Borrowing it
Nothing to install: this file belongs to tony1223/better-agent-terminal. Take a copy, put it at the same path in your own repository, and replace the rules that are about this project with yours.
curl -O https://raw.githubusercontent.com/tony1223/better-agent-terminal/main/.claude/skills/check-sdk-updates/SKILL.mdgit clone --depth 1 https://github.com/tony1223/better-agent-terminalWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/tony1223/better-agent-terminal/check-sdk-updates)<a href="https://agentmods.dev/skills/tony1223/better-agent-terminal/check-sdk-updates"><img src="https://agentmods.dev/badge/skills/tony1223/better-agent-terminal/check-sdk-updates/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/tony1223/better-agent-terminal/check-sdk-updates"><img src="https://agentmods.dev/badge/skills/tony1223/better-agent-terminal/check-sdk-updates.svg" alt="Reviewed on agentmods" width="80" height="20"></a>- NVIDIA SkillSpector pass
What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00065 | $0.00917 |
| Opus 5 | $0.00032 | $0.00458 |
| Sonnet 5 | $0.00013 | $0.00183 |
| Haiku 4.5 | $0.00006 | $0.00092 |
Grade A, and why
check-sdk-updates scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 11d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 65 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Check SDK Updates
Compare the versions of @anthropic-ai/claude-code, @anthropic-ai/claude-agent-sdk, and @openai/codex-sdk declared in package.json against the latest published version on npm.
Steps
-
Read the
dependenciesblock ofpackage.jsonand extract the current declared range for each of:@anthropic-ai/claude-code@anthropic-ai/claude-agent-sdk@openai/codex-sdk
-
Run the following command (single Bash call) to fetch latest versions in parallel:
npm view @anthropic-ai/claude-code version & \ npm view @anthropic-ai/claude-agent-sdk version & \ npm view @openai/codex-sdk version & \ waitMap the three lines of output back to the three packages in the order requested.
-
For each package, compare the declared version (strip leading
^/~) with the latest. Report a compact table:Package Current Latest Status @anthropic-ai/claude-code 2.1.119 2.1.120 ⬆ update @anthropic-ai/claude-agent-sdk 0.2.119 0.2.119 ✓ up to date @openai/codex-sdk 0.125.0 0.126.0 ⬆ update -
For each outdated package, analyze the gap between current and latest so the user can decide how to implement the update. For each one:
a. Get the list of versions in between with:
npm view <pkg> versions --jsonFilter to versions strictly greater than current and ≤ latest. Note the count and span (patch / minor / major bumps).
b. Try to fetch release notes / changelog. Try in this order, stop at the first that works:
npm view <pkg> repository.url→ if it points to a GitHub repo, usegh release list -R <owner/repo> --limit 30andgh release view <tag> -R <owner/repo>for the relevant tags.- Look for a
CHANGELOG.mdinsidenode_modules/<pkg>/(already-installed copy reflects the current version, but its history section may still cover newer versions if upstream backfills). - Fall back to:
npm view <pkg>@<latest> --jsonand read thedescription/homepagefields, thenWebFetchthe homepage's changelog/releases page.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 11d ago First seen · 65 lines · 65 tokens per session scan A 90991fc1d58f
check-sdk-updates is a skill published in the GitHub repository tony1223/better-agent-terminal (504 stars, last pushed today), licensed MIT. It adds 65 tokens to every session and 917 once invoked, about $0.0003 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other skills, from other repositories
mle-workflow
Production machine-learning engineering workflow for data contracts, reproducible training, model evaluation, deployment, monitoring, and rollback. Use when building, reviewing, or hardening ML systems beyond one-off notebooks.
autonomous-loops
Patterns and architectures for autonomous Claude Code loops — from simple sequential pipelines to RFC-driven multi-agent DAG systems.
react-patterns
React 18/19 patterns including hooks discipline, server/client component boundaries, Suspense + error boundaries, form actions, data fetching, state management decision trees, and accessibility-first composition. Use when writing or reviewing React components.
article-writing
Write articles, guides, blog posts, tutorials, newsletter issues, and other long-form content in a distinctive voice derived from supplied examples or brand guidance. Use when the user wants polished written content longer than a paragraph, especially when voice consistency, structure, and credibility matter.
security-review
Perform a focused security review of pending git changes to identify high-confidence security vulnerabilities with real exploitation potential. Use this skill when the user asks for a security review, security audit, vulnerability scan, or wants to check pending changes on a branch for security issues before merging.…
huggingface-llm-trainer
Train or fine-tune language models with TRL or Unsloth on Hugging Face Jobs, including SFT, DPO, GRPO, reward models, and GGUF conversion. Use for cloud LLM training; use huggingface-vision-trainer for vision tasks.