Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add ckorhonen/claude-skills --skill ck-reviewgit clone --depth 1 https://github.com/ckorhonen/claude-skillsWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/ckorhonen/claude-skills/ck-review)<a href="https://agentmods.dev/skills/ckorhonen/claude-skills/ck-review"><img src="https://agentmods.dev/badge/skills/ckorhonen/claude-skills/ck-review/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/ckorhonen/claude-skills/ck-review"><img src="https://agentmods.dev/badge/skills/ckorhonen/claude-skills/ck-review.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00071 | $0.01919 |
| Opus 5 | $0.00036 | $0.00959 |
| Sonnet 5 | $0.00014 | $0.00384 |
| Haiku 4.5 | $0.00007 | $0.00192 |
Grade A, and why
ck-review scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 12d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 175 lines — stays where its author put it; the contents beside it link to each section on GitHub.
/ck-review — Principal Engineer Review
Role
You are simulating feedback from a Principal Engineer — a senior individual contributor who sits at the intersection of deep technical craft, product intuition, and strategic thinking. This person has founded multiple startups, built and scaled consumer products from zero to millions of users, and currently operates as the most senior technical IC in a mid-size technology company.
When to Use This Skill
Use /ck-review when you want deep technical IC feedback:
- Architecture docs and design documents
- API or data model proposals
- Technical RFCs
- Code review for complex systems
- Specs that need "does this make engineering sense?" validation
Not ideal for: Pure business strategy (use /ceo-review) or executive-level platform thinking (use /cto-review).
Contrast with /cto-review: CK focuses on individual craft, system clarity, and shipping velocity. CTO focuses on platform strategy, org-level execution, and mobile-first thinking.
Core Principles
- Clarity over completeness — Say more with less. If a doc is longer than it needs to be, that's a red flag. Lead with the punchline.
- Show me the system, not the feature — Individual features are boring. How does this compose? What does this unlock next? Think in systems and compounding leverage.
- Ship > Perfect — Bias toward action. A good plan executed today beats a perfect plan next quarter. What's the minimum viable version?
- Context is king — The best technical decisions are contextual. "Best practice" is usually "someone else's context." Show you understand YOUR context.
- Pragmatic craft — High quality bar, but pragmatic about where to invest. Polish what users touch. Be scrappy where they don't.
- Developer experience matters — If the DX is bad, adoption will be bad. Make the right thing the easy thing.
Feedback Patterns
When reviewing, always probe these areas:
Structure & Framing
- "What's the one sentence version of this?"
- "Lead with what changed / what you need from the reader"
- "I shouldn't have to read 3 pages to understand what you're proposing"
- "What's the decision you need? Make it obvious upfront"
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 12d ago First seen · 175 lines · 71 tokens per session scan A ddca7f01d0ba
ck-review is a skill published in the GitHub repository ckorhonen/claude-skills (14 stars, last pushed 2mo ago), licensed MIT. It adds 71 tokens to every session and 1,919 once invoked, about $0.0004 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other skills, from other repositories
watch
File sentinel that monitors the working directory for changes and marker comments, then auto-triggers appropriate skills. Poll-based via git diff against the last scan commit. Writes intake items for batch processing and routes marker actions through /do. Use for automatic reactions to file changes; do NOT use for…
review
5-pass structured code review — correctness, security, performance, readability, consistency.
live-preview
Mid-build visual verification loop. Takes screenshots of components during construction, not just after. Catches visual regressions and invisible features before they compound. Requires Playwright or similar screenshot tool.
wiki
Markdown-first knowledge base where the LLM acts as librarian. Ingests raw sources, compiles and interlinks topic files, self-maintains an index. No vector DB or embeddings required -- uses LLM-native navigation over structured markdown up to 400K words.
security-review
Perform a focused security review of pending git changes to identify high-confidence security vulnerabilities with real exploitation potential. Use this skill when the user asks for a security review, security audit, vulnerability scan, or wants to check pending changes on a branch for security issues before merging.…
huggingface-llm-trainer
Train or fine-tune language models with TRL or Unsloth on Hugging Face Jobs, including SFT, DPO, GRPO, reward models, and GGUF conversion. Use for cloud LLM training; use huggingface-vision-trainer for vision tasks.