Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add DauQuangThanh/hanoi-rainbow --skill code-quality-reviewgit clone --depth 1 https://github.com/DauQuangThanh/hanoi-rainbowWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/dauquangthanh/hanoi-rainbow/code-quality-review)<a href="https://agentmods.dev/skills/dauquangthanh/hanoi-rainbow/code-quality-review"><img src="https://agentmods.dev/badge/skills/dauquangthanh/hanoi-rainbow/code-quality-review/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/dauquangthanh/hanoi-rainbow/code-quality-review"><img src="https://agentmods.dev/badge/skills/dauquangthanh/hanoi-rainbow/code-quality-review.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00127 | $0.00936 |
| Opus 5 | $0.00063 | $0.00468 |
| Sonnet 5 | $0.00025 | $0.00187 |
| Haiku 4.5 | $0.00013 | $0.00094 |
Grade A, and why
code-quality-review scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 10d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 105 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Code Quality Review
Overview
Conducts systematic code quality analysis across multiple dimensions: maintainability, readability, complexity, design patterns, naming conventions, code duplication, and adherence to best practices. Produces actionable feedback with severity ratings and specific improvement recommendations.
Core Capabilities
- Code Smells Detection - Identifies bloaters, object-orientation abusers, change preventers, dispensables, and couplers
- Complexity Analysis - Measures cyclomatic and cognitive complexity with risk assessment
- Maintainability Assessment - Evaluates code maintainability index and technical debt
- Design Pattern Evaluation - Reviews architectural patterns and SOLID principles
- Best Practices Validation - Checks adherence to language-specific standards and conventions
Review Workflow
Step 1: Scope Assessment
Determine review scope based on change size:
- Small (<100 lines): Quick correctness check, 15-30 minutes
- Medium (100-500 lines): Full quality analysis, 1-2 hours
- Large (>500 lines): Architectural review, break into smaller reviews if possible, 2-4 hours
For scope-specific guidance, see review-scope-guidelines.md
Step 2: Initial Assessment
Gather Context:
- Identify programming language and framework
- Understand project type (web app, API, library, CLI, etc.)
- Note existing coding standards or style guides
- Check for linter configuration files (.eslintrc, .pylintrc, checkstyle.xml, etc.)
Read the Code:
- Start with entry points (main files, index files)
- Review module/package organization
- Check dependency management
- Examine test files if available
Step 3: Quality Analysis
Analyze code across key dimensions:
- Code Smells: Long methods, large classes, duplicate code, dead code, etc.
- Complexity: Cyclomatic complexity (target <15), cognitive complexity, nesting depth
- Maintainability: Clear naming, proper abstraction, separation of concerns
- Design Patterns: Appropriate pattern usage, SOLID principles adherence
- Best Practices: Language idioms, error handling, resource management
What ships with it
7 files beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 10d ago First seen · 105 lines · 127 tokens per session scan A bf810364e533
code-quality-review is a skill published in the GitHub repository DauQuangThanh/hanoi-rainbow (16 stars, last pushed 7mo ago), licensed MIT. It adds 127 tokens to every session and 936 once invoked, about $0.0006 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other skills, from other repositories
code-review-hardening
Use this skill for rigorous, structured code review with a self-repair loop. Applies change-type-aware strategies (feat, fix, hotfix, refactor, migrate, docs). Findings are severity-classified, then auto-fixed where possible. Triggers on PR reviews, code review requests, or when reviewing any change set.
quality-grading
Use this skill to grade code, specifications, or design documents across four quality dimensions using a 1-5 scoring scale. In grade-and-fix mode, the skill auto-improves artifacts scoring below 5 without prompting. Invoke when you want consistent quality assessment on design, implementation, or specification with…
agent-work-auditor
Unified auditing skill for AI agent workflows. Provides change-type-aware, artifact-adaptive auditing with self-fix capabilities. Works standalone or with spec-driven extensions. Three-layer architecture: core (always active), modules (per-type), extensions (auto-detected).
spec-driven-development
Spec-first workflow where an executable, testable specification is written before code and becomes the single source of truth that tests verify against, flowing spec → acceptance criteria → tasks → implementation.
bmad-review-edge-case-hunter
Walk every branching path and boundary condition in content, report only unhandled edge cases. Orthogonal to adversarial review - method-driven not attitude-driven. Use when you need exhaustive edge-case analysis of code, specs, or diffs.
bmad-review-adversarial-general
Perform a Cynical Review and produce a findings report. Use when the user requests a critical review of something.