Borrowing it
Nothing to install: this file belongs to band-app/band. Take a copy, put it at the same path in your own repository, and replace the rules that are about this project with yours.
curl -O https://raw.githubusercontent.com/band-app/band/main/.claude/skills/review-and-apply/SKILL.mdgit clone --depth 1 https://github.com/band-app/bandWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/band-app/band/review-and-apply)<a href="https://agentmods.dev/skills/band-app/band/review-and-apply"><img src="https://agentmods.dev/badge/skills/band-app/band/review-and-apply/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/band-app/band/review-and-apply"><img src="https://agentmods.dev/badge/skills/band-app/band/review-and-apply.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00127 | $0.01454 |
| Opus 5 | $0.00063 | $0.00727 |
| Sonnet 5 | $0.00025 | $0.00291 |
| Haiku 4.5 | $0.00013 | $0.00145 |
Grade A, and why
review-and-apply scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 11d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 129 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Review and Apply — Review → Fix → Verify
Two-phase flow:
- Review — invoke the
review-changesskill. It already knows how to gather context, dispatch the four specialist reviewers in parallel, and return sectioned findings plus a singleVerdict:line. You just tell it what to review. - Fix — read the findings, apply each one's
Fix:with Edit/Write, verify with lint/clippy/tests. Don't re-review; trust the specialists unless a finding is clearly wrong.
Step 1 — Identify the change set
Gather the facts the reviewer needs. Don't make it re-derive them.
# Refresh remote refs so the base comparison isn't stale.
git fetch origin --quiet
# Base ref (merge target). Default origin/main; fall back if HEAD ref points elsewhere.
BASE=$(git symbolic-ref --quiet refs/remotes/origin/HEAD 2>/dev/null | sed 's|^refs/remotes/||' || echo origin/main)
HEAD=$(git rev-parse --short HEAD)
# Open PR? (If yes, the reviewer will prefer `gh pr diff/view`.)
gh pr view --json number,headRefName,baseRefName 2>/dev/null || echo "no PR yet"
# Linked issues: PR body, commit messages, branch name.
{
gh pr view --json body --jq .body 2>/dev/null
git log "$BASE..HEAD" --format='%s%n%b'
git rev-parse --abbrev-ref HEAD
} | grep -iEoh '(closes|fixes|resolves) +#[0-9]+|#[0-9]+' | sort -u
If you find no linked issue, pass issues=none detected. The reviewer still runs against the diff; linked-issue context is just additional input for the specialists when present.
Step 2 — Invoke review-changes
Use the Skill tool to invoke the review-changes skill. The skill is self-contained — it loads its specialists, fetches the diff/issue context itself, and produces the sectioned report.
Skill(skill="review-changes", args="
Review this change set.
- Base: <BASE ref>
- Head: <HEAD short sha>
- PR: <number, or 'no PR yet'>
- Issues: <comma-separated list of #N, or 'none detected'>
")
The skill returns a sectioned report with four fixed-order domain headers (Coding → Testing → Security → Performance), each with a status emoji, followed by a single overall Verdict line:
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 11d ago First seen · 129 lines · 127 tokens per session scan A 9a56cdf7d08a
review-and-apply is a skill published in the GitHub repository band-app/band (5 stars, last pushed yesterday), licensed MIT. It adds 127 tokens to every session and 1,454 once invoked, about $0.0006 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other skills, from other repositories
adversarial-reviewer
Adversarial code review that assumes bugs exist and hunts for them. Use when asked to review code, find bugs, audit for correctness, stress-test a PR, or when someone says "tear this apart" or "what's wrong with this". Give no benefit of the doubt — every line is guilty until proven innocent.
adk-go-self-review
Review an ADK Go change the way a maintainer will — a fresh-context pass over the whole diff, five lenses (correctness and tests, scope, simplicity, style, adk-python parity), and the mutation check that proves your tests pin the change. Use before opening a PR, before any later push that changes code, and when asked…
go-testing
Trigger: Go tests, go test coverage, Bubbletea teatest, golden files. Apply focused Go testing patterns.
semgrep-rule-variant-creator
Creates language variants of existing Semgrep rules. Use when porting a Semgrep rule to specified target languages. Takes an existing rule and target languages as input, produces independent rule+test directories for each language.
brooks-sweep
Full-sweep mode: runs a unified analysis across all quality dimensions — code decay, architecture, tech debt, and test quality — then applies fixes directly to the codebase. Safe changes are auto-applied; risky changes are confirmed before execution. Drawing on twelve classic engineering books. Triggers when: user…
include-test-files-that-assert-on-behavior-being-changed-in-decl
When delegating a task affected by this skill, include.