openplan-review

openplan-review is a skill for Codex from BANANASJIM/openplan-skill. It costs 107 tokens per session (760 once invoked), scanned A, original, MIT.

A read-only review method for checking automated agent work, including plans, code changes, documents, and generated project files.

In plain words
What is it for?
Use it to define what is being reviewed, run safe checks, inspect the relevant files or diffs, and produce an independent findings report.
Why use it?
It helps separate inspection from approval or editing, so problems can be reported with evidence before anyone merges or changes the work.

Skill for Codex

Written for Codex: agents/openai.yaml present. Also seen: mentions Claude Code; mentions Codex; $skill-name invocation.

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add skills/bananasjim/openplan-skill/openplan-review
Any agent
npx skills add BANANASJIM/openplan-skill --skill openplan-review
Clone the repo
git clone --depth 1 https://github.com/BANANASJIM/openplan-skill

Made for: Codex.

Wrote this? Show the measurements

A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.

agentmods badge for openplan-review

README.md
[![agentmods](https://agentmods.dev/badge/skills/bananasjim/openplan-skill/openplan-review.svg)](https://agentmods.dev/skills/bananasjim/openplan-skill/openplan-review)
Your own site
<a href="https://agentmods.dev/skills/bananasjim/openplan-skill/openplan-review"><img src="https://agentmods.dev/badge/skills/bananasjim/openplan-skill/openplan-review.svg" alt="Measured on agentmods" height="20"></a>
Per session 107 Skills are progressive disclosure: only the name and description are preloaded; the body loads when the skill is used.
When invoked 760 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5.1 $0.00107 $0.00760
Opus 5 $0.00053 $0.00380
Sonnet 5 $0.00021 $0.00152
Haiku 4.5 $0.00011 $0.00076

Measured 6d ago against content hash ce651fb3d03d, method: parsed. Prices are Anthropic first-party input rates as of 2026-09-06, from the pricing page.

Security

Grade A, and why

openplan-review scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 6d ago.

The scan reads SKILL.md. This mod also ships 1 executable file (scripts/validate_review_report.py), listed below but not scanned — reading those needs a real analyzer, not pattern matching.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

skills/openplan-review/SKILL.md · 57 lines

How it starts

The opening of the file, as written. The whole thing — 57 lines — stays where its author put it; the contents beside it link to each section on GitHub.

OpenPlan Review

Use this after $openplan-core to review automated agent work without becoming another ungoverned agent. The review must be evidence-backed, read-only by default, preserve dual-surface separation when present, and remain independent of any one platform's enforcement implementation.

Core Rule

Do not approve, merge, commit, rewrite, or fix the work under review. Inspect, verify, classify, and report. If the user explicitly asks for fixes after the review, treat that as a separate task.

Review Flow

  1. Define scope from the user request and durable artifacts such as files, diffs, reports, logs, transcripts, or git metadata when available.
  2. Load only context needed for review: request, changed artifacts, declared goal/intent/spec/plan if available, and any local project rules that directly constrain the artifact.
  3. Identify what layer is being reviewed: goal/intent, design/rationale, plan/spec, implementation, review report, or generated skill/plugin surface.
  4. Run safe deterministic checks only when they are available and proportionate. Treat checks as evidence sources, not approval gates.
  5. Apply the invariant checklist in references/invariants.md.
  6. Produce findings using references/output-contract.md.
  7. Optionally validate the report shape:
python3 scripts/validate_review_report.py <report.md>

YOLO/Auto Rules

  • Prefer fail-closed reporting over guessing.
  • Ask no broad clarification questions during unattended review; instead record BLOCKED with the exact missing artifact.
  • Never use destructive commands (git reset --hard, branch checkout, deleting working directories, cleanup of untracked files).
  • Do not rely on chat memory for state. Re-read durable artifacts where available.
  • Do not treat passing tests as approval. Tests are evidence, not a decision.
  • Do not treat reviewer non-blocking findings as automatic fix permission.
  • Do not create human decisions. List them under Non-Decisions.

Severity Model

Read the full file on GitHub · 57 lines

Files

What ships with it

6 files beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 6d ago First seen · 57 lines · 107 tokens per session scan A ce651fb3d03d

Subscribe to this mod's changes

openplan-review is a skill published in the GitHub repository BANANASJIM/openplan-skill (4 stars, last pushed 3mo ago), licensed MIT. It adds 107 tokens to every session and 760 once invoked, about $0.0005 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.