review

review is a skill for Claude Code, Codex from glebis/humane-agentic-design. It costs 144 tokens per session (3,683 once invoked), scanned A, original, MIT.

A coordinated review process for an interface or document that combines specialist checks for layout, wording, usability, task completion, and color contrast into one prioritized result.

In plain words
What is it for?
Use it to review a screen, user flow, running app, UI source, README, documentation page, product requirements document, or similar design or product artifact.
Why use it?
It saves the reader from reconciling separate audit reports and clearly marks areas that cannot be assessed from the supplied artifact.

Skill for Claude CodeCodex

Written for Claude Code and Codex: shipped in a Claude Code plugin, but also agents/openai.yaml present. Also seen: mentions CLAUDE.md; mentions subagents; mentions Claude Code.

Part of the humane plugin — 17 skills, 1 agent shipped together

Good fit Use it to review a screen, user flow, running app, UI source, README, documentation page, product requirements document, or similar design or product artifact.

Compare 6 skills from other repositories ↓
Install with agentmods
npx agentmods add skills/glebis/humane-agentic-design/review
Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

Any agent
npx skills add glebis/humane-agentic-design --skill review
Clone the repo
git clone --depth 1 https://github.com/glebis/humane-agentic-design

Made for: Claude Code, Codex.

Or install humane, the plugin that ships this one along with the rest of its 17 skills, 1 agent.

Wrote this? Show the measurements

A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.

agentmods badge for review

README.md
[![agentmods](https://agentmods.dev/badge/skills/glebis/humane-agentic-design/review.svg)](https://agentmods.dev/skills/glebis/humane-agentic-design/review)
Your own site
<a href="https://agentmods.dev/skills/glebis/humane-agentic-design/review"><img src="https://agentmods.dev/badge/skills/glebis/humane-agentic-design/review.svg" alt="Measured on agentmods" height="20"></a>
Per session 144 Skills are progressive disclosure: only the name and description are preloaded; the body loads when the skill is used.
When invoked 3,683 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. A grade says what 26 rules found in the file — not that it is safe. Third-party audits
  • NVIDIA SkillSpector warn 7 Sept 2026
SkillSpector: 1 finding, up to medium

These are SkillSpector’s own severities. On a checked sample its high-severity flags on skills were ~96% false positives — a documented command, a public API, a “never do X” rule — so we show them as a caution to read, not a verdict. Why →

  • medium Memory Poisoning · line 118
    Skill attempts to fill the context window with filler content, displacing legitimate instructions and safety constraints. This can degrade agent performance or bypass safety boundaries.
    Fix: Implement context-window management that detects and rejects padding or stuffing attempts. Prioritize system instructions over user-injected content.
How audits are shown
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5.1 $0.00144 $0.03683
Opus 5 $0.00072 $0.01842
Sonnet 5 $0.00029 $0.00737
Haiku 4.5 $0.00014 $0.00368

Measured 3d ago against content hash d60687ef19b4, method: parsed. Prices are Anthropic first-party input rates as of 2026-09-08, from the pricing page.

Security

Grade A, and why

review scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 3d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

humane/skills/review/SKILL.md · 313 lines

How it starts

The opening of the file, as written. The whole thing — 313 lines — stays where its author put it; the contents beside it link to each section on GitHub.

Review the whole thing, once

Announce at start: "I'm using the humane:review skill to run the review cycle and consolidate one verdict."

Five separate audits stapled together is not a review — it is five reports the reader has to reconcile. This skill runs the domains, lets each owning skill apply its own rules, and consolidates the evidence into one ranked verdict.

This skill owns orchestration only. It never restates or overrides a domain rule. Structure and defect classes belong to layout-rules; wording to ux-writing; usability principles to nielsen-heuristics; task completion to walkthrough; color measurement to design-tokens. If you find yourself writing a rule here, it belongs in the skill that owns it.

1. Identify the artifact before anything else

This pipeline is built for an interface. Given something else it will happily stretch — returning a table of N/A and one strained domain — so decide what you are holding first, and say so in the output.

Artifact What to run
Screen, flow, feature, running app, UI source The full pipeline below
Document — README, docs page, PRD, spec, proposal The document pipeline: ux-writing for the prose, layout-rules for structure and hierarchy only (rules 1–4, 39), plus persona-review if the reader's objections matter more than the wording. Skip walkthrough, nielsen-heuristics, and contrast — mark them N/A (not an interface), not Clear
Copy in isolation — a tagline, a hero, brand values Not a review. Hand it to respondent-panel, and to ux-writing for the rewrite
Spec for an unbuilt interface nielsen-heuristics design-risk mode, which produces unscored risk flags. Never severity-score a thing that does not run
Token set with no UI design-tokens contrast alone

A document still gets the full contract — findings table, considered-but-rejected, verification, verdict — just over fewer domains. State the reduced pipeline in Scope and Coverage so the reader knows what was and was not possible.

Read the full file on GitHub · 313 lines

Files

What ships with it

1 file beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 3d ago Changed · +1 lines d60687ef19b4
  2. 8d ago First seen · 312 lines · 144 tokens per session scan A bc6d588cddc4

Subscribe to this mod's changes

review is a skill published in the GitHub repository glebis/humane-agentic-design (28 stars, last pushed 6d ago), licensed MIT. It adds 144 tokens to every session and 3,683 once invoked, about $0.0007 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.

Related

Other skills, from other repositories

figma-extract-design-system

Extract a design system from vibe-coded production apps that never had one: inventory components, mine de-facto styling into DTCG tokens, scaffold a Storybook package, port components, and optionally round-trip tokens/components into Figma. Use when the user wants to 'extract a design system', 'create a design system…

southleft/figma-console-mcp-skills · 133 tokens

figma-blame-node

Find which Figma version introduced a specific change — a component property or a child node — via a binary search over version history (log2(N) API calls instead of N). Answers 'who added this and when'. Use when the user wants git-blame-style attribution for a Figma design — triggers: 'when was this component…

southleft/figma-console-mcp-skills · 176 tokens

figma-export-tokens

Export Figma variables to design token files in DTCG, CSS custom properties, Tailwind v4/v3, SCSS, TypeScript, JSON, Style Dictionary, or Tokens Studio. Use when the user wants to pull design tokens OUT of Figma into code — triggers: 'export tokens', 'export Figma variables', 'generate CSS variables from Figma', 'turn…

southleft/figma-console-mcp-skills · 144 tokens

figma-generate-component-doc

Generate complete Markdown documentation for a Figma component — anatomy/layer tree, design tokens (colors, spacing, typography), states/variants matrix, accessibility notes, content guidelines, and optional code-parity + YAML frontmatter. Use when the user wants a docs page or handoff spec for a component or…

southleft/figma-console-mcp-skills · 150 tokens

figma-version-history

List a Figma file's version history, snapshot the file at any past version, and diff two versions (added/removed/renamed pages plus deep per-component changes). Use when the user wants to inspect Figma history — triggers: 'list Figma versions', 'what versions does this file have', 'show version history', 'snapshot…

southleft/figma-console-mcp-skills · 181 tokens

figma-comments

Read, post, reply to, and delete comments on a Figma file via the REST API — including pinning a comment to a specific node and threading replies. Use when the user wants to work with Figma comments programmatically — triggers: 'get Figma comments', 'read comments on this file', 'post a comment in Figma', 'leave a…

southleft/figma-console-mcp-skills · 151 tokens