Getting it into your agent
It runs from inside its repository, so the clone comes first — what it calls does not travel with the file alone.
git clone --depth 1 https://github.com/GlamgarOnDiscord/claude-saas-blueprintnpx agentmods add skills/glamgarondiscord/claude-saas-blueprint/reviewWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/glamgarondiscord/claude-saas-blueprint/review)<a href="https://agentmods.dev/skills/glamgarondiscord/claude-saas-blueprint/review"><img src="https://agentmods.dev/badge/skills/glamgarondiscord/claude-saas-blueprint/review/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/glamgarondiscord/claude-saas-blueprint/review"><img src="https://agentmods.dev/badge/skills/glamgarondiscord/claude-saas-blueprint/review.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00026 | $0.00572 |
| Opus 5 | $0.00013 | $0.00286 |
| Sonnet 5 | $0.00005 | $0.00114 |
| Haiku 4.5 | $0.00003 | $0.00057 |
Grade A, and why
review scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 12d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
What it actually says
Instructions
1. Identifier les changements
git diff --name-only HEAD~1 # derniers fichiers modifiés
Si pas de git → demander quels fichiers reviewer.
2. Scan secrets (obligatoire en premier)
python scripts/scan_secrets.py --staged-only
Si exit 1 → bloquer la review, corriger avant tout.
3. Review automatique (3 agents en parallèle)
Agent 1 — Clean Code (Explore)
Lire [fichiers modifiés] et vérifier :
- Fichiers > 200 lignes ?
- Fonctions > 50 lignes ?
- Duplication de code ?
- `any` utilisé ?
- `console.log` oublié ?
- Imports inutilisés ?
Retourner UNIQUEMENT les problèmes trouvés, pas les OK.
Agent 2 — Sécurité (Explore)
Lire [fichiers modifiés] et vérifier :
- Inputs validés avec Zod AVANT usage ?
- Auth + organizationId vérifiés sur chaque route ?
- Pas de secrets hardcodés ?
- Rate limiting présent sur les endpoints publics ?
- Headers sécurité en place (CSP, X-Frame-Options) ?
- SQL/HTML injection possible ?
Référence : .claude/rules/security.md
Retourner UNIQUEMENT les vulnérabilités trouvées.
Agent 3 — Architecture (Explore)
Lire [fichiers modifiés] et vérifier :
- core/ importe-t-il depuis adapters/ ? (violation hexagonale)
- Les types sont cohérents avec core/entities/ ?
- Les usecases retournent des types typés, pas des objets bruts ?
- Pas d'accès DB direct dans les routes (passer par usecase) ?
- Conventions respectées : kebab-case fichiers, PascalCase types ?
Retourner UNIQUEMENT les violations trouvées.
4. Rapport
## Code Review — [date] — [branche]
### Fichiers reviewés
[liste]
### Secrets
✓ Aucun secret détecté | ✗ [problèmes]
### Problèmes trouvés
- [CRITICAL] ...
- [WARNING] ...
- [SUGGESTION] ...
### Verdict
APPROVE | CHANGES_REQUESTED
Score sécurité : x/5
5. Auto-fix
Proposer de corriger automatiquement : imports inutilisés, console.log, nommage évident.
Pour les problèmes architecturaux → utiliser /refactor.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 12d ago First seen · 86 lines · 26 tokens per session scan A e8cfc6bd01ac
review is a skill published in the GitHub repository GlamgarOnDiscord/claude-saas-blueprint (2 stars, last pushed 3mo ago), licensed MIT. It adds 26 tokens to every session and 572 once invoked, about $0.0001 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other skills, from other repositories
sdd-apply
Skill "sdd-apply" from Gentleman-Programming/gentle-ai, covering execution role, language domain contract, purpose, what you receive and execution and persistence contract.
gentle-ai-collab-perfect
Trigger: contributing to Gentleman-Programming/gentle-ai as an external collaborator. Strict issue-first workflow, honest PR bodies, contributor-vs-maintainer scope, chained-PR strategy, verification protocol, docstring coverage. Load whenever the active repo is Gentleman-Programming/gentle-ai and any part of the…
issue-creation
Trigger: issue creation, bug reports, feature requests, or issue approval. Create and triage GitHub issues from repository evidence.
sdd-spec
Write SDD delta specs with requirements and scenarios. Trigger: orchestrator launches spec work for a change.
sdd-tasks
Break an SDD change into implementation tasks. Trigger: orchestrator launches task planning for a change.
sdd-verify
Skill "sdd-verify" from Gentleman-Programming/gentle-ai, covering execution role, language domain contract, activation contract, hard rules and decision gates.