Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add skills/aaronjmars/aeon-agent/code-reviewernpx skills add aaronjmars/aeon-agent --skill code-reviewergit clone --depth 1 https://github.com/aaronjmars/aeon-agentWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/aaronjmars/aeon-agent/code-reviewer)<a href="https://agentmods.dev/skills/aaronjmars/aeon-agent/code-reviewer"><img src="https://agentmods.dev/badge/skills/aaronjmars/aeon-agent/code-reviewer.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00000 | $0.01058 |
| Opus 5 | $0.00000 | $0.00529 |
| Sonnet 5 | $0.00000 | $0.00212 |
| Haiku 4.5 | $0.00000 | $0.00106 |
Grade A, and why
[REPLACE: SKILL_NAME] scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 4d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
This is a copy
100% identical to [REPLACE: SKILL_NAME] — 0 lines differ, which has more behind it and is treated as the original. This page carries a canonical link to it rather than competing with it.
How it starts
The opening of the file, as written. The whole thing — 80 lines — stays where its author put it; the contents beside it link to each section on GitHub.
name: [REPLACE: SKILL_NAME] description: First-touch review of newly opened PRs on [REPLACE: WATCHED_REPO] — verdict + welcoming comment + label metadata: category: dev var: "" tags: - dev
${var} — Optional. PR number to review. If empty, scans all newly-opened PRs on
[REPLACE: WATCHED_REPO].
Today is ${today}. Review external PRs on [REPLACE: WATCHED_REPO] with a focus on [REPLACE: REVIEW_FOCUS].
Steps
-
List candidates — every open PR opened in the last 24h that hasn't been reviewed by this skill yet:
if [ -n "${var:-}" ]; then PRS="$var" else PRS=$(gh pr list -R [REPLACE: WATCHED_REPO] --state open --json number,author,createdAt,additions,deletions \ --jq '.[] | select(.author.login != "github-actions[bot]" and .author.login != "aeonframework") | .number') fiTrack previously-reviewed PRs in
memory/topics/[REPLACE: SKILL_NAME]-reviewed.json(a flat array of PR numbers). Skip anything already in there. -
For each PR — fetch metadata + diff:
gh pr view "$PR" -R [REPLACE: WATCHED_REPO] --json title,body,additions,deletions,files,author > .pr-meta.json gh pr diff "$PR" -R [REPLACE: WATCHED_REPO] > .pr-diff.patchSkip if
additions + deletions > [REPLACE: MAX_PR_LINES]— flag it asDEFERRED: too large for first-touch review, leave a note, and move on. -
Apply the rubric — assign one of four verdicts:
Verdict Trigger ACCEPT Touches expected paths, follows repo conventions, focused scope, no obvious bugs in the diff. NEEDS-CHANGES Reasonable intent but specific issues: missing tests, broken format, incorrect assumption, naming. DEFER Out of scope for this skill — needs a human reviewer (large refactor, architectural change). OUT-OF-SCOPE Touches files outside what the repo accepts contributions on (e.g. lock files, generated assets). Focus the rubric on [REPLACE: REVIEW_FOCUS] — that's the lens that matters most for this repo.
-
Post a comment — use a friendly, specific tone. Acknowledge the contributor, name the verdict, give 1-3 concrete bullets:
gh pr comment "$PR" -R [REPLACE: WATCHED_REPO] --body "Thanks for the PR! [verdict text] - [bullet 1] - [bullet 2]" -
Label the PR via
gh pr edit "$PR" -R [REPLACE: WATCHED_REPO] --add-label "<label>"— useaccepted/needs-changes/defer/out-of-scope(create the labels in the target repo first if they don't exist). -
Notify via
./notifyonly onACCEPTorOUT-OF-SCOPE— those are the actionable verdicts for the operator. Silent onNEEDS-CHANGESandDEFER(the comment on the PR is the signal). -
Log — append to
memory/logs/${today}.md:## [REPLACE: SKILL_NAME] - **PRs reviewed**: N (skipped M as previously seen) - **Verdicts**: accept=X, needs-changes=Y, defer=Z, out-of-scope=W - **Status**: REVIEW_OK | REVIEW_QUIET (no new PRs)
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 4d ago First seen · 80 lines · 0 tokens per session scan A 5b9bc341a60c
[REPLACE: SKILL_NAME] is a skill published in the GitHub repository aaronjmars/aeon-agent (11 stars, last pushed 4d ago), licensed MIT. It costs nothing until one of its globs matches a file; then it loads 1,058 tokens. A static security scan graded it A with 0 findings. It is 100% identical to [REPLACE: SKILL_NAME], differing in 0 lines, and is treated as a copy.
Other skills, from other repositories
systematic-debugging
Use when encountering any bug, test failure, or unexpected behavior, before proposing fixes.
brainstorming
You MUST use this before any creative work - creating features, building components, adding functionality, or modifying behavior. Explores user intent, requirements and design before implementation.
auto-perf-optimize
Run agent-driven VS Code performance or memory investigations. Use when asked to launch Code OSS, automate a VS Code scenario, run the Chat memory smoke runner, capture renderer heap snapshots, take workflow screenshots, compare run summaries, or drive a repeatable scenario before heap-snapshot analysis.
chat-perf
Run chat perf benchmarks and memory leak checks against the local dev build or any published VS Code version. Use when investigating chat rendering regressions, validating perf-sensitive changes to chat UI, or checking for memory leaks in the chat response pipeline.
chat-pet-sprite-creation
Use when creating or changing VS Code chat pet sprite art, sprite sheets, state animations, eye treatments, Stable/Insiders variants, or pet transitions under src/vs/workbench/contrib/chat/browser/widget/media/chatPet.
cpu-profile-analysis
Analyze V8/Chrome CPU profiles (.cpuprofile) and DevTools trace files (Trace-.json). Use when: profiling performance, investigating slow functions, comparing code paths, finding bottlenecks, analyzing timeToRequest, understanding call trees from sampling profiler data, analyzing layout/paint/rendering, investigating…