Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add skills/spaquet/gemtracker/gem-checknpx skills add spaquet/gemtracker --skill gem-checkgit clone --depth 1 https://github.com/spaquet/gemtrackerWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/spaquet/gemtracker/gem-check)<a href="https://agentmods.dev/skills/spaquet/gemtracker/gem-check"><img src="https://agentmods.dev/badge/skills/spaquet/gemtracker/gem-check.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00019 | $0.02179 |
| Opus 5 | $0.00010 | $0.01090 |
| Sonnet 5 | $0.00004 | $0.00436 |
| Haiku 4.5 | $0.00002 | $0.00218 |
Grade A, and why
gem-check scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 4d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 294 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Gem Check Skill
Analyze your Ruby project's dependencies for security vulnerabilities, outdated gems, and maintenance concerns. This skill runs gemtracker to provide structured reports and helps prioritize which gems to update.
How to Use This Skill
When using gem-check, follow these steps:
- Run the analysis - Execute
/gem-checkto scan your project's Gemfile.lock - Review findings - I'll present vulnerabilities, outdated gems, and health concerns with severity levels
- Understand priorities - Vulnerabilities first, then first-level gems, then transitive dependencies
- Ask follow-up questions - For any gem, ask for help understanding changes, testing strategy, or upgrade assistance
- Take action - Request specific updates or a complete upgrade plan based on your priorities
Key principle: You decide what to update and when. I can provide analysis, explain changes, help with conflicts, and suggest strategies—but you control the final decisions.
What This Skill Does
When invoked on a Ruby project with Gemfile.lock, this skill:
- Detects gemtracker - Checks if gemtracker is installed, prompts to install if needed
- Runs analysis - Executes
gemtracker --report jsonto get structured dependency data - Highlights issues:
- 🔴 Security vulnerabilities (CVEs) in any gem
- 🟡 Outdated gems with available updates
- 🟠 Health concerns for first-level dependencies (unmaintained, few maintainers)
- Generates report - Presents findings with severity levels and suggested actions
- Enables decisions - Lets you choose which gems to update and get help with each upgrade
Using This Skill
Quick Start
/gem-check
This will analyze your current project's Gemfile.lock and report findings.
With Specific Project Path
/gem-check /path/to/rails-app
What You'll See
Security Vulnerabilities Report
Shows all CVEs found in your gems:
🔴 SECURITY VULNERABILITIES (2 found)
─────────────────────────────────────
1. rack (2.1.2 → CRITICAL)
CVE-2021-22942: HTTP request smuggling vulnerability
Scope: default (PRODUCTION)
Impact: DIRECT - First-level dependency
→ Upgrade to rack 2.2.4 or 3.0.0+
2. devise (4.8.0 → HIGH)
CVE-2022-0000: Authentication bypass in certain configurations
Scope: default (PRODUCTION)
Impact: TRANSITIVE - Dependency of other gems
What ships with it
8 files beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 4d ago First seen · 294 lines · 19 tokens per session scan A 11df995bf164
gem-check is a skill published in the GitHub repository spaquet/gemtracker (22 stars, last pushed 4d ago), licensed MIT. It adds 19 tokens to every session and 2,179 once invoked, about $0.0001 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other skills, from other repositories
release-notes
Draft concise release notes.
use-modern-go
Use the Modern Go Guidelines CLI whenever writing, modifying, fixing, or refactoring Go code. Apply its version-specific guidance to generated changes.
jwx-guide-v4
Guide for developing Go applications with github.com/lestrrat-go/jwx v4 — parse/sign JWTs, work with JWS/JWE/JWK, pick algorithms, and avoid the common footguns. For developers using jwx, not for developing the library itself.
jwx-companion-bulk
Apply bulk operations across all jwx companion modules. Args.
readme-generate
從原始碼分析自動生成雙語 README。當使用者請求為專案建立 README、需要從程式碼庫生成 README.md(英文)和 README.zh.md(中文)、或希望為其函式庫/套件建立一致的多語言文件時使用。.
extension-upload
Package a script tool under /.config/agenvoy/tools/script/ into a tar.gz and publish to pkg.agenvoy.com registry. Keyword picker, dep/key detection, config-stored email (ask + lowercase + persist), ask version, email verification gate, multipart upload with downgrade/unique guards.