Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add cicababba/claude-plugins-marketplace --skill dev-quality-reportgit clone --depth 1 https://github.com/cicababba/claude-plugins-marketplaceWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/cicababba/claude-plugins-marketplace/dev-quality-report)<a href="https://agentmods.dev/skills/cicababba/claude-plugins-marketplace/dev-quality-report"><img src="https://agentmods.dev/badge/skills/cicababba/claude-plugins-marketplace/dev-quality-report/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/cicababba/claude-plugins-marketplace/dev-quality-report"><img src="https://agentmods.dev/badge/skills/cicababba/claude-plugins-marketplace/dev-quality-report.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00045 | $0.01389 |
| Opus 5 | $0.00023 | $0.00694 |
| Sonnet 5 | $0.00009 | $0.00278 |
| Haiku 4.5 | $0.00005 | $0.00139 |
Grade A, and why
dev-quality-report scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 10d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 233 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Dev Quality Report
This skill generates persistent code quality reports.
When to Use
- During
/quality-checkcommand - When quality check is requested during
/end - When analyzing code quality for specific paths
- Independent of any active session
Input
paths: List of paths to analyze (default: repo root)options:include: Glob patterns to includeexclude: Glob patterns to excludedefaultExcludes: boolean (default: true) - Apply default ignore rules
Responsibilities
- Ask user which paths to analyze (if not provided)
- Apply default ignore rules (unless disabled)
- Generate unique
reportId(8-char hex) - Generate report path:
.claude/dev-sessions/quality-reports/YYYYMMDD-HHmm-qa-{reportId}.md - Write initial report with
Status: PENDING - Call
code-quality-analyzeragent in read-only mode - Rewrite report with full analysis and
Status: DONEorABORTED - Return report path and summary
Default Ignore Rules
Always ignored unless defaultExcludes: false:
**/node_modules/****/.git/****/dist/**,**/build/**,**/.next/**,**/.vite/****/coverage/**,**/.turbo/**,**/.cache/****/tmp/**,**/.tmp/****/package-lock.json,**/pnpm-lock.yaml,**/yarn.lock**/*.min.*
MUST
- Use
artifact-fs-managerfor all file operations - Never modify repository source files
- Never change any session Status
- Always set report Status to PENDING before analysis
- Always set report Status to DONE or ABORTED after
MUST NOT
- Modify any source code files
- Install or change dependencies
- Change session status
- Run commands that modify the codebase
Process
Step 1: Determine Paths
If paths not provided:
- Ask user: "Which paths should I analyze? (default: repo root)"
- Accept user input or use default
Step 2: Apply Ignore Rules
- Start with default ignore patterns (if
defaultExcludes: true) - Add any additional
excludepatterns - Apply
includepatterns to narrow scope
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 10d ago First seen · 233 lines · 45 tokens per session scan A 896fd672eacb
dev-quality-report is a skill published in the GitHub repository cicababba/claude-plugins-marketplace (3 stars, last pushed 9mo ago), licensed MIT. It adds 45 tokens to every session and 1,389 once invoked, about $0.0002 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other skills, from other repositories
autoreview
Pre-commit/ship code review: Codex default; optional Claude or Pi.
rework-rate
Measure and interpret PR rework rate — the emerging 5th DORA metric.
omh-code-review
This is a Hermes-native code-review workflow skill.
revdiff-plan
Review the last Codex assistant message (plan, analysis, or proposal) with inline annotations in a TUI overlay. Extracts the most recent response from Codex rollout files and opens it in revdiff for review and annotation. Activates on "revdiff-plan", "review plan with revdiff", "annotate plan", "review last response"…
code-reviewer
Code review specialist focused on patterns, bugs, security, and performance.
full-repo-review
Comprehensive four-wave review of all repo source files, producing a prioritized issue backlog.