Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add kirich1409/krozov-ai-tools --skill dependency-conflictsgit clone --depth 1 https://github.com/kirich1409/krozov-ai-toolsWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/kirich1409/krozov-ai-tools/dependency-conflicts)<a href="https://agentmods.dev/skills/kirich1409/krozov-ai-tools/dependency-conflicts"><img src="https://agentmods.dev/badge/skills/kirich1409/krozov-ai-tools/dependency-conflicts/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/kirich1409/krozov-ai-tools/dependency-conflicts"><img src="https://agentmods.dev/badge/skills/kirich1409/krozov-ai-tools/dependency-conflicts.svg" alt="Reviewed on agentmods" width="80" height="20"></a>- NVIDIA SkillSpector pass
What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00064 | $0.00521 |
| Opus 5 | $0.00032 | $0.00260 |
| Sonnet 5 | $0.00013 | $0.00104 |
| Haiku 4.5 | $0.00006 | $0.00052 |
Grade A, and why
dependency-conflicts scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 9d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
What it actually says
Dependency Conflicts
Detect Maven/Gradle coordinates (groupId:artifactId) that appear at more than one version
across a project's dependency graph, and report which version wins.
Steps
-
Call
detect_dependency_conflictswithprojectPath(default: cwd) and optionalbuildSystem(mavenorgradle) to override auto-detection.- Gradle projects compare versions across Gradle-resolved scan usages
(
resolvedBy: "gradle") — mediation ishighest-wins. - Maven projects fetch a deps.dev transitive graph per versioned direct dependency
and union
groupId:artifactId → {versions seen}— mediation isnearest-wins(BFS depth from each direct root; same-depth ties break to the highest version).
- Gradle projects compare versions across Gradle-resolved scan usages
(
-
Present each conflict: the GA,
versionsseen,resolvedTo(what wins),strategy, andrisk(high/medium/low). Sort by risk descending.
No conflicts found: say so; do not speculate about hidden ones.
Known limitations
For Maven, this unions per-root deps.dev graphs resolved in isolation — it
approximates but is not a full project-wide resolve. Project dependencyManagement,
Gradle ResolutionStrategy / strict versions / enforcedPlatform, exclusions, and
private/unpublished coordinates are not modeled. Surface notes[] / per-root errors[] /
partial from the result when present rather than treating the report as exhaustive.
Fallback (MCP unavailable only)
For Gradle, ./gradlew <module>:dependencies --configuration <name> already prints
conflict resolution (-> x.y.z annotations) — read that output directly instead of
reimplementing mediation by hand. For Maven, mvn dependency:tree -Dverbose shows omitted
conflicting versions. Prefer the real build tool's own resolution over a hand-rolled graph
walk in both cases.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 9d ago First seen · 47 lines · 64 tokens per session scan A c5a20d084faf
dependency-conflicts is a skill published in the GitHub repository kirich1409/krozov-ai-tools (22 stars, last pushed 4d ago), licensed MIT. It adds 64 tokens to every session and 521 once invoked, about $0.0003 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-09-01.
Other skills, from other repositories
dotnet-reverse
A guide for analyzing compiled .NET and C# programs, including managed Windows executables and libraries. Reverse engineering means studying compiled software to understand how it works, and decompiling turns it back into readable approximate source code.
check-bin-obj-clash
Detects MSBuild projects with conflicting OutputPath or IntermediateOutputPath. USE FOR: builds failing with 'Cannot create a file when that file already exists', 'The process cannot access the file because it is being used by another process', intermittent build failures that succeed on retry, or missing/overwritten…
dart-run-static-analysis
Execute dart analyze to identify warnings and errors, and use dart fix --apply to automatically resolve mechanical lint issues. Use during development to ensure code quality and before committing changes.
agents-sdk-dotnet-debugging
Use when troubleshooting an agent built with the Microsoft Agents SDK (Microsoft.Agents.Hosting.AspNetCore and related packages) in C# / .NET. Trigger on any of these symptoms: build or C# compile errors, crashes on startup, 401 or auth errors on incoming requests, the bot not responding to messages, appsettings.json…
hotpath_init
Configure hotpath profiling in a Rust project. Adds the hotpath dependency with feature-gated setup, instruments main with hotpath::main, functions with measure/measureall, and wraps channels, mutexes, rwlocks, streams, futures, reqwest clients, axum routers and byte-level I/O with hotpath macros. Use when the user…
golang-error-handling
Idiomatic Golang error handling — creation, wrapping with %w, errors.Is/As, errors.Join, custom error types, sentinel errors, panic/recover, the single handling rule, structured logging with slog, HTTP request logging middleware, and samber/oops for production errors. Built to make logs usable at scale with log…