Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add strikersam/autonomous-ai-agency --skill dependency-auditgit clone --depth 1 https://github.com/strikersam/autonomous-ai-agencyWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/strikersam/autonomous-ai-agency/dependency-audit)<a href="https://agentmods.dev/skills/strikersam/autonomous-ai-agency/dependency-audit"><img src="https://agentmods.dev/badge/skills/strikersam/autonomous-ai-agency/dependency-audit/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/strikersam/autonomous-ai-agency/dependency-audit"><img src="https://agentmods.dev/badge/skills/strikersam/autonomous-ai-agency/dependency-audit.svg" alt="Reviewed on agentmods" width="80" height="20"></a>- NVIDIA SkillSpector pass
What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00032 | $0.00772 |
| Opus 5 | $0.00016 | $0.00386 |
| Sonnet 5 | $0.00006 | $0.00154 |
| Haiku 4.5 | $0.00003 | $0.00077 |
Grade A, and why
dependency-audit scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 11d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 105 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Skill: dependency-audit
When to Use
- Before adding any new package to
requirements.txt - Before upgrading a package to a new major version
- Periodically (quarterly) to audit for known CVEs
Instructions
Step 1 — Evaluate the new dependency
Answer these questions:
- Is it necessary? Can this be done with the stdlib or an already-imported package?
- Is it maintained? Check the GitHub repo — recent commits, open issues, last release.
- Is the license compatible? This project appears MIT/Apache-compatible. Avoid GPL dependencies unless isolated.
- What is the download / adoption level? Low-adoption packages carry higher supply chain risk.
- Does it have known CVEs? Check https://pypi.org/project// and https://osv.dev.
Step 2 — Pin appropriately
This repo uses >= version lower bounds in requirements.txt.
- Use
>=X.Y.Zwith a known-working version. - For security-sensitive packages (auth, crypto), prefer
>=X.Y.Z,<X+1(major-pinned).
Step 3 — Install and verify
source .venv/bin/activate
pip install -r requirements.txt
pytest -x
All existing tests must still pass after the dependency change.
Step 4 — Check for conflicts
pip check
No dependency conflicts should be reported.
Step 5 — Update changelog
Add an entry to docs/changelog.md:
### Changed
- `requirements.txt` — added `<package>>=X.Y.Z` for <reason>.
or
### Changed
- `requirements.txt` — upgraded `<package>` from `>=X.Y` to `>=Z.W` for <reason>.
Step 6 — Update .env.example if needed
If the new package requires configuration (API keys, URLs), add example env vars to .env.example.
Acceptance Checks
- Necessity evaluated — stdlib/existing package could not do the job
- License checked — compatible with project
- No known CVE at time of addition (note if CVE exists and is accepted)
-
requirements.txtupdated with appropriate version bound -
pytest -xpasses after adding package -
pip checkshows no conflicts -
docs/changelog.mdupdated -
.env.exampleupdated if new config required
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 11d ago First seen · 105 lines · 32 tokens per session scan A 30873ec7143c
dependency-audit is a skill published in the GitHub repository strikersam/autonomous-ai-agency (8 stars, last pushed today), licensed MIT. It adds 32 tokens to every session and 772 once invoked, about $0.0002 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other skills, from other repositories
python-package-management
Guide for managing packages in the Agent Framework Python monorepo, including creating new connector packages, versioning, and the lazy-loading pattern. Use this when adding, modifying, or releasing packages.
temporal-python-testing
Test Temporal workflows with pytest, time-skipping, and mocking strategies. Covers unit testing, integration testing, replay testing, and local development setup. Use when implementing Temporal workflow tests or debugging test failures.
python-feature-lifecycle
Guidance for package and feature lifecycle in the Agent Framework Python codebase, including stage meanings, feature-stage decorators, feature enums, and how to move APIs from one stage to the next.
python-code-quality
Code quality checks, linting, formatting, and type checking commands for the Agent Framework Python codebase. Use this when running checks, fixing lint errors, or troubleshooting CI failures.
cuopt-routing-api-python
Vehicle routing (VRP, TSP, PDP) with cuOpt — Python API only. Use when the user is building or solving routing in Python.
mcore-linting-and-formatting
Linting and formatting for Megatron-LM. Covers running autoformat.sh, tools (ruff, black, isort, pylint, mypy), and code style rules.