Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add skills/blueberrycongee/termcanvas/code-reviewnpx skills add blueberrycongee/termcanvas --skill code-reviewgit clone --depth 1 https://github.com/blueberrycongee/termcanvasWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00050 | $0.00742 |
| Opus 5 | $0.00025 | $0.00371 |
| Sonnet 5 | $0.00010 | $0.00148 |
| Haiku 4.5 | $0.00005 | $0.00074 |
Grade A, and why
code-review scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 92 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Code Review
Structured multi-pass review. Read the full diff before commenting on anything.
Phase 1: Orient
- Determine the review scope:
- If reviewing a PR:
git diff <base>..HEAD - If reviewing staged changes:
git diff --cached - If reviewing a file: read the file
- If reviewing a PR:
- Understand the intent: read the commit messages, PR description, or task description to understand what the change is supposed to do
- Identify the change type: feature, bugfix, refactor, config, dependency update
Phase 2: Critical Pass
Read the diff line by line. Flag only real issues:
Always check:
- Logic errors (wrong conditions, off-by-one, missing null checks on external data)
- SQL injection, XSS, command injection, path traversal
- Race conditions in concurrent code
- Resource leaks (unclosed handles, missing cleanup)
- Missing error handling at system boundaries (network, file I/O, user input)
- Breaking API contract changes without version bump
Never flag:
- Style preferences (naming, formatting) unless they cause confusion
- Missing comments on self-explanatory code
- Hypothetical edge cases that cannot happen given the invariants
- "I would have done it differently" without a concrete defect
Phase 3: Specialist Focus
Based on the change type, apply the relevant specialist lens:
If the diff touches tests:
- Do tests actually test behavior, or just assert mock return values?
- Are there tautological assertions (
expect(true).toBe(true))? - Is the test coupled to implementation details rather than outcomes?
If the diff touches data access:
- N+1 query patterns in loops
- Unbounded result sets without pagination
- Transactions where atomic operations are needed
If the diff touches auth/security:
- Apply Phase 2-4 of the
security-auditskill to the changed code
If the diff touches UI:
- State management: are loading/error/empty states handled?
- Accessibility: keyboard navigation, semantic HTML, ARIA labels
- Responsive: does it work at mobile/tablet/desktop breakpoints?
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 2d ago First seen · 92 lines · 50 tokens per session scan A 8a2d82013058
code-review is a skill published in the GitHub repository blueberrycongee/termcanvas (392 stars, last pushed 3mo ago), licensed MIT. It adds 50 tokens to every session and 742 once invoked, about $0.0003 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other skills, from other repositories
convert-sales-page
Author long-form direct-response sales pages: section architecture, full body copy, paste-ready HTML/CSS, and Method audit footer. Applies The Donahoe Method top-to-bottom across 16 sections. Use when the user has a product and needs a complete sales page built from a brief - not a teardown of an existing URL. Not for…
fix-issues
Auto-fix GitHub issues labeled as bugs: fetch open bug issues, analyze feasibility, fix code, and submit PRs. One issue per invocation. Use when: (1) User says "/fix-issues", (2) User asks to fix GitHub issues.
fix-sentry
Auto-fix high-frequency Sentry issues: fetch issues > N occurrences, analyze stack traces, fix code, create GitHub issues, and submit PRs. Supports user feedback issues (event.type "default") with attachment analysis (logs, screenshots) when includefeedback=true. Use when: (1) User says "/fix-sentry", (2) User asks to…
pr-automation
PR Automation Orchestrator: poll open PRs, check CI, run review, fix, and merge eligible PRs. Use when: (1) Invoked by daemon via scripts/pr-automation.sh, (2) User says "/pr-automation".
pr-verify
PR Verification & Merge: verify bot:ready-to-merge PRs with impact analysis, test supplementation, and one-click merge. Use when: (1) User says "/pr-verify", (2) User wants to verify and merge ready PRs.
content-about-page
Build a long-form About page that converts visitors into subscribers and buyers - not a bio expanded into paragraphs, but a full DR asset that hooks with the reader's problem, tells a story-of-discovery, proves the path with results, and closes with an explicit next step. Outputs a structured content brief plus…