Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add skills/asap-protocol/asap-protocol/code-quality-reviewnpx skills add asap-protocol/asap-protocol --skill code-quality-reviewgit clone --depth 1 https://github.com/asap-protocol/asap-protocolWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00021 | $0.00439 |
| Opus 5 | $0.00010 | $0.00219 |
| Sonnet 5 | $0.00004 | $0.00088 |
| Haiku 4.5 | $0.00002 | $0.00044 |
Grade A, and why
Code Quality Review scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 3d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
What it actually says
Code Quality Review
You are an expert code quality reviewer.
Pre-requisites
Read before reviewing:
- Clean code (required):
.cursor/rules/agent-clean-code.mdc - Product layout:
.cursor/rules/architecture-principles.mdc - Backend:
.cursor/rules/python-best-practices.mdc(when reviewingsrc/asap/ortests/) - Frontend:
.cursor/rules/frontend-best-practices.mdc(when reviewingapps/web/orpackages/ui/) - Tests:
.cursor/rules/testing-standards.mdc(when the diff adds or changes tests) - Security (ingress/auth changes):
.cursor/rules/security-standards.mdc - Git hygiene:
.cursor/rules/git-commits.mdc - Agent index:
.cursor/README.md
Review process
1. Structure and architecture
- Check separation of concerns; code in the right layer per
architecture-principles.mdc. - Identify logic that belongs in services, handlers, or components.
- Flag functions longer than 40 lines (split per
agent-clean-code.mdc).
2. Standards compliance
- Types: Are all public functions and methods typed?
- Docs: Do public APIs have docstrings (intent + example)?
- Tests: Per
agent-clean-code.mdctest policy — regression tests for bugs, tests for new public APIs insrc/asap/.
3. Error handling
- Are exceptions caught specifically (not bare
except)? - Do error messages include the offending value and expected shape?
- Is there structured logging for failures?
Output format
Provide analysis with:
- Severity: Critical / Major / Minor
- Location: File and line
- Recommendation: Code snippet of the fix
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 3d ago First seen · 51 lines · 21 tokens per session scan A 7c4a658a0dd1
Code Quality Review is a skill published in the GitHub repository asap-protocol/asap-protocol (14 stars, last pushed 3d ago), licensed Apache-2.0. It adds 21 tokens to every session and 439 once invoked, about $0.0001 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other skills, from other repositories
inkbox-python
Use when writing Python code that imports from inkbox, uses pip install inkbox, or when adding email, mailbox imports, phone, text/SMS, iMessage, A2A task/message history, contacts, notes, contact rules, vault, tunnels, mailbox storage, mail clients (IMAP/SMTP), or agent identity features using the Inkbox Python SDK.
inkbox-ts
Use when writing TypeScript or JavaScript code that imports from @inkbox/sdk, uses npm install @inkbox/sdk, or when adding email, mailbox imports, phone, text/SMS, iMessage, A2A task/message history, contacts, notes, contact rules, vault, tunnels, mailbox storage, mail clients (IMAP/SMTP), or agent identity features…
inkbox-cli
Use when running or writing shell commands with the Inkbox CLI (inkbox / @inkbox/cli) for identities, email, mailbox imports, phone, text/SMS, iMessage, A2A task/message history, contacts, notes, contact rules, vault, mailbox storage, mail clients (IMAP/SMTP), phone number, webhook, or signup workflows.
inkbox-tunnels
Use when bringing a local server online behind a public Inkbox URL — covers Python, TypeScript, and Rust tunnel runtimes, edge vs passthrough TLS, forwarding, handlers, and local liveness.
inkbox-agent-self-signup
Use when guiding or implementing the Inkbox agent self-signup flow, including verification, resend-verification, signup restrictions, and optional signup fields like agent handles or mailbox local parts.
inkbox-onboarding
Use when setting up an existing Inkbox identity for email, SMS, iMessage, calls, inbound handling, and recurring communications triage with the API, CLI, Python SDK, or TypeScript SDK.