Use Trivy vulnerability scanner in offline mode to detect CVEs in npm dependencies and generate structured JSON reports.