Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add skills/chadixearth/graphyloop/dependency-auditnpx skills add chadixearth/graphyloop --skill dependency-auditgit clone --depth 1 https://github.com/chadixearth/graphyloopWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/chadixearth/graphyloop/dependency-audit)<a href="https://agentmods.dev/skills/chadixearth/graphyloop/dependency-audit"><img src="https://agentmods.dev/badge/skills/chadixearth/graphyloop/dependency-audit.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00074 | $0.01407 |
| Opus 5 | $0.00037 | $0.00704 |
| Sonnet 5 | $0.00015 | $0.00281 |
| Haiku 4.5 | $0.00007 | $0.00141 |
Grade A, and why
dependency-audit scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 4d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 110 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Dependency audit and supply chain
Two failures, opposite directions: shipping a package nobody vetted (install script, typosquatted name, unmaintained transitive dep), and burning a day on advisories that are unreachable in this app. Both come from not asking is this reachable, and what does it cost to remove.
When to activate
- Before
npm i <new-package>(or pip/go/cargo/composer equivalent). npm audit/ Dependabot / Snyk / GitHub alert, or a CI security job failing.- A PR whose diff includes a lockfile.
- Post-incident: "was this package the way in?"
Adding a dependency — the 60-second vet
- Do you need it? Platform first:
Intl,URL,fetch,crypto.subtle,structuredClone, CSS:has. A 3-line helper beats a transitive tree. - Is the name right? Typosquats live one character away
(
react-domm,lodash.js,crossenv,discord.js-selfbot). Copy the name from the official docs, never from a model's memory or a blog post. - Is it alive? Last publish, open-issue trend, maintainer count, downloads. One maintainer + last release three years ago = you are adopting the code.
- What does it drag in?
npm view <pkg> dependencies/npx howfat <pkg>— count transitives and installed size before, not after. - Does it run code on install?
npm view <pkg> scripts— apostinstallin a utility library is a red flag; install with--ignore-scriptsif you must. - License compatible? MIT/Apache-2.0/BSD fine for most products; AGPL/SSPL and "source-available" licenses are a legal decision, not a dev one.
- Pin it. Exact version in
package.json(no^for anything security- or build-critical), lockfile committed,npm ciin CI — nevernpm installthere.
Triaging an advisory
Run the tool, then think — the count is not the finding.
npm audit --json # or: pnpm audit / yarn npm audit
npm ls <vulnerable-pkg> # WHO pulls it in — the fix lives at that edge
pip-audit # python
govulncheck ./... # go: reports reachable symbols, not just versions
cargo audit # rust
composer audit # php
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 4d ago First seen · 110 lines · 74 tokens per session scan A 6ac0e5ad3ff2
dependency-audit is a skill published in the GitHub repository chadixearth/graphyloop (2 stars, last pushed 18d ago), licensed MIT. It adds 74 tokens to every session and 1,407 once invoked, about $0.0004 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other skills, from other repositories
agent-code-analyzer
Agent skill for code-analyzer - invoke with $agent-code-analyzer.
agui-dotnet-streaming-chat
Get started with the AG-UI .NET SDK: bootstrap and run your first streaming-chat app (client + server) with the AG-UI .NET NuGet packages (AGUI.Client, AGUI.Server, AGUI.Formatting, AGUI.Abstractions). USE FOR: which packages to install and how to wire them; constructing an AGUIChatClient against an endpoint and…
agui-dotnet-sample-step
Add a GettingStarted sample Step (a Server/Client pair) to the AG-UI .NET SDK that demonstrates one protocol feature the way we want users to write it. USE FOR: adding a new samples/GettingStarted/StepNN Server+Client pair, wiring it into AGUI.slnx and the integration-test project, giving it a deterministic…
agui-dotnet-protobuf
Use the protobuf wire transport (instead of the default Server-Sent Events) for an AG-UI connection with the AG-UI .NET SDK — a compact binary event stream negotiated via the Accept header. USE FOR: making an AGUIChatClient prefer protobuf by wiring an AGUIEventStreamHandler with ProtobufEventStreamFormatter (then…
revdiff-plan
Review the last Codex assistant message (plan, analysis, or proposal) with inline annotations in a TUI overlay. Extracts the most recent response from Codex rollout files and opens it in revdiff for review and annotation. Activates on "revdiff-plan", "review plan with revdiff", "annotate plan", "review last response"…
moai-ref-ui-polish
UI polish and interface-completion reference: the small visual details — concentric border radius, optical alignment, shadow-vs-border, motion easing, typography smoothing, tabular numbers, icon stroke weight, hit areas — that separate polished interfaces from generic ones. Agent-extending skill that amplifies…