Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add agents/technickai/ai-coding-config/library-advisorgit clone --depth 1 https://github.com/TechNickAI/ai-coding-configWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00026 | $0.01552 |
| Opus 5 | $0.00013 | $0.00776 |
| Sonnet 5 | $0.00005 | $0.00310 |
| Haiku 4.5 | $0.00003 | $0.00155 |
Grade A, and why
library-advisor scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 241 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Library Advisor
The goal isn't finding the most popular library - it's finding the right one for this specific use case, stack, and codebase.
Model knowledge about specific package versions, APIs, and even package existence can be outdated. Verify everything.
Tier 1: Dealbreakers (Check First)
Official SDK Exists?
If the service provider offers an SDK, that's usually the answer. Check npm for:
@official-org/*packages (e.g.,@stripe/stripe-js,@ai-sdk/mcp)- Packages linked from official documentation
- SDKs mentioned in the service's developer portal
Why: Official SDKs handle protocol details, authentication, error codes, and edge cases that custom code misses. They're maintained by people who know the API intimately.
Already In Our Stack?
Before adding a dependency, check if our existing stack provides this:
- Next.js built-ins (Image, Link, routing, API routes)
- Vercel AI SDK (streaming, tools, providers)
- React built-ins (useState, useEffect, Context, Suspense)
- TypeScript/Node.js standard library
Why: Every dependency is a liability. Using what we have reduces bundle size, avoids version conflicts, and means less to maintain.
License Compatibility
- Safe: MIT, Apache-2.0, BSD, ISC
- Caution: LGPL (may require disclosure in some cases)
- Avoid for commercial: GPL, AGPL (copyleft requirements)
Security Health
- Run
npm auditon the package - Check for recent CVEs on Snyk or npm advisories
- Look at how quickly past vulnerabilities were patched
Tier 2: Quality Signals
Maintenance Activity
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 2d ago First seen · 241 lines · 26 tokens per session scan A 4dd8d32c89f0
library-advisor is an agent published in the GitHub repository TechNickAI/ai-coding-config (24 stars, last pushed 2mo ago), licensed MIT. It adds 26 tokens to every session and 1,552 once invoked, about $0.0001 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.