Borrowing it
Nothing to install: this file belongs to fqmyysjjd/agent-feed. Take a copy, put it at the same path in your own repository, and replace the rules that are about this project with yours.
curl -O https://raw.githubusercontent.com/fqmyysjjd/agent-feed/main/.agents/skills/project-review/SKILL.mdgit clone --depth 1 https://github.com/fqmyysjjd/agent-feedWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/fqmyysjjd/agent-feed/project-review)<a href="https://agentmods.dev/skills/fqmyysjjd/agent-feed/project-review"><img src="https://agentmods.dev/badge/skills/fqmyysjjd/agent-feed/project-review/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/fqmyysjjd/agent-feed/project-review"><img src="https://agentmods.dev/badge/skills/fqmyysjjd/agent-feed/project-review.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00025 | $0.00976 |
| Opus 5 | $0.00013 | $0.00488 |
| Sonnet 5 | $0.00005 | $0.00195 |
| Haiku 4.5 | $0.00003 | $0.00098 |
Grade A, and why
project-review scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 9d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 76 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Project Review Skill
Required Use
Use this skill for code, diff, commit, merge, or AI-generated implementation review.
Do not modify code during a review unless the user explicitly asks for fixes in the same task.
Review Mode
Classify the review before acting:
Pure review: the user asked for review, diff review, commit review, or findings. Do not edit files. Return findings and residual risk only.Implementation gate: the review is part of a task that already includes coding, refactor, fix, or tests. Findings may become follow-up fixes inside the same Task Brief.
For implementation gates, route P0/P1 findings and default-fix P2 findings through .agents/skills/project-fix/SKILL.md, then rerun relevant verification before final handoff.
If a finding requires an unconfirmed decision outside the current Task Brief, stop and apply .agents/rules/decision-gates.md.
Required Reading
.agents/rules/outcome-boundary.md.agents/project/architecture-boundaries.md.agents/rules/development-workflow.md.agents/project/project-structure.md.agents/rules/testing-gates.md.agents/rules/review-gates.md.agents/domain/contracts.md.agents/skills/README.md.agents/skills/specialist-router/SKILL.mdwhen an optional, imported, custom, or specialized skill may match the diff or risk.
Review Scope
Findings should prioritize correctness, contract drift, module ownership, tests, error handling, security/secret handling, and maintainability.
Before finalizing findings, check .agents/skills/README.md for specialized review or fix skills that match the changed language, architecture, framework, persistence layer, or risk category. Use .agents/skills/specialist-router/SKILL.md when the match is not obvious, when a custom skill is involved, or when multiple skills could apply. Use only the skills that directly serve the current review boundary.
Use .agents/skills/concept-review/SKILL.md when the diff introduces or changes names, concepts, abstractions, protocol terms, user-facing language, or skill vocabulary.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 9d ago First seen · 76 lines · 25 tokens per session scan A 7a1c945cbe8e
project-review is a skill published in the GitHub repository fqmyysjjd/agent-feed (4 stars, last pushed 4mo ago), licensed MIT. It adds 25 tokens to every session and 976 once invoked, about $0.0001 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other skills, from other repositories
audit-round
External-audit role for arcgentic rounds. Loaded when arcgentic state.yaml is in awaitingaudit or auditinprogress, OR when the user explicitly requests an external audit of a finished round, OR when reviewing a handoff doc + commit chain against the round's declared scope. Produces a PASS / NEEDSFIX / AUDITINCOMPLETE…
deslop
Remove AI-generated code slop, unnecessary comments, and over-engineering from the current branch diff. Cleans up boilerplate, simplifies abstractions, strips defensive code, and in skill-file mode lints SKILL.md files for quality. Use when cleaning up code, simplifying, removing boilerplate, before committing, or…
llm-gate
LLM-powered quality verification using prompt hooks. Validates commit messages, code patterns, and conventions using AI before allowing operations. Use to set up intelligent guardrails.
improve-architecture
Audit an area of the codebase and propose the smallest structural moves that improve it - untangle boundaries, kill duplication, fix seams, break cycles. Produces a prioritized plan and decision records, not a rewrite. Use when a codebase feels tangled, hard to change, or is becoming a ball of mud, or when asked to…
smart-commit
Run quality gates, review staged changes for issues, and create a well-crafted conventional commit. Use when saying "commit", "git commit", "save my changes", or ready to commit after making changes.
dxkit-action
Read a dxkit report and execute fixes — prioritize findings by severity, plan the fix sequence, run the fix, verify the score moved, re-baseline if appropriate. Supports a SCOPED pass to burn down one category at a time (dependency/BOM vulnerabilities, security, code quality, tests, docs), and a BASELINE-CLEANUP pass…