Gentleman Guardian Angel is an AI code-review tool that checks staged files against a repository’s coding standards. Developers use it as a Git pre-commit hook or to review full pull requests, with different AI providers available. The catalogue add-ons support its workflows.
Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add Gentleman-Programming/gentleman-guardian-angel --skill shellcheck-standardsgit clone --depth 1 https://github.com/Gentleman-Programming/gentleman-guardian-angelWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/gentleman-programming/gentleman-guardian-angel/shellcheck-standards)<a href="https://agentmods.dev/skills/gentleman-programming/gentleman-guardian-angel/shellcheck-standards"><img src="https://agentmods.dev/badge/skills/gentleman-programming/gentleman-guardian-angel/shellcheck-standards/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/gentleman-programming/gentleman-guardian-angel/shellcheck-standards"><img src="https://agentmods.dev/badge/skills/gentleman-programming/gentleman-guardian-angel/shellcheck-standards.svg" alt="Reviewed on agentmods" width="80" height="20"></a>- NVIDIA SkillSpector pass
What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00000 | $0.00714 |
| Opus 5 | $0.00000 | $0.00357 |
| Sonnet 5 | $0.00000 | $0.00143 |
| Haiku 4.5 | $0.00000 | $0.00071 |
Grade A, and why
shellcheck-standards scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 10d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 109 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Skill: gga-shellcheck-standards
Purpose
Maintain shell script quality and portability across all GGA bash scripts.
When to Use
When writing or modifying bash scripts in bin/ or lib/.
Running ShellCheck
# Via make (preferred)
make lint
# Direct (matches CI configuration)
shellcheck -x -e SC1090,SC1091,SC2162,SC2129 bin/gga lib/*.sh
All new code must pass make lint before pushing.
Accepted Exclusions
| Code | Rule | Why GGA Excludes It |
|---|---|---|
| SC1090 | Can't follow non-constant source | GGA uses dynamic paths for lib loading |
| SC1091 | Not following sourced file | Same — dynamic lib sourcing |
| SC2162 | read without -r | GGA intentionally handles backslash input |
| SC2129 | Use { } >> file | Style preference — individual redirects are clearer here |
Do NOT add new exclusions without justification in a PR comment.
Critical Rules
Quoting
# GOOD — always quote variables
echo "$var"
"$cmd" "$arg"
# BAD — unquoted
echo $var
$cmd $arg
Conditionals
# GOOD — use [[ ]] in bash
[[ "$var" == "value" ]]
[[ -f "$file" ]]
# BAD — use [ ] only for POSIX compatibility
[ "$var" = "value" ]
Function Variables
# GOOD — always local
my_function() {
local result
result="something"
}
# BAD — leaks to global scope
my_function() {
result="something"
}
No eval
# BAD — never
eval "$user_input"
# If you think you need eval, you don't. Use arrays or parameter expansion.
macOS vs Linux Portability
# sed -i behaves differently
# macOS requires an extension (even empty string)
sed -i '' 's/foo/bar/' file # macOS
sed -i 's/foo/bar/' file # Linux
# GGA pattern — detect and branch:
if [[ "$OSTYPE" == "darwin"* ]]; then
sed -i '' 's/foo/bar/' "$file"
else
sed -i 's/foo/bar/' "$file"
fi
Common Fixes
| ShellCheck warning | Fix |
|---|---|
| SC2086: double quote | Add "$var" around the variable |
| SC2181: check $? | Replace if [ $? -eq 0 ] with if command; then |
| SC2155: declare + assign | Split: local var; var=$(cmd) |
| SC2206: word splitting | Use read -ra arr <<< "$str" |
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 10d ago First seen · 109 lines · 0 tokens per session scan A 3118b5372f00
shellcheck-standards is a skill published in the GitHub repository Gentleman-Programming/gentleman-guardian-angel (1,146 stars, last pushed 2mo ago), licensed MIT. It costs nothing until one of its globs matches a file; then it loads 714 tokens. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other skills, from other repositories
dotnet-reverse
A guide for analyzing compiled .NET and C# programs, including managed Windows executables and libraries. Reverse engineering means studying compiled software to understand how it works, and decompiling turns it back into readable approximate source code.
check-bin-obj-clash
Detects MSBuild projects with conflicting OutputPath or IntermediateOutputPath. USE FOR: builds failing with 'Cannot create a file when that file already exists', 'The process cannot access the file because it is being used by another process', intermittent build failures that succeed on retry, or missing/overwritten…
dart-run-static-analysis
Execute dart analyze to identify warnings and errors, and use dart fix --apply to automatically resolve mechanical lint issues. Use during development to ensure code quality and before committing changes.
agents-sdk-dotnet-debugging
Use when troubleshooting an agent built with the Microsoft Agents SDK (Microsoft.Agents.Hosting.AspNetCore and related packages) in C# / .NET. Trigger on any of these symptoms: build or C# compile errors, crashes on startup, 401 or auth errors on incoming requests, the bot not responding to messages, appsettings.json…
hotpath_init
Configure hotpath profiling in a Rust project. Adds the hotpath dependency with feature-gated setup, instruments main with hotpath::main, functions with measure/measureall, and wraps channels, mutexes, rwlocks, streams, futures, reqwest clients, axum routers and byte-level I/O with hotpath macros. Use when the user…
golang-error-handling
Idiomatic Golang error handling — creation, wrapping with %w, errors.Is/As, errors.Join, custom error types, sentinel errors, panic/recover, the single handling rule, structured logging with slog, HTTP request logging middleware, and samber/oops for production errors. Built to make logs usable at scale with log…