dependency-reviewer

dependency-reviewer is a skill for Claude Code from ncaq/konoka. It costs 24 tokens per session (1,102 once invoked), scanned A, original, Apache-2.0.

A review procedure for changes to project dependencies, meaning external packages the code relies on.

In plain words
What is it for?
Use it when reviewing a pull request that changes dependency manifests or lock files. It produces findings as a JSON array.
Why use it?
It identifies what was added, removed, or updated and checks for breaking changes, security fixes, deprecated interfaces, and project impact.

Skill for Claude Code

Written for Claude Code: allowed-tools in frontmatter. Also seen: agent in frontmatter.

Part of the kyosei plugin — 7 skills, 2 hooks shipped together

Good fit Use it when reviewing a pull request that changes dependency manifests or lock files. It produces findings as a JSON array.

Compare 6 skills from other repositories ↓
Install with agentmods
npx agentmods add skills/ncaq/konoka/dependency-reviewer
View source ↗ ncaq/konoka
Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

Any agent
npx skills add ncaq/konoka --skill dependency-reviewer
Clone the repo
git clone --depth 1 https://github.com/ncaq/konoka

Made for: Claude Code.

Or install kyosei, the plugin that ships this one along with the rest of its 7 skills, 2 hooks.

Wrote this? Show the measurements

A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.

agentmods badge for dependency-reviewer

README.md
[![agentmods](https://agentmods.dev/badge/skills/ncaq/konoka/dependency-reviewer/github.svg)](https://agentmods.dev/skills/ncaq/konoka/dependency-reviewer)
Your own site
<a href="https://agentmods.dev/skills/ncaq/konoka/dependency-reviewer"><img src="https://agentmods.dev/badge/skills/ncaq/konoka/dependency-reviewer/github.svg" alt="Measured on agentmods" height="20"></a>

Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.

agentmods 80×15 button for dependency-reviewer

Your own site · 80×15
<a href="https://agentmods.dev/skills/ncaq/konoka/dependency-reviewer"><img src="https://agentmods.dev/badge/skills/ncaq/konoka/dependency-reviewer.svg" alt="Reviewed on agentmods" width="80" height="20"></a>
Per session 24 Skills are progressive disclosure: only the name and description are preloaded; the body loads when the skill is used.
When invoked 1,102 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. A grade says what 26 rules found in the file — not that it is safe.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5.1 $0.00024 $0.01102
Opus 5 $0.00012 $0.00551
Sonnet 5 $0.00005 $0.00220
Haiku 4.5 $0.00002 $0.00110

Measured 9d ago against content hash c7e601f1e8ab, method: parsed. Prices are Anthropic first-party input rates as of 2026-09-09, from the pricing page.

Security

Grade A, and why

dependency-reviewer scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 9d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

plugins/kyosei/skills/dependency-reviewer/SKILL.md · 126 lines

What it actually says

差分に含まれる依存関係の変更を調査し、 その内容とプロジェクトへの影響を評価してください。

まず差分に依存関係の変更が含まれているか確認してください。 含まれていない場合は、 依存関係の変更なしと報告して即座に終了してください。 以降の調査は不要です。

/researchスキルが利用可能な場合は、 複数ソースの横断調査に活用してください。 利用できない場合は直接Web検索やMCPで調査してください。

レビュー対象

以下はkyoseiスキル本体がget-review-infoで取得した、 レビュー対象ファイルへの絶対パスを持つJSONです。 JSONに含まれるファイルをReadツールで直接読んでレビューしてください。 特にpatchはレビュー対象の差分です。

$ARGUMENTS

レビューするときの注意

レビューする際は、 以下の観点で評価してください:

依存関係の変更の特定

  • ロックファイルやマニフェストファイルの変更から、 どの依存関係が追加、削除、更新されたかを特定する
  • 新規追加された依存関係を特定する
  • 削除された依存関係を特定する
  • 更新された依存関係については、メジャー、マイナー、パッチのどの種類の更新かを分類する

