Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add skills/ambient-code/platform/amber-reviewnpx skills add ambient-code/platform --skill amber-reviewgit clone --depth 1 https://github.com/ambient-code/platformWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00065 | $0.01347 |
| Opus 5 | $0.00032 | $0.00674 |
| Sonnet 5 | $0.00013 | $0.00269 |
| Haiku 4.5 | $0.00006 | $0.00135 |
Grade A, and why
amber-review scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 139 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Amber Review
Stringent, standards-driven code review against this repository's documented patterns, security requirements, and architectural conventions.
User Input
$ARGUMENTS
Consider the user input before proceeding (if not empty). The input may specify files, a PR number, a branch, or a focus area.
Execution Steps
1. Load Review Context
Read all of the following files to build your review context. Do not skip any.
CLAUDE.md(master project instructions)specs/standards/backend/conventions.spec.md(Go backend, Gin, K8s integration)specs/standards/frontend/conventions.spec.md(NextJS, Shadcn UI, React Query)specs/standards/security/security.spec.md(auth, RBAC, token handling, container security)specs/standards/backend/k8s-client.spec.md(user token vs service account)specs/standards/backend/error-handling.spec.md(consistent error patterns)specs/standards/frontend/react-query.spec.md(data fetching patterns)specs/standards/control-plane/conventions.spec.md(K8s operator, reconciliation, OwnerReferences)
2. Identify Changes to Review
Determine the scope based on user input:
- If a PR number is provided: Use
gh pr diff <number>to get the diff - If files/paths are provided: Review those specific files
- If a branch is provided: Diff against
main - If no input: Review all uncommitted changes (
git diff+git diff --cached)
3. Perform Review
Evaluate every changed file against the loaded standards. Apply ALL relevant checks.
Review Axes
- Code Quality — Does it follow CLAUDE.md patterns? Naming conventions?
- Security — User token auth (
GetK8sClientsForRequest), RBAC checks, token redaction, input validation, SecurityContext on Job pods, no secrets in code - Performance — Unnecessary re-renders, missing query key parameters, N+1 queries, unbounded list operations
- Testing — Adequate coverage for new functionality? Tests follow existing patterns?
- Architecture — Follows project structure? Correct layer separation?
- Error Handling — No
panic(), no silent failures, wrapped errors with context, generic user messages with detailed server logs
What ships with it
1 file beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 2d ago First seen · 139 lines · 65 tokens per session scan A 8bb0642a1ff3
amber-review is a skill published in the GitHub repository ambient-code/platform (129 stars, last pushed 2d ago), licensed MIT. It adds 65 tokens to every session and 1,347 once invoked, about $0.0003 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other skills, from other repositories
argent-tv-interact
Control and inspect TV apps via argent — Apple TV (tvOS), Android TV (leanback), and Amazon Fire TV (Vega). Boot the target, read focus, navigate with the D-pad remote, type, screenshot, and on Vega debug the JS runtime (evaluate, console logs, network inspector). Use when a task targets a TV (runtimeKind "tv", or…
review-offered-task
Review a task that has been offered to you and decide whether to accept or reject it.
company-hiring-intelligence
Reverse-engineer what a company is building by scraping their job postings, careers page, LinkedIn Jobs, and engineering blog using TinyFish web agents. Use whenever a user wants to understand a company's strategic direction from hiring signals, do competitive intelligence, figure out a tech stack from job…
aidd-dev:08:for-sure
Iterative agent loop that tracks attempts and retries until a success condition is met. Use when the user says "for sure", "make sure", "keep trying until", "loop until done", "don't stop until", or needs guaranteed completion of a task with explicit success criteria.
Swift Performance Optimization Skill
Use when investigating measured Swift or Apple-platform regressions in CPU, memory, launch, scrolling, animation hitches, image processing, energy, networking, or concurrency, or when designing performance tests and Instruments experiments. Do not use for speculative micro-optimization, ordinary refactoring, or a…
app-screenshot-debug
Drive the running termio app via AppleScript / System Events to reach a UI state (focus the window, click a sidebar project, a terminal pane, a control), capture a pixel-accurate screenshot of just that window, and read it back for visual analysis — for diagnosing layout / spacing / alignment / 'this looks ugly'…