: there’s no pre-bash rule blocking a bare install command run outside this channel the way the crypto/secret gate blocks a raw shell command. The discipline depends on actually routing installs through here.
/ca:add-dep <package[@version]>Version is optional; omitting it evaluates the latest available release.
Example
Section titled “Example”> /ca:add-dep left-pad@1.3.0
dependency-reviewer: left-pad@1.3.0 license: MIT (allowed) provenance: npm registry, 6M+ weekly downloads, maintained supply-chain: no known advisories
Cleared. Install command ready: npm install left-pad@1.3.0Run it? (lock-file change will be committed alongside package.json)When to reach for it
Section titled “When to reach for it”Removing a dependency, or a code change that happens to bump one, goes through /ca:fix or
/ca:feature instead (the manifest change is reviewed at /ca:pr); asking about a package
without installing it is /ca:btw’s job.
| Gate | When | Effect |
|---|---|---|
| dependency review | before any install runs | the dependency-reviewer agent must clear the package first — a denied license or unresolved supply-chain concern blocks the install |
Related
Section titled “Related”Source
Section titled “Source”Source — plugins/ca/commands/add-dep.md (v2.11.0)
---description: Vet a new or changed third-party dependency for license, provenance, and supply-chain risk before any install runs.argument-hint: "<package[@version]>"---
# /ca:add-dep — dependency review
Gate a new or changed third-party dependency through review before it lands. When you route throughthis command, the orchestrator runs no install until the `dependency-reviewer` agent clears thepackage. Specify the exact version if you have one; without one, the reviewer evaluates the latestavailable version.
## Routes to
The `dependency-reviewer` agent (`${CLAUDE_PLUGIN_ROOT}/agents/dependency-reviewer.md`). The agentreads `${CLAUDE_PROJECT_DIR}/.codearbiter/security-controls.md` (allowed/denied licenses, provenanceand supply-chain policy) and `${CLAUDE_PROJECT_DIR}/.codearbiter/tech-stack.md` (stack fit, dependencymanager) to judge the package.
After the agent clears it, the orchestrator surfaces the install command for confirmation. The lockfile change is committed alongside the manifest change — never one without the other.
## When NOT to use
- Removing a dependency → `/ca:fix` or `/ca:feature` with the change described.- Updating an existing dependency as part of a code change → `/ca:feature` / `/ca:fix`; manifest changes route to review at `/ca:pr`.- Asking about a package without installing it → `/ca:btw`.
## Ephemeral tool run — one invocation, nothing adopted
A one-time developer tool is not a dependency, and reviewing it as one is whatissue #346 records going wrong: a duplicate-code investigation was interruptedand pushed toward project-dependency review for `jscpd`, which the operator hadexplicitly said must never be listed as a dependency. The redirect loop thenreached for `/ca:override`, a bypass invented to cover missing coverage. Thissection is that coverage.
**The distinction is the dependency GRAPH, not the download.** Adopting orchanging anything that enters `package.json`, a lockfile, or a base image is thereview above, unchanged. Running a pinned tool once, against the repository,adopting nothing, is this.
Route here when ALL of these hold. If any is unclear, it is a dependency andtakes the full review:
1. The operator asked for this specific tool, by name, in this session.2. It runs ONCE, for inspection or analysis. It is not wired into a script, a hook, or CI.3. Nothing it does may change a manifest, a lockfile, or a committed artifact.
Then:
- **Pin the exact version.** `npx jscpd@4.0.5 .`, never bare `npx jscpd` — an unpinned invocation resolves to whatever was published this morning, which is the supply-chain exposure the review exists for and the one part of it that still applies at full strength.- **Use the approved registry.** `https://registry.npmjs.org` is the only one (`security-controls.md`); no `git+`, no `file:`, no non-TLS source.- **Confirm before running**, naming the exact command. One approval, not a review — the operator has already made the adoption decision, which is "no".- **Isolate what you can.** Prefer a cache directory under the system temp dir over the project tree, and write any report there too, so the run leaves no residue a later commit could pick up.- **Report what ran** — the pinned command and where its output went.
**Hard gate: MUST NOT modify a manifest or a lockfile.** If the tool writes one,that is adoption, and it stops here and routes to the review above. Verifyrather than trust: `git status --porcelain` over the manifest and lockfile pathsmust be unchanged after the run. A tool that requires adoption to run at all isa dependency, and saying so is the correct answer.
This is a bounded carve-out inside this command, not a command of its own(ADR-0023). A new command would add a public surface — the catalog, the Picommand catalog, the README counts, the site sidebar — to govern an action whosewhole definition is that it changes nothing.
## Hard gate
MUST NOT install before `dependency-reviewer` clears the package. BLOCK on a denied license or anyunresolved supply-chain or provenance concern.
This gate is **orchestrator-enforced, not hook-enforced**: unlike the crypto/secret gate(`pre-bash.py` H-09b/H-10b), there is no pre-bash rule that blocks a bare `npm`/`pip`/`yarn`/`pnpminstall` typed outside this command. The discipline depends on routing installs through `/ca:add-dep`.A hook-level install block (parallel to the security-gate marker) would be a stronger posture, but is adeliberate behavior change — a possible future enhancement, not the current contract.