Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add EricSanchezok/repo-seed --skill repo-reviewgit clone --depth 1 https://github.com/EricSanchezok/repo-seedWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/ericsanchezok/repo-seed/repo-review)<a href="https://agentmods.dev/skills/ericsanchezok/repo-seed/repo-review"><img src="https://agentmods.dev/badge/skills/ericsanchezok/repo-seed/repo-review/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/ericsanchezok/repo-seed/repo-review"><img src="https://agentmods.dev/badge/skills/ericsanchezok/repo-seed/repo-review.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00046 | $0.01403 |
| Opus 5 | $0.00023 | $0.00701 |
| Sonnet 5 | $0.00009 | $0.00281 |
| Haiku 4.5 | $0.00005 | $0.00140 |
Grade A, and why
repo-review scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 12d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 57 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Reviewing a change in this repository
Read the diff, the owning docs, the decision log, and enough surrounding code to understand the design before judging it. Blocking requirements are hard: a violation blocks the change. Manual checks rank remaining risk by this project's real failure modes — apply the ones the change touches, not every one, to every change.
Sources of truth
- AGENTS.md: standing repository rules.
- docs/AGENTS.md: documentation placement and prose discipline.
- docs/decisions/: durable design rationale. Disagreement with a decision record is a design discussion, not an automatic veto.
- docs/specs/: risk-triggered change contracts.
- docs/testing.md: risk-to-layer selection, test topology, evidence rules, and maintenance budget.
- docs/architecture.md: the module map and seams.
Blocking requirements
Universal (applies to any repository)
- New prose receives semantic review. Critically review every added or changed Markdown passage, JSDoc, comment, prompt, description, diagnostic, and visible string. Verify required coverage, accuracy, placement, and editorial quality against the owning code or behavior; automated checks do not establish those properties.
- Docs match the code. Config, defaults, errors, wire fields, events, and public behavior update the owning docs and JSDoc in the same diff.
- Contracts and decisions use the right artifact. A risk-boundary change has an Approved spec; a durable choice with real alternatives has a decision record. Do not demand an ADR as a change log.
- Tests provide minimum sufficient behavior evidence. Name the meaningful regression each changed test prevents and place its primary evidence at the lowest sufficiently real boundary. A fix links an existing deterministic reproduction or adds a regression test that fails before the fix and passes afterward; redundant coverage or implementation-only assertions do not satisfy this requirement.
- External-source provenance is retained. If implementation is materially derived from a paper, article, community post, benchmark, research report, or copied/adapted code, cite it at the closest stable code location or link that location to a decision record whose
## Linkscites the source. A pull request, issue, prompt, or chat-only citation does not count; copied or adapted material also preserves applicable license and NOTICE requirements.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 12d ago First seen · 57 lines · 46 tokens per session scan A af3065ef5318
repo-review is a skill published in the GitHub repository EricSanchezok/repo-seed (8 stars, last pushed 16d ago), licensed MIT. It adds 46 tokens to every session and 1,403 once invoked, about $0.0002 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other skills, from other repositories
sdd-tasks
Break an SDD change into implementation tasks. Trigger: orchestrator launches task planning for a change.
go-testing
Trigger: Go tests, go test coverage, Bubbletea teatest, golden files. Apply focused Go testing patterns.
pr-blocker-summarizer
Summarizes open pull requests into a blockers-first standup digest. Activates when the user asks to summarize open PRs, find blocked pull requests, generate a PR standup, or triage review backlog from a PR export.
review-work
Post-implementation gate review: run manual QA on the real surface yourself, then launch ONE gate reviewer (never a panel) to audit goal, constraints, code quality, security, missed context, and QA evidence. Use before a PR handoff or when the user explicitly asks to review completed work.
ijfw-cross-audit
Generate a cross-platform multi-model audit (Trident) on a diff, brief, or artifact. Trigger: 'cross audit', 'Trident', 'second opinion', 'check with other models', 'check with other AIs', 'cross-check this', 'get another perspective', /cross-audit.
doc-drift
Use this skill when the user wants to audit the memory and documents Claude Code loads into context — CLAUDE.md (user global + project + nested), MEMORY.md, @imports, .claude/skills, .claude/agents, .claude/commands, installed plugins — and detect four kinds of issues: outdated claims, mutually contradictory…