Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add avsm/ocaml-claude-marketplace --skill review-ocamlgit clone --depth 1 https://github.com/avsm/ocaml-claude-marketplaceWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/avsm/ocaml-claude-marketplace/review-ocaml)<a href="https://agentmods.dev/skills/avsm/ocaml-claude-marketplace/review-ocaml"><img src="https://agentmods.dev/badge/skills/avsm/ocaml-claude-marketplace/review-ocaml/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/avsm/ocaml-claude-marketplace/review-ocaml"><img src="https://agentmods.dev/badge/skills/avsm/ocaml-claude-marketplace/review-ocaml.svg" alt="Reviewed on agentmods" width="80" height="20"></a>- NVIDIA SkillSpector pass
What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00084 | $0.01678 |
| Opus 5 | $0.00042 | $0.00839 |
| Sonnet 5 | $0.00017 | $0.00336 |
| Haiku 4.5 | $0.00008 | $0.00168 |
Grade A, and why
review-ocaml scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 8d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 167 lines — stays where its author put it; the contents beside it link to each section on GitHub.
OCaml Project Review
A review in two phases. The interfaces are judged first, on their own, as a user of the library sees them. Only then are the implementations read, one module at a time, by a dedicated subagent each.
Never merge the phases. Reading an implementation before judging its interface is how a bad interface gets rationalised.
Phase 1: Interfaces
What to read
Read only these files.
dune-project- every
dune - every
.mli - every
.mld *.opamif present
Do not open a .ml in this phase. A module with no .mli is itself a
finding. Note the module, record what dune says about it, and move on.
Build the map
From the dune files alone, record:
- Every library and executable, its
public_name, and itslibraries. - Which modules are
(modules ...)of which stanza, and which are private. - Whether libraries are
wrappedand what the wrapper module re-exports. (flags ...), disabled warnings,preprocessstanzas.- Dependency direction between the project's own libraries, and any cycle pressure or layering violation.
State the map back as a short dependency listing before reviewing anything.
Judge each interface
For every .mli, check the following.
Shape
- Does the module do one thing? A module that would need two synopsis sentences is two modules.
- Is there a central
type t, and is it abstract? Exposed records that carry invariants are a finding. - Are the values ordered sensibly, with constructors first, then accessors, then predicates and comparisons, then converters and printers?
- Are
pp,equalandcomparepresent where the type warrants them? - Are the generic names gone?
Util,Helpers,CommonandMiscare findings.
API quality
- Unlabelled booleans and unlabelled same-typed adjacent arguments.
find_*returningoptionandget_*returning a value directly, or the convention broken.- Error handling. Recoverable failure is a
result. An exception in a public signature must be documented and justified. - Values exported only because a test or a sibling module needs them. These
belong behind a private module or an
_intfsplit. - Leaked internals. Types from a dependency in the signature that the caller should not have to depend on.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 8d ago First seen · 167 lines · 84 tokens per session scan A ad1dd14879c6
review-ocaml is a skill published in the GitHub repository avsm/ocaml-claude-marketplace (35 stars, last pushed 10d ago), licensed ISC. It adds 84 tokens to every session and 1,678 once invoked, about $0.0004 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-09-04.
Other skills, from other repositories
cpp-coding-standards
C++ coding standards based on the C++ Core Guidelines (isocpp.github.io). Use when writing, reviewing, or refactoring C++ code to enforce modern, safe, and idiomatic practices.
qt-cpp-review
Invoke when the user asks to review, check, audit, or look over Qt6 C++ code — or suggest before committing. Runs deterministic linting (60+ rules) then six parallel deep- analysis agents covering model contracts, ownership, threading, API correctness, error handling, and performance. Reports only high-confidence…
frama-c-proofreader
Verify and proofread C code with ACSL using this repository's Frama-C MCP workflow, Frama-C WP static proof, EVA alarms, and optional E-ACSL runtime checks. Use when asked to run Frama-C, check ACSL contracts, explain WP goals, inspect EVA alarms, validate C annotations, or state what a C proof does and does not…
ia-c-systems
C patterns for systems code, libraries, and native extensions: module layout, function decomposition, status-enum errors, memory safety, undefined behavior, and performance measurement. Use when writing, reviewing, refactoring, or debugging C, working with malloc lifetimes, buffer overflows, sanitizers, or Valgrind…
code-reviewer
A code-review procedure for Python, JavaScript, and Go programs. It checks security, performance, maintainability, naming, error handling, and testing.
project-setup
Setup and hardening review for cross-platform modern-C++ (C++17) native projects, especially Node.js addons built with node-gyp / node-addon-api. Use when asked to "set up a native addon", "harden a C/C++ build", "review my binding.gyp", "add compiler hardening flags", "wire up AddressSanitizer/UBSan/TSan/clang-tidy"…