Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add DauQuangThanh/hanoi-rainbow --skill frontend-code-reviewgit clone --depth 1 https://github.com/DauQuangThanh/hanoi-rainbowWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/dauquangthanh/hanoi-rainbow/frontend-code-review)<a href="https://agentmods.dev/skills/dauquangthanh/hanoi-rainbow/frontend-code-review"><img src="https://agentmods.dev/badge/skills/dauquangthanh/hanoi-rainbow/frontend-code-review/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/dauquangthanh/hanoi-rainbow/frontend-code-review"><img src="https://agentmods.dev/badge/skills/dauquangthanh/hanoi-rainbow/frontend-code-review.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00130 | $0.01515 |
| Opus 5 | $0.00065 | $0.00758 |
| Sonnet 5 | $0.00026 | $0.00303 |
| Haiku 4.5 | $0.00013 | $0.00152 |
Grade A, and why
frontend-code-review scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 11d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 224 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Frontend Code Review
Systematically review frontend code to identify issues, ensure quality, and provide actionable improvement recommendations across code quality, performance, accessibility, and security dimensions.
Review Workflow
1. Initial Assessment
Gather context about the project and identify review scope:
Project Context:
- Framework and version (React, Vue, Angular, vanilla JS)
- Build tools and dependencies
- Target browsers/devices
- Accessibility requirements (WCAG level)
- Performance targets (Core Web Vitals)
Review Scope:
- New features vs. refactoring vs. bug fixes
- Component complexity level
- Critical user paths
- Security-sensitive areas
2. Code Quality Analysis
Evaluate component structure, code patterns, and maintainability:
Key Areas:
- Component architecture (single responsibility, composition patterns)
- JavaScript/TypeScript quality (type safety, naming, complexity)
- State management decisions (local vs. global, immutability)
- Error handling and edge cases
- Code duplication and DRY violations
Load references/code-quality-checklist.md for detailed quality criteria, common issues, and fixes with code examples
3. Performance Review
Assess rendering efficiency, resource loading, and Core Web Vitals:
Focus Areas:
- Rendering optimization (React.memo, useMemo, useCallback, keys)
- Resource loading (images, fonts, scripts, lazy loading)
- Bundle size and code splitting
- Core Web Vitals: LCP < 2.5s, FID < 100ms, CLS < 0.1
- Memory leaks and cleanup
Load references/performance-checklist.md for detailed optimization techniques and Web Vitals guidelines with code examples
4. Accessibility Assessment
Evaluate WCAG 2.1 compliance and inclusive design:
Key Areas:
- Semantic HTML (proper headings, landmarks, lists)
- ARIA implementation (labels, roles, live regions)
- Keyboard navigation and focus management
- Screen reader support (alt text, labels, announcements)
- Color contrast ratios
What ships with it
5 files beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 11d ago First seen · 224 lines · 130 tokens per session scan A feb8b01b486c
frontend-code-review is a skill published in the GitHub repository DauQuangThanh/hanoi-rainbow (17 stars, last pushed 7mo ago), licensed MIT. It adds 130 tokens to every session and 1,515 once invoked, about $0.0006 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other skills, from other repositories
meta-reviewing-web-reviewing
UI component review patterns. Use when reviewing React components, hooks, props, state, styling, and accessibility. Covers rules of hooks, effect cleanup, render performance, list keys, keyboard and ARIA patterns.
code-review-hardening
Use this skill for rigorous, structured code review with a self-repair loop. Applies change-type-aware strategies (feat, fix, hotfix, refactor, migrate, docs). Findings are severity-classified, then auto-fixed where possible. Triggers on PR reviews, code review requests, or when reviewing any change set.
quality-grading
Use this skill to grade code, specifications, or design documents across four quality dimensions using a 1-5 scoring scale. In grade-and-fix mode, the skill auto-improves artifacts scoring below 5 without prompting. Invoke when you want consistent quality assessment on design, implementation, or specification with…
agent-work-auditor
Unified auditing skill for AI agent workflows. Provides change-type-aware, artifact-adaptive auditing with self-fix capabilities. Works standalone or with spec-driven extensions. Three-layer architecture: core (always active), modules (per-type), extensions (auto-detected).
react
Audits React and Next.js code for high-leverage runtime and rendering pitfalls, then routes to deep-dive references on useEffect anti-patterns, re-render causes, rendering model selection, React 19 APIs, and waterfall chains. Use when a .tsx or .jsx file is opened or reviewed, the user asks "is my React code good"…
battle-tested-engineer
Engineering judgment for code write/refactor/test and frontend UI. Trigger on code review, legacy cleanup, tests, UI with data, bloat/over-engineer complaints — even with no explicit mention, before any diff/rewrite/test suite. Output ultra-terse caveman style; code, commits, PR desc, security warnings stay normal…