gem-check

gem-check is a skill for Claude Code, Codex from spaquet/gemtracker. It costs 19 tokens per session (2,179 once invoked), scanned A, original, MIT.

A skill that examines a Ruby project’s Gemfile.lock, the file recording its installed Ruby packages, for security vulnerabilities, old dependencies, and maintenance concerns.

In plain words
What is it for?
Use it to run gemtracker, review findings by severity and dependency level, understand upgrade effects, plan tests, and decide which Ruby gems to update.
Why use it?
It helps reveal which packages may put the project at risk or need attention, including both directly used packages and packages pulled in by other packages.

Skill for Claude CodeCodex

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add skills/spaquet/gemtracker/gem-check
Any agent
npx skills add spaquet/gemtracker --skill gem-check
Clone the repo
git clone --depth 1 https://github.com/spaquet/gemtracker

Made for: Claude Code, Codex.

Wrote this? Show the measurements

A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.

agentmods badge for gem-check

README.md
[![agentmods](https://agentmods.dev/badge/skills/spaquet/gemtracker/gem-check.svg)](https://agentmods.dev/skills/spaquet/gemtracker/gem-check)
Your own site
<a href="https://agentmods.dev/skills/spaquet/gemtracker/gem-check"><img src="https://agentmods.dev/badge/skills/spaquet/gemtracker/gem-check.svg" alt="Measured on agentmods" height="20"></a>
Per session 19 Skills are progressive disclosure: only the name and description are preloaded; the body loads when the skill is used.
When invoked 2,179 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.00019 $0.02179
Opus 5 $0.00010 $0.01090
Sonnet 5 $0.00004 $0.00436
Haiku 4.5 $0.00002 $0.00218

Measured 4d ago against content hash 11df995bf164, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade A, and why

gem-check scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 4d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

.claude/skills/gem-check/SKILL.md · 294 lines

How it starts

The opening of the file, as written. The whole thing — 294 lines — stays where its author put it; the contents beside it link to each section on GitHub.

Gem Check Skill

Analyze your Ruby project's dependencies for security vulnerabilities, outdated gems, and maintenance concerns. This skill runs gemtracker to provide structured reports and helps prioritize which gems to update.

How to Use This Skill

When using gem-check, follow these steps:

  1. Run the analysis - Execute /gem-check to scan your project's Gemfile.lock
  2. Review findings - I'll present vulnerabilities, outdated gems, and health concerns with severity levels
  3. Understand priorities - Vulnerabilities first, then first-level gems, then transitive dependencies
  4. Ask follow-up questions - For any gem, ask for help understanding changes, testing strategy, or upgrade assistance
  5. Take action - Request specific updates or a complete upgrade plan based on your priorities

Key principle: You decide what to update and when. I can provide analysis, explain changes, help with conflicts, and suggest strategies—but you control the final decisions.

What This Skill Does

When invoked on a Ruby project with Gemfile.lock, this skill:

  1. Detects gemtracker - Checks if gemtracker is installed, prompts to install if needed
  2. Runs analysis - Executes gemtracker --report json to get structured dependency data
  3. Highlights issues:
    • 🔴 Security vulnerabilities (CVEs) in any gem
    • 🟡 Outdated gems with available updates
    • 🟠 Health concerns for first-level dependencies (unmaintained, few maintainers)
  4. Generates report - Presents findings with severity levels and suggested actions
  5. Enables decisions - Lets you choose which gems to update and get help with each upgrade

Using This Skill

Quick Start

/gem-check

This will analyze your current project's Gemfile.lock and report findings.

With Specific Project Path

/gem-check /path/to/rails-app

What You'll See

Security Vulnerabilities Report

Shows all CVEs found in your gems:

🔴 SECURITY VULNERABILITIES (2 found)
─────────────────────────────────────

1. rack (2.1.2 → CRITICAL)
   CVE-2021-22942: HTTP request smuggling vulnerability
   Scope: default (PRODUCTION)
   Impact: DIRECT - First-level dependency

   → Upgrade to rack 2.2.4 or 3.0.0+

2. devise (4.8.0 → HIGH)
   CVE-2022-0000: Authentication bypass in certain configurations
   Scope: default (PRODUCTION)
   Impact: TRANSITIVE - Dependency of other gems

Read the full file on GitHub · 294 lines

Files

What ships with it

8 files beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 4d ago First seen · 294 lines · 19 tokens per session scan A 11df995bf164

Subscribe to this mod's changes

gem-check is a skill published in the GitHub repository spaquet/gemtracker (22 stars, last pushed 4d ago), licensed MIT. It adds 19 tokens to every session and 2,179 once invoked, about $0.0001 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.