Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add contentstack/contentstack-ios --skill code-reviewgit clone --depth 1 https://github.com/contentstack/contentstack-iosWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/contentstack/contentstack-ios/code-review)<a href="https://agentmods.dev/skills/contentstack/contentstack-ios/code-review"><img src="https://agentmods.dev/badge/skills/contentstack/contentstack-ios/code-review.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00032 | $0.00624 |
| Opus 5 | $0.00016 | $0.00312 |
| Sonnet 5 | $0.00006 | $0.00125 |
| Haiku 4.5 | $0.00003 | $0.00062 |
Grade A, and why
code-review scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 3d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 61 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Code Review – Contentstack iOS CDA SDK
Use this skill when performing or preparing a pull request review for the iOS CDA SDK.
When to use
- Reviewing someone else’s PR.
- Self-reviewing your own PR before submission.
- Checking that changes meet project standards (API, errors, compatibility, tests, security).
Instructions
Work through the checklist below. Optionally tag items with severity: Blocker, Major, Minor. The canonical short checklist lives in .cursor/rules/code-review.mdc (aligned with contentstack-java and other CDA SDKs).
1. API design and stability
- Public API: New or changed public headers are necessary and documented (header comments / usage examples consistent with the repo).
- Backward compatibility: No breaking changes to public Objective-C / Swift-visible API without agreement (major version or explicit migration).
- Naming: Consistent with existing SDK and CDA terminology (
Stack,Entry,Query,Config, etc.).
Severity: Breaking public API without approval = Blocker. Missing docs on new public API = Major.
2. Error handling and robustness
- Errors: Failures use
NSError, failure blocks, or delegates as appropriate for the module. - Nullability: Annotations remain correct; no ignored errors in new code paths.
- Memory / concurrency: No obvious retain cycles; threading matches existing networking patterns.
Severity: Wrong or missing error handling in new code = Major.
3. Dependencies and security
- Dependencies: Podspec / vendored code changes are justified; versions do not introduce known critical issues.
- SCA: Security findings (Snyk, Dependabot, etc.) are addressed or tracked.
Severity: New critical/high vulnerability = Blocker.
4. Testing
- Coverage: New or modified behavior has XCTest coverage where feasible.
- Conventions: Test classes follow
*Testnaming; async tests use expectations and sane timeouts. - Quality: Tests are deterministic and readable.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 3d ago First seen · 61 lines · 32 tokens per session scan A dcc1b9ece62f
code-review is a skill published in the GitHub repository contentstack/contentstack-ios (3 stars, last pushed 1mo ago), licensed MIT. It adds 32 tokens to every session and 624 once invoked, about $0.0002 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-09-04.
Other skills, from other repositories
adversarial-reviewer
Adversarial code review that assumes bugs exist and hunts for them. Use when asked to review code, find bugs, audit for correctness, stress-test a PR, or when someone says "tear this apart" or "what's wrong with this". Give no benefit of the doubt — every line is guilty until proven innocent.
go-testing
Trigger: Go tests, go test coverage, Bubbletea teatest, golden files. Apply focused Go testing patterns.
semgrep-rule-variant-creator
Creates language variants of existing Semgrep rules. Use when porting a Semgrep rule to specified target languages. Takes an existing rule and target languages as input, produces independent rule+test directories for each language.
brooks-sweep
Full-sweep mode: runs a unified analysis across all quality dimensions — code decay, architecture, tech debt, and test quality — then applies fixes directly to the codebase. Safe changes are auto-applied; risky changes are confirmed before execution. Drawing on twelve classic engineering books. Triggers when: user…
include-test-files-that-assert-on-behavior-being-changed-in-decl
When delegating a task affected by this skill, include.
plugin-review
Review plugin quality with tiered checks and dependency scoping. Use for PR and pre-release audits.