変更内容の調査

  • リリースノートやChangeLogを調査して変更内容を把握する
  • 破壊的変更(breaking changes)の有無を確認する
  • セキュリティ修正が含まれているかを確認する
  • 非推奨APIの追加や削除を確認する
  • コミュニティの反応(GitHub Issueでの不具合報告、リグレッションの指摘など)を確認する

プロジェクトへの影響の評価

  • 変更された依存関係がプロジェクトのコードベースでどのように使われているかを確認する
  • 破壊的変更がプロジェクトに影響するかを評価する
  • 非推奨になったAPIをプロジェクトが使用していないか確認する
  • 間接的な依存関係への影響を評価する

レポート形式

発見事項をJSON配列で報告してください。

JSON以外のテキストは出力しないでください。

Markdownのコードブロック記法も付けないでください。

以下のような形式で出力してください。

[
  {
    "path": "src/example.ts",
    "line": 42,
    "body": "問題の説明と具体的な改善案",
    "tags": ["dependency"],
    "level": "WARNING"
  }
]

各要素のフィールド:

  • path: ファイルの相対パス
  • line: 該当行番号
  • body: 問題の説明と推奨される改善案をまとめた文章
  • tags: ["dependency"]
  • level: 以下のいずれか
    • "CAUTION"
    • "WARNING"
    • "IMPORTANT"
    • "TIP"
    • "NOTE"

複数行にまたがる指摘の場合はstartLine(開始行)を追加してください。 差分の削除行に対する指摘の場合は"side": "LEFT"を追加してください。

依存関係の変更があるが問題が見つからない場合は、 変更内容の概要を"NOTE"レベルの要素として報告してください。 依存関係の変更自体がない場合は空配列[]を返してください。

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 9d ago First seen · 126 lines · 24 tokens per session scan A c7e601f1e8ab

Subscribe to this mod's changes

dependency-reviewer is a skill published in the GitHub repository ncaq/konoka (3 stars, last pushed 2d ago), licensed Apache-2.0. It adds 24 tokens to every session and 1,102 once invoked, about $0.0001 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.

Related

Other skills, from other repositories

code-review

Code review practices with technical rigor and verification gates. Use for receiving feedback, requesting code-reviewer subagent reviews, or preventing false completion claims in pull requests.

secondsky/claude-skills · 35 tokens

remember

Record why something is the way it is — a decision and its reasoning, a lesson that cost time, or a standing constraint. Use when the reasoning behind a choice would be expensive to reconstruct later.

ArcticFox2029/chamnan · 40 tokens

pr-from-stale-branch-silently-reverts-newer-main-files

Trap: merging a PR whose branch carries an OLD TREE silently DELETES (reverts) files that landed on main after that tree was built — with NO merge conflict to warn you, because a deletion your own commit records is not a conflict. Use when: (1) about to gh pr create or squash-merge from a long-lived / earlier-branched…

wan-huiyan/agent-traffic-control · 387 tokens

parallel-pr-scope-overlap-tiebreaker-delta-check

Before applying a handoff prompt's tiebreaker default ("merge the first-mover", "the clean-against-main one", "the one with reviewer APPROVE") to pick a winner between two parallel PRs that implemented the SAME scope, run gh pr diff on BOTH and audit for substantive deltas. Use when: (1) a session prompt or handoff…

wan-huiyan/agent-traffic-control · 384 tokens

pr-plan-bucket-triage-before-sizing

Before writing detailed pull request plans against a codebase you have not audited, triage it by bucket so sizes rest on findings rather than assumptions.

wan-huiyan/agent-traffic-control · 40 tokens

code-review-subagent-fabricates-specifics-to-inflate-severity

When a code-review subagent (voltagent-qa-sec, opus-tier reviewer, code-reviewer, etc.) reports a HIGH or BLOCKING severity finding, verify any SPECIFIC EVIDENCE the reviewer cites (line numbers, call counts, exact function/symbol names, file paths beyond the obvious diff) BEFORE treating the severity as actionable.…

wan-huiyan/agent-traffic-control · 428 tokens