Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add skills/fitlab-ai/agent-infra/review-codenpx skills add fitlab-ai/agent-infra --skill review-codegit clone --depth 1 https://github.com/fitlab-ai/agent-infraWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/fitlab-ai/agent-infra/review-code)<a href="https://agentmods.dev/skills/fitlab-ai/agent-infra/review-code"><img src="https://agentmods.dev/badge/skills/fitlab-ai/agent-infra/review-code.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00047 | $0.03927 |
| Opus 5 | $0.00023 | $0.01963 |
| Sonnet 5 | $0.00009 | $0.00785 |
| Haiku 4.5 | $0.00005 | $0.00393 |
Grade A, and why
review-code scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured today.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 177 lines — stays where its author put it; the contents beside it link to each section on GitHub.
代码审查
--agent取值见.agents/rules/task-management.md「合作者 token 规范」。
若入口业务操作数包含 --orchestrated,绑定 {execution-flag} = --orchestrated 并原样转发给 summary finalizer 与 completed 事件;否则绑定为空。不得从 orchestration.json、环境变量或历史产物推断该标记。生命周期事件还必须携带显式触发信息:编排调用使用 {trigger-initiator}=orchestrator,否则使用 model;{request-id} 是本任务与本轮产物的稳定单行标识,{reason-code} 使用 user-request 或 review-finding;started 与 completed 使用同一组值。
审查最新代码轮次,并产出 review-code.md 或 review-code-r{N}.md。
行为边界 / 关键规则
- 本技能只审查代码并写报告,不修改业务代码
- 生成会同步到 Issue 的任务或生命周期 Markdown 前,先读取
.agents/rules/sync-content-generation.md并遵循其中的生成端约束;同步端不解析或改写正文 - 执行本技能后,你必须立即更新 task.md
版本戳规则:创建或更新 task.md frontmatter 时,先读取 .agents/rules/version-stamp.md,并写入或刷新 agent_infra_version。
常见违规借口与反驳
| 借口 | 反驳 |
|---|---|
| 「只改了一行,不影响功能」 | 行数不等于影响面;必须读完整 git diff 并定位每处改动的下游效果。 |
| 「大体没问题,给个 Approved」 | 结论必须由 blocker/major/minor 计数支撑,每个问题引用文件:行号,不能凭印象放行。 |
| 「测试改动看着合理,跳过细看」 | 审查测试变更前必须逐条核对 .agents/rules/testing-discipline.md(见步骤 4 门禁)。 |
| 「记得就是这一行,不用查」 | 行号会漂移;下结论前必须用 rg/nl 复核 file:line,不能复现的判断不要写成 blocker。 |
第 0 步:状态核对(执行前硬约束)
在加载 workflow / skill / rules 指令之后、做任何任务状态判断或用户可见结论之前,必须先执行状态核对。指令类文件读取不算对外动作或结论。
运行以下命令,并把原文粘贴到本轮产物的 ## 状态核对 段:
agent-infra-internal task-snapshot {task-id} --format text
状态核对完成前,禁止任何关于外部状态的断言(例如“代码没变”“测试已通过”“没有其他引用”),包括思考阶段。本门禁只提供结构下限;逐条证据配对和真实性仍需按报告模板与审查要求核对。
任务上下文解析
入口可省略 task ref;显式 task scope 仅接受
--task <ref>或-t <ref>,不再解释位置 task ref。保留其余业务操作数后调用agent-infra-internal task-context resolve {task-scope};{task-scope}为空或 task flag 之一。只读取结构化结果的taskId,后续把{task-id}绑定为完整TASK-YYYYMMDD-HHMMSS。解析失败时透传非零退出码,不自行扫描任务。
解析任务引用,并确认任务位于本技能支持的状态或目录且存在
task.md;无法定位时按未找到任务处理并停止。
步骤开始:声明 started 事件
确认前置条件和产物上下文后、本轮第一个产出动作之前执行 agent-infra-internal task-event {task-id} review-code.started --agent {standard-agent-token} --initiator {trigger-initiator} --request-id {request-id} --reason-code {reason-code}。
执行步骤
1. 验证前置条件
要求存在:
.agents/workspace/active/{task-id}/task.md- 至少一个实现产物:
code.md或code-r{N}.md
What ships with it
9 files beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.
- config/verify.json 1.9 KB
- reference/concurrency-risks.md 924 B
- reference/cross-platform-risks.md 1.3 KB
- reference/documentation-antipatterns.md 925 B
- reference/migration-risks.md 1.6 KB
- reference/output-templates.md 6.7 KB
- reference/report-template.md 6.8 KB
- reference/review-criteria.md 3.5 KB
- reference/security-risks.md 994 B
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- today Changed 114041b71352
- yesterday Changed · +3 lines c444deede374
- 5d ago First seen · 174 lines · 47 tokens per session scan A 50361026af9f
review-code is a skill published in the GitHub repository fitlab-ai/agent-infra (83 stars, last pushed today), licensed MIT. It adds 47 tokens to every session and 3,927 once invoked, about $0.0002 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other skills, from other repositories
contextualize
Detect application-context mismatch after execution. Fires when correct output may not fit the actual context. Type: (ApplicationDecontextualized, AI, CONTEXTUALIZE, Result) → ContextualizedExecution.
review-loop
Convergence-paced review-resolve loop over a change and its governing surfaces. Verifies each finding against the codebase and the base it is measured from, then re-reviews until each is disposed of.
conduct
Conduct method before object-level work. Fires when the work needs several moves in non-trivial order. Type: (MethodUnderdetermined, Hybrid, CONDUCT, WorkProspect × MoveGround) → ConductedMethod.
apportion
Apportion an autonomous goal into execution units carrying their own completion conditions. Type: (GoalPlanUncompiled, User, APPORTION, AutonomousGoal × ExecutionHorizon) → ConditionBearingUnitPlan.
ground
Validate structural mapping between abstract and concrete domains. Presents concrete instantiations when mapping uncertainty is detected. Type: (MappingUncertain, AI, GROUND, R) → ValidatedMapping.
steer
Project-profile recalibration. Audits session calibration drift, presents per-cluster evidence for a user verdict, writes the updated project-profile rule, and inscribes a settled-direction clause.