Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add skills/delphicleancode/delphi-spec-kit/code-reviewnpx skills add delphicleancode/delphi-spec-kit --skill code-reviewgit clone --depth 1 https://github.com/delphicleancode/delphi-spec-kitWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00021 | $0.01011 |
| Opus 5 | $0.00010 | $0.00505 |
| Sonnet 5 | $0.00004 | $0.00202 |
| Haiku 4.5 | $0.00002 | $0.00101 |
Grade A, and why
Delphi Code Review scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
Copies of this mod
1 near-identical copy found in the catalogue:
- code-review — 95% identical, 4 lines differ
How it starts
The opening of the file, as written. The whole thing — 145 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Delphi Code Review — Skill
Quick Checklist
Corretude
- Code does what it's supposed to do
- Edge cases handled (nil, empty list, zero value)
- Error handling implemented with specific exceptions
- No obvious bugs
Security
- Parameterized SQL queries (without string concatenation)
- Validated and sanitized input
- No hardcoded credentials or passwords
- No SQL injection via
Formator concatenation in queries
Performance
- No N+1 queries (avoid loop with query inside)
- No unnecessary loops
- Large objects released as early as possible
-
TObjectListwithOwnsObjectsconfigured correctly
Code Quality
- Self-descriptive names following Pascal Guide
- DRY — no duplicate code
- SOLID — principles respected
- Methods ≤ 20 lines
- Guard clauses instead of deep nesting
Memory Management
-
try/finallywithFreefor temporary objects - Interfaces for automatic reference counting
-
Assigned()before accessing references that may be nil - Destructor
Destroywithoverridefreeing owned fields - No memory leaks in exception paths
Pascal Nomenclature
- PascalCase for all identifiers
- Prefix
Tin classes,Iin interfaces,Ein exceptions - Prefix
Fin private fields,Ain parameters,Lin local variables - Units:
Projeto.Camada.Dominio.Funcionalidade.pas - Components: 3-letter prefix (
btn,edt,lbl, etc.)
Tests
- Unit tests for new code
- Edge cases tested
- Readable and maintainable tests
Documentation
- XMLDoc for public methods and properties
- Comments in Portuguese when necessary
- Do not comment self-explanatory code
Anti-Patterns to Flag
//❌ Magic numbers
if ACustomer.Age > 18 then
//✅ Named constants
const MINIMUM_AGE = 18;
if ACustomer.Age > MINIMUM_AGE then
//❌ with statement
with AQuery do begin
SQL.Text := '...';
Open;
end;
//✅ Explicit reference
AQuery.SQL.Text := '...';
AQuery.Open;
//❌ Generic Catch
except
on E: Exception do ShowMessage(E.Message);
//✅ Specific exceptions
except
on E: EFDDBEngineException do
raise EDatabaseException.Create('Falha: ' + E.Message);
//❌ Logic in OnClick
procedure TfrmMain.btnSaveClick(Sender: TObject);
begin
//50 lines of business logic here
end;
//✅ Delegate for Service
procedure TfrmMain.btnSaveClick(Sender: TObject);
begin
FService.SaveCustomer(GetFormData);
end;
// ❌ Memory leak
function GetItems: TStringList;
begin
Result := TStringList.Create;
LoadItems(Result); //if LoadItems throws exception, leak!
end;
//✅ Safe
function GetItems: TStringList;
begin
Result := TStringList.Create;
try
LoadItems(Result);
except
Result.Free;
raise;
end;
end;
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 2d ago First seen · 145 lines · 21 tokens per session scan A b88700832590
Delphi Code Review is a skill published in the GitHub repository delphicleancode/delphi-spec-kit (50 stars, last pushed 5mo ago), licensed MIT. It adds 21 tokens to every session and 1,011 once invoked, about $0.0001 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other skills, from other repositories
dmvcframework
Use when writing any server-side feature with DelphiMVCFramework (DMVC) — controllers, routes, REST endpoints, entities, middleware, validation, dependency injection, JWT, SSE, or the server bootstrap. The core skill; the Minimal API, web-app, UI, security and testing skills build on it. Triggers on "DMVCFramework"…
dmvcframework-jsonrpc
Use when building or consuming a JSON-RPC 2.0 endpoint with DelphiMVCFramework — publishing a plain Delphi class as remotely callable methods, or calling one from a Delphi client. Triggers on "JSON-RPC", "JSONRPC", "MVCFramework.JSONRPC", "RPC method", "PublishObject", "TMVCJSONRPCController", "TMVCJSONRPCPublisher"…
dmvcframework-testing
Use when writing or fixing tests for a DelphiMVCFramework API — integration tests that drive real HTTP against an in-process server, or unit tests around controllers. Covers the DUnitX + in-process IMVCServer + IMVCRESTClient stack, CRUD/auth/authorization test patterns, database fixtures and the console runner.…
delphi
Use when writing, reviewing or fixing Delphi / Object Pascal code — any .pas or .dpr unit, the RTL or the VCL — independently of any framework. Covers language level and version gating, inline var, generics, anonymous methods, memory and lifetime (Free, try/finally, interfaces, managed records), strings and encodings…
dmvcframework-minimal-api
Use when building a DelphiMVCFramework service with lambda/anonymous-method routes instead of controller classes — Minimal API. Triggers on "minimal API", "MapGet", "MapPost", "MapMethods", "route group", "endpoint filter", "HTTP filter", "TMVCRouteGroup", "AsWeb", "lambda routes", "no controller", "Prefix"…
dmvcframework-ui
Use when styling or laying out the HTML of a DMVCFramework web application — adding a page, a nav entry, a card, a form, a toast, a theme toggle, or touching style.css. Covers the presentation layer the DMVCFramework wizard actually generates: Bootstrap 5.3 (loaded from CDN in baselayout), the brand tokens in…