I believe what's being suggested is that `cargo audit` should be a part of cargo rather than an add on.
You'd obviously already have cargo installed, which means you should be able to run a command against cargo to see if you are currently exposed to any security problems. Even if it's not the current "audit" add on.