Home / athola / claude-night-market · plugins/imbue/skills/dependency-verification/SKILL.md · GitHub

dependency-verification skillA

dependency-verification is agent-read markdown (skill) from athola/claude-night-market: Verifies a package exists before install, defending against hallucination and slopsquatting. Use when adding, recommending, or installing a package..

Indexed from public GitHub and served as immutable, content-addressed versions. Install it pinned to an exact SHA-256 with the mdr CLI, and every file is verified against the hash recorded here before it reaches your agent. The deterministic audit below grades the latest version, and the same file always earns the same grade.

What the file says

> A package name the model produced is a claim, not a fact. The
> registry is the fact. Verify before you install.

# Dependency Verification

## Overview

Code-generating language models recommend packages that do not
exist at a measured rate of 5.2% (commercial models) to 21.7%
(open models) across 576,000 samples (Spracklen et al. 2024,
arXiv 2406.10279). Worse, 58% of hallucinated names recur across
reruns, so an attacker can predict them, register the empty name,
and ship malware. This is "slopsquatting." A proof-of-concept
package (`huggingface-cli`) drew over 30,000 downloads after being
registered against a commonly hallucinated name. Package
hallucination is also inversely correlated with coding-benchmark
score, so a better model does not make this go away.

The defense is cheap: confirm the name exists in its registry
before installing or recommending it. This skill defines that
check and is enforced by the `guard_package_hallucination.py`
PreToolUse hook.

## When To Use

Apply before any of these:

- Running `pip install`, `uv add`, `npm install`, `pnpm add`,
  `yarn add`, `cargo add`, `poetry add`, or `pdm add`.
…

Read the whole file at its exact version.

How to install

Latest version
mdr add athola/claude-night-market/dependency-verification@git:20260713.f98719b
Exact content
mdr add athola/claude-night-market/dependency-verification@sha256:0756f5bb8aa97202

Pin to a label to follow the author's releases, or to a sha256 to freeze the exact bytes forever. Either way the resolved hash is written to mdr.lock, and mdr install reproduces it on any machine.

Badge

mdr badge

[![mdr](https://markdownregistry.com/badge/art_jhgmaaq2bd2ftisz.svg)](https://markdownregistry.com/a/art_jhgmaaq2bd2ftisz)

1 badge views in 30 days

Versions

versioncommittedcommitsizeaudit
git:20260713.f98719b latest2026-07-13 f98719b 5,705 BA view · diff
git:20260602.cd561172026-06-02 cd56117 5,517 BA view · diff
git:20260601.47cc3932026-06-01 47cc393 4,337 BA view

Audit of the latest version

A  17 of 17 checks passed. Deterministic, no model, same answer every run.
  • pass: Frontmatter block present
  • pass: Frontmatter declares a name
  • pass: Frontmatter declares a description
  • pass: Size between 200 bytes and 200 KB (5705 bytes)
  • pass: No zero-width or bidi control characters
  • pass: No instruction hidden inside an HTML comment
  • pass: No link to an exfiltration or paste host
  • pass: No credential-shaped string
  • pass: No instruction to send local credentials anywhere
  • pass: No text hidden with inline styles
  • pass: No prompt-injection phrasing
  • pass: No curl or wget piped into a shell
  • pass: No recursive delete of root, home or parent
  • pass: No instruction to read or print local credentials
  • pass: No base64 blob over 200 characters
  • pass: No link to a raw IP address
  • pass: No script tag

Source

GitHub

athola/claude-night-market · 338 stars · license MIT · pushed 2026-09-22 · branch master

API

GET https://markdownregistry.com/api/v1/artifacts/art_jhgmaaq2bd2ftisz
GET https://markdownregistry.com/api/v1/resolve?ref=athola/claude-night-market/dependency-verification
GET https://markdownregistry.com/api/v1/blob/0756f5bb8aa972027fa74f8cecf1c4d5ec41640639cfa836d79e44fc8914e353

Your agent does the legwork. You hear about the deals worth your word. Hand yours the standing instructions at modelranch.com and it joins the network that reads files like this one.

More from athola/claude-night-market

claude-code-plugin-reference skill
athola/claude-night-market · .claude/skills/claude-code-plugin-reference/SKILL.md · Explain plugin, skill, command, agent, and hook mechanics used here. Use when authoring or debugging plugins. Do not…
git:20260826.94911b9 · audit A · 338 stars
night-market-architecture-contract skill
athola/claude-night-market · .claude/skills/night-market-architecture-contract/SKILL.md · States load-bearing decisions, invariants, and weak points. Use when judging a design change. Do not use for gating…
git:20260826.3466862 · audit A · 338 stars
night-market-build-and-env skill
athola/claude-night-market · .claude/skills/night-market-build-and-env/SKILL.md · Rebuild the dev environment: uv, Python tiers, pins, traps. Use when onboarding or toolchain breaks. Do not use for…
git:20260903.255430d · audit A · 338 stars
night-market-change-control skill
athola/claude-night-market · .claude/skills/night-market-change-control/SKILL.md · Classify, gate, and review changes. Use when landing a PR, releasing, or amending rules. Do not use for failure triage…
git:20260703.19ab4d6 · audit A · 338 stars
night-market-collective-memory skill
athola/claude-night-market · .claude/skills/night-market-collective-memory/SKILL.md · Search and record project memory (Discussions, journal, ADRs). Use before re-investigating anything. Do not use for…
git:20260703.19ab4d6 · audit A · 338 stars
night-market-completion-integrity-campaign skill
athola/claude-night-market · .claude/skills/night-market-completion-integrity-campaign/SKILL.md · Bind loop 'done' to unfakeable gates. Use to harden egregore/herald loops or promote completion_integrity. Not for QA…
git:20260727.85e2370 · audit A · 338 stars
night-market-config-catalog skill
athola/claude-night-market · .claude/skills/night-market-config-catalog/SKILL.md · Catalog every config axis, its defaults and guards. Use when adding or auditing configuration. Do not use for running…
git:20260823.20abea8 · audit A · 338 stars
night-market-debugging-playbook skill
athola/claude-night-market · .claude/skills/night-market-debugging-playbook/SKILL.md · Triage night-market failures by symptom (hooks, CI, tests). Use when a check fails unexpectedly. Do not use for routine…
git:20260703.19ab4d6 · audit A · 338 stars
night-market-diagnostics-toolkit skill
athola/claude-night-market · .claude/skills/night-market-diagnostics-toolkit/SKILL.md · Run and interpret repo diagnostic scripts (ratchets, validators, token stats). Use when measuring health. Do not use to…
git:20260703.19ab4d6 · audit A · 338 stars
night-market-docs-and-writing skill
athola/claude-night-market · .claude/skills/night-market-docs-and-writing/SKILL.md · Maintain docs of record, ADRs, changelog, and house style. Use when writing repo docs. Do not use for release steps…
git:20260902.b3bb3ff · audit A · 338 stars
night-market-failure-archaeology skill
athola/claude-night-market · .claude/skills/night-market-failure-archaeology/SKILL.md · Chronicles settled battles, reverts, and dead ends. Use when a fix echoes a past failure. Do not use for live triage…
git:20260703.19ab4d6 · audit A · 338 stars
night-market-model-and-harness-updates skill
athola/claude-night-market · .claude/skills/night-market-model-and-harness-updates/SKILL.md · Sweep plugins, skills, agents, commands, and hooks after a model release or Claude Code version bump. Use when upstream…
git:20260814.0f2ecb7 · audit A · 338 stars

Every file in athola/claude-night-market

Browse by kind, by grade A, or by owner.