Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add ncaq/konoka --skill dependency-reviewergit clone --depth 1 https://github.com/ncaq/konokaWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/ncaq/konoka/dependency-reviewer)<a href="https://agentmods.dev/skills/ncaq/konoka/dependency-reviewer"><img src="https://agentmods.dev/badge/skills/ncaq/konoka/dependency-reviewer/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/ncaq/konoka/dependency-reviewer"><img src="https://agentmods.dev/badge/skills/ncaq/konoka/dependency-reviewer.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00024 | $0.01102 |
| Opus 5 | $0.00012 | $0.00551 |
| Sonnet 5 | $0.00005 | $0.00220 |
| Haiku 4.5 | $0.00002 | $0.00110 |
Grade A, and why
dependency-reviewer scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 9d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
What it actually says
差分に含まれる依存関係の変更を調査し、 その内容とプロジェクトへの影響を評価してください。
まず差分に依存関係の変更が含まれているか確認してください。 含まれていない場合は、 依存関係の変更なしと報告して即座に終了してください。 以降の調査は不要です。
/researchスキルが利用可能な場合は、
複数ソースの横断調査に活用してください。
利用できない場合は直接Web検索やMCPで調査してください。
レビュー対象
以下はkyoseiスキル本体がget-review-infoで取得した、
レビュー対象ファイルへの絶対パスを持つJSONです。
JSONに含まれるファイルをReadツールで直接読んでレビューしてください。
特にpatchはレビュー対象の差分です。
$ARGUMENTS
レビューするときの注意
レビューする際は、 以下の観点で評価してください:
依存関係の変更の特定
- ロックファイルやマニフェストファイルの変更から、 どの依存関係が追加、削除、更新されたかを特定する
- 新規追加された依存関係を特定する
- 削除された依存関係を特定する
- 更新された依存関係については、メジャー、マイナー、パッチのどの種類の更新かを分類する
変更内容の調査
- リリースノートやChangeLogを調査して変更内容を把握する
- 破壊的変更(breaking changes)の有無を確認する
- セキュリティ修正が含まれているかを確認する
- 非推奨APIの追加や削除を確認する
- コミュニティの反応(GitHub Issueでの不具合報告、リグレッションの指摘など)を確認する
プロジェクトへの影響の評価
- 変更された依存関係がプロジェクトのコードベースでどのように使われているかを確認する
- 破壊的変更がプロジェクトに影響するかを評価する
- 非推奨になったAPIをプロジェクトが使用していないか確認する
- 間接的な依存関係への影響を評価する
レポート形式
発見事項をJSON配列で報告してください。
JSON以外のテキストは出力しないでください。
Markdownのコードブロック記法も付けないでください。
以下のような形式で出力してください。
[
{
"path": "src/example.ts",
"line": 42,
"body": "問題の説明と具体的な改善案",
"tags": ["dependency"],
"level": "WARNING"
}
]
各要素のフィールド:
path: ファイルの相対パスline: 該当行番号body: 問題の説明と推奨される改善案をまとめた文章tags:["dependency"]level: 以下のいずれか"CAUTION""WARNING""IMPORTANT""TIP""NOTE"
複数行にまたがる指摘の場合はstartLine(開始行)を追加してください。
差分の削除行に対する指摘の場合は"side": "LEFT"を追加してください。
依存関係の変更があるが問題が見つからない場合は、
変更内容の概要を"NOTE"レベルの要素として報告してください。
依存関係の変更自体がない場合は空配列[]を返してください。
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 9d ago First seen · 126 lines · 24 tokens per session scan A c7e601f1e8ab
dependency-reviewer is a skill published in the GitHub repository ncaq/konoka (3 stars, last pushed 2d ago), licensed Apache-2.0. It adds 24 tokens to every session and 1,102 once invoked, about $0.0001 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other skills, from other repositories
code-review
Code review practices with technical rigor and verification gates. Use for receiving feedback, requesting code-reviewer subagent reviews, or preventing false completion claims in pull requests.
remember
Record why something is the way it is — a decision and its reasoning, a lesson that cost time, or a standing constraint. Use when the reasoning behind a choice would be expensive to reconstruct later.
pr-from-stale-branch-silently-reverts-newer-main-files
Trap: merging a PR whose branch carries an OLD TREE silently DELETES (reverts) files that landed on main after that tree was built — with NO merge conflict to warn you, because a deletion your own commit records is not a conflict. Use when: (1) about to gh pr create or squash-merge from a long-lived / earlier-branched…
parallel-pr-scope-overlap-tiebreaker-delta-check
Before applying a handoff prompt's tiebreaker default ("merge the first-mover", "the clean-against-main one", "the one with reviewer APPROVE") to pick a winner between two parallel PRs that implemented the SAME scope, run gh pr diff on BOTH and audit for substantive deltas. Use when: (1) a session prompt or handoff…
pr-plan-bucket-triage-before-sizing
Before writing detailed pull request plans against a codebase you have not audited, triage it by bucket so sizes rest on findings rather than assumptions.
code-review-subagent-fabricates-specifics-to-inflate-severity
When a code-review subagent (voltagent-qa-sec, opus-tier reviewer, code-reviewer, etc.) reports a HIGH or BLOCKING severity finding, verify any SPECIFIC EVIDENCE the reviewer cites (line numbers, call counts, exact function/symbol names, file paths beyond the obvious diff) BEFORE treating the severity as actionable.…