Version-Sentinel GEMINI.md

A Gemini CLI extension that checks package versions before allowing dependency changes. It records a source link and the version checked.

In plain words
What is it for?
It helps approve or block edits to dependency files and package-install commands for npm, Python, Rust, and .NET projects.
Why use it?
It prevents coding agents from using package versions that are outdated or made up from memory. It also makes intentional old-version pins explicit.

Instructions file for Gemini CLI

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add instructions/ksegit/version-sentinel/gemini-md
Clone the repo
git clone --depth 1 https://github.com/KSEGIT/Version-Sentinel

Made for: Gemini CLI.

Per session 506 This file is loaded in full into every session.
When invoked 506 The same file — it is already loaded in full.
Security scan A 1 finding. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.00506 $0.00506
Opus 5 $0.00253 $0.00253
Sonnet 5 $0.00101 $0.00101
Haiku 4.5 $0.00051 $0.00051

Measured yesterday against content hash 1c623ab23ab9, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade A, and why

Version-Sentinel GEMINI.md scanned grade A with 1 finding against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured yesterday.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Makes network callslowCapability

Not a fault in itself. Listed so you know the mod talks to something, and to what.

`bash`, `jq`, `curl`, and `python3` (3.11+, for `tomllib`) on `PATH`.
GEMINI.md · 57 lines

What it actually says

version-sentinel (Gemini CLI extension)

This extension hard-blocks dependency additions, bumps, and downgrades until a fresh, source-cited version check is recorded. It exists to stop the model from shipping a hallucinated or stale package version remembered from training data.

How it works

  1. You try to edit a dependency manifest (write_file / replace on package.json, requirements*.txt, pyproject.toml, Cargo.toml, *.csproj, ...) or run an install command via run_shell_command (npm install, pip install, cargo add, dotnet add package, ...).
  2. A BeforeTool hook fires and exits 2 — the tool call is blocked and the hook's stderr explains why:
    BLOCKED: version-sentinel.
    Package: lodash (npm). Version: 4.17.21.
    No fresh version check on record.
    
  3. To unblock: look up the real latest version on the upstream registry (npmjs.com, pypi.org, crates.io, nuget.org), then record the check:
    /vs-record npm lodash 4.17.21 https://www.npmjs.com/package/lodash
    
    Then retry the original edit or install — the hook finds the fresh entry and lets it through.

Intentional pins

Pinning an old version on purpose is fine — record it with a reason instead of a URL:

/vs-record npm pkg 1.0.0 "intentional: CVE fix deferred pending audit"

Intentional pins unblock the hook and show as intentional-pin (not DRIFT) in audits.

Auditing drift

Run /check-versions to scan manifests within 4 directory levels of the workspace and compare each pinned version against the latest upstream release. Advisory only — never blocks.

Escape hatch

Set VS_DISABLE=1 in the environment to make every version-sentinel hook a no-op (useful for throwaway sessions).

Prerequisites

bash, jq, curl, and python3 (3.11+, for tomllib) on PATH.

Recorded checks live in <workspace>/.version-sentinel/checks.json (auto-gitignored on first write).

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. yesterday First seen · 57 lines · 506 tokens per session scan A 1c623ab23ab9

Subscribe to this mod's changes

Version-Sentinel GEMINI.md is an instructions file published in the GitHub repository KSEGIT/Version-Sentinel (3 stars, last pushed 2d ago), licensed MIT. It adds 506 tokens to every session, about $0.0025 per session on Opus 5. A static security scan graded it A with 1 finding (makes network calls). No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.