Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add anaxite/agent-skills --skill three-way-reviewgit clone --depth 1 https://github.com/anaxite/agent-skillsWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/anaxite/agent-skills/three-way-review)<a href="https://agentmods.dev/skills/anaxite/agent-skills/three-way-review"><img src="https://agentmods.dev/badge/skills/anaxite/agent-skills/three-way-review/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/anaxite/agent-skills/three-way-review"><img src="https://agentmods.dev/badge/skills/anaxite/agent-skills/three-way-review.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00119 | $0.01237 |
| Opus 5 | $0.00060 | $0.00619 |
| Sonnet 5 | $0.00024 | $0.00247 |
| Haiku 4.5 | $0.00012 | $0.00124 |
Grade A, and why
three-way-review scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 11d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 147 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Three-Way Review
Dispatches three independent subagents to review one or more files from distinct starting perspectives, then synthesizes their findings. Each subagent approaches the content as a reviewer with a different personality: one skeptical and critical, one generous and appreciative, one balanced with no prior lean. The goal is to surface insights that a single perspective would miss.
This skill requires subagents. If the environment does not support subagent dispatch, tell the user and stop. This skill requires textual content. Do not use this skill to review binary files.
Step 0: Confirm environment
Check that subagents can be dispatched. If not, explain the limitation and stop.
Step 1: Understand the files
Load and read each file. For each file:
- Note its type (prose, markdown, code, config, etc.)
- Note its apparent purpose
- Estimate its size
Then assess relationships between files (see "Multi-file handling" below).
Size check — do this before proceeding:
- If total content across all files exceeds 200KB, warn the user explicitly and ask whether they want to proceed. Explain that reviews may be incomplete or sampled.
- If content is under 200KB but there are many files, use a temporary staging area (e.g. a project-approved temp location, or "project memory" in environments that support memory) to avoid passing oversized context to subagents.
Step 2: Multi-file handling
If more than one file is provided:
-
Infer relationships first. Look for: shared imports or links, matching terminology, complementary structure (e.g., a spec and its implementation), overlapping concepts, or naming conventions that group them. Check surrounding files in the same directory if accessible; those may clarify context.
-
If the relationship is clear, proceed. Note the relationship briefly so subagents can factor it in.
-
If the relationship is unclear, ask the user before dispatching subagents:
"Before I start, I want to confirm these files are meant to be reviewed together. Can you describe how they relate?"
What ships with it
2 files beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 11d ago First seen · 147 lines · 119 tokens per session scan A 8b3e2c6fd386
three-way-review is a skill published in the GitHub repository anaxite/agent-skills (2 stars, last pushed 4mo ago), licensed Apache-2.0. It adds 119 tokens to every session and 1,237 once invoked, about $0.0006 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other skills, from other repositories
python-style
Validate Python code against style and architectural conventions.
go-proverbs
Validate Go code changes against Go Proverbs.
review
Review recent changes - run all validators and report status.
star-chamber
Multi-LLM craftsmanship council with live progress and debate mode for code review and design questions.
skill-author
Package and validate an existing skill draft for AutoVault when its frontmatter, resources, capabilities, or admission result need review.
secure-code-review
The sinks and boundaries that belong to no framework: passing input to a shell or an evaluator, letting input choose a filesystem path, validating at a boundary that is not an HTTP request, and handling regulated data (PII, PHI, cardholder data) so it does not spread into paths nobody reviews. Use when generating or…