* fix: pin npm package versions in MCP integration templates Prevent supply chain attacks by pinning exact versions instead of using unpinned `npx -y @package` which pulls latest on every run. 23 of 25 integrations pinned. sqlite-mcp and aws skipped (packages not found on npm registry). * fix: use stable azure/mcp version instead of beta * feat: add pricing sync script and update model prices from OpenRouter API - scripts/sync-pricing.py fetches real-time pricing from OpenRouter - Updated 64 price fields across 13 provider files - Run periodically or in CI to keep prices current
Scripts
Utility scripts for maintaining the LibreFang registry.
validate.py
Validates all TOML content files across the registry.
python scripts/validate.py
What It Checks
Per content type:
- Providers -- required fields, valid tiers, non-negative costs, no duplicate model IDs
- Agents -- required fields (name, description, module), name matches directory
- Hands -- required fields (id, name, description), valid category, [agent] section, id matches directory
- Integrations -- required fields (id, name), [transport] section, id matches filename
- Skills -- [skill] section with name, [runtime] with valid type
- Plugins -- name matches directory, [hooks] section, hook files exist
Cross-type checks:
- Routing alias collisions between agents and hands (reported as warnings)
- Cross-file duplicate model IDs within the same provider
Requirements
- Python 3.11+ (uses
tomllib) - Or Python 3.8+ with
pip install tomli
Exit Codes
0-- all checks passed1-- one or more validation errors