Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add commands/varienos/agentic-workflow/task-review.skeletongit clone --depth 1 https://github.com/varienos/agentic-workflowWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00000 | $0.03482 |
| Opus 5 | $0.00000 | $0.01741 |
| Sonnet 5 | $0.00000 | $0.00696 |
| Haiku 4.5 | $0.00000 | $0.00348 |
Grade A, and why
task-review.skeleton scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 270 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Task Review — 3+1 Ajanli Kod Inceleme
Son commit veya belirtilen diff'i 3 paralel ajanla inceler. Guvenlik/auth/odeme/API/migration degisikliklerinde opsiyonel 4. ajan (devils-advocate) eklenir. Kullanim:
/task-review,/task-review <commit_hash>,/task-review HEAD~3..HEAD
Step 1 — Diff Cikar
1.1 — Arguman Cozumleme
| Girdi | Davranis |
|---|---|
| Bos | Son commit: cd ../Codebase && git diff HEAD~1..HEAD |
| Commit hash | Belirtilen commit: cd ../Codebase && git show <hash> |
| Range | Aralik: cd ../Codebase && git diff <range> |
1.2 — Diff Analizi
Diff'ten asagidaki bilgileri cikar:
- Degisen dosya listesi
- Her dosyadaki eklenen/silinen satirlar
- Degisikliklerin turu (yeni dosya, degisiklik, silme)
KURAL: Diff bossa veya sadece whitespace degisikligi varsa, "Incelenecek degisiklik yok" deyip DUR.
Step 2 — 3 Ajan Spawn Et
Asagidaki 3 ajanin HER BIRINI paralel olarak calistir. Her ajan diff'in tamami uzerinde calisir.
Ajan 1 — Kod Inceleyici (Code Reviewer)
Gorev: Kod kalitesi, yapi, best practice kontrolu.
Kontrol Listesi (Sabit Cekirdek):
- Mantik hatasi: Yanlis kosul, eksik null check, off-by-one, yanlis operator
- Hata yonetimi: Try-catch eksikligi, hata yutma, generic catch, hata mesajlarinin bilgi icermemesi
- Isimlendirme: Degisken/fonksiyon isimleri anlamsiz, tutarsiz, yaniltici
- Tekrar (Duplication): Ayni kod birden fazla yerde, cikarilabilecek ortak fonksiyon
- Performans: Gereksiz dongu, N+1 query, eksik index kullanimi, gereksiz re-render
- Guvenlik: SQL injection, XSS, CSRF, yetkisiz erisim, hassas veri loglama
- Tip guvenligi:
anykullanimi, eksik tip, yanlis tip assertion - Edge case: Bos dizi, null/undefined, sinir degerleri, race condition
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 2d ago First seen · 270 lines · 0 tokens per session scan A a37f3c81b594
task-review.skeleton is a command published in the GitHub repository varienos/agentic-workflow (58 stars, last pushed 2mo ago), licensed MIT. It costs nothing until one of its globs matches a file; then it loads 3,482 tokens. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other commands, from other repositories
design-to-code
Mockup-to-component pipeline using Google Stitch, 21st.dev, and Storybook MCP. Accepts a screenshot, a description, or a URL and produces production-ready React components, checking existing Storybook components before generating anything new. Use when implementing UI from a mockup or screenshot. To call the MCP tool…
memory
Search, store, and manage AI Team Memory — agent expertise, decisions, learnings, and code patterns. File-based by default, with an optional memory MCP overlay.
triage-issues
Launch the Issue Triage Agent (Haiku) to categorize and prioritize GitHub issues.
do-it-retrospective
开关本项目的本地行为反馈记录,或输出已记录问题的去敏复盘报告。参数为 on / off / status / report。.
fix-issue
!gh issue view $ARGUMENTS 2>/dev/null || echo "Could not fetch issue $ARGUMENTS".
verify
Verify factual claims in content using deep research methodology - fact-checks key assertions and updates NCI scores.