Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add griffinwork40/agent-afk --skill reviewgit clone --depth 1 https://github.com/griffinwork40/agent-afkWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/griffinwork40/agent-afk/review)<a href="https://agentmods.dev/skills/griffinwork40/agent-afk/review"><img src="https://agentmods.dev/badge/skills/griffinwork40/agent-afk/review.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00100 | $0.06671 |
| Opus 5 | $0.00050 | $0.03335 |
| Sonnet 5 | $0.00020 | $0.01334 |
| Haiku 4.5 | $0.00010 | $0.00667 |
Grade A, and why
review scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 7d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
Copies of this mod
1 near-identical copy found in the catalogue:
- review — 100% identical, 0 lines differ
How it starts
The opening of the file, as written. The whole thing — 172 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Read-only — hard constraint
This skill analyzes and reports; it never mutates the repository, the PR/MR, or anything external. After you emit the merge recommendation, STOP.
Never — not for a real bug, not for a blocking defect, not even when there is no human reviewer and "someone has to fix it":
- edit, create, or delete files (no
write/edit-style mutations); git add/commit/stash/reset,git checkoutto discard changes, orgit push;gh pr comment/review/edit/merge/create, or post or edit any PR/MR body, comment, or description;- run any other write- or network-mutating shell command.
The only shell permitted is read-only inspection: git diff / git show / gh pr diff, grep / rg, and file reads — plus dispatching the review sub-agents. Resolving findings, fixing bugs, resolving merge conflicts, and "making the branch mergeable" are explicitly out of scope: a fixable defect is a finding to report (file:line + a one-line fix in the suggestion field), never a license to act.
Sub-agent contract
/contract
Skip for: lock files (package-lock.json, go.sum, yarn.lock), auto-generated files (*.generated.*), pure-docs diffs, vendored deps.
Resolve target → diff (inline). The review target argument is: $ARGUMENT (empty = review working-tree/HEAD changes). Map this argument to a diff source, then capture the diff text plus a one-line target descriptor for the triage header. Also capture the reviewed ref (branch HEAD SHA or equivalent) — this is required for citation verification later:
--staged→git diff --staged; reviewed ref =git write-tree(snapshots the staged index to a throwaway tree so citations resolve against the staged content under review, not HEAD)--heador no arg →git diff HEAD; reviewed ref =git stash create(snapshots worktree + index to a throwaway commit so citations resolve against the content under review; empty output = no local changes → fall back togit rev-parse HEAD)- arg matches
^https?://.*/pull/\d+(GitHub/GitLab PR URL) →gh pr diff <url>(orglab mr diff); reviewed ref = head SHA fromgh pr view <url> --json headRefOid -q .headRefOid; record PR title + base/head refs - arg matches
^#?\d+$(bare PR number, optionally#-prefixed) → resolve in current repo withgh pr diff <n>; reviewed ref = head SHA fromgh pr view <n> --json headRefOid -q .headRefOid; ifghis unavailable or repo has no PR matching, abort withAsking(one question: which repo/PR) - arg matches
^[0-9a-f]{7,40}$(commit SHA) →git show <sha>; reviewed ref =<sha> - arg matches a known ref (
git rev-parse --verify <arg>succeeds) →git diff <merge-base>...<arg>against the repo's default branch; reviewed ref =git rev-parse <arg> - arg is a path or
*.diff/*.patchfile → read file contents as the diff; reviewed ref =unknown (patch file — no live ref available) - otherwise → abort with
Askingnaming the ambiguous arg
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 7d ago First seen · 172 lines · 100 tokens per session scan A a669d27cb892
review is a skill published in the GitHub repository griffinwork40/agent-afk (53 stars, last pushed yesterday), licensed Apache-2.0. It adds 100 tokens to every session and 6,671 once invoked, about $0.0005 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other skills, from other repositories
hunk-extensions
Maps the hunkdiff/extension authoring surface for Hunk, the terminal diff viewer — hiding or reordering reviewed files, docked panes, alternate file views, commands and key bindings, dialogs, workspace writes, themes, syntax languages, VCS backends, lifecycle events. Use when writing, debugging, or installing a Hunk…
hunk-launch-video
Produces Hunk videos by driving the real TUI headlessly in a PTY, compositing captioned 1080p frames in Chromium, and encoding with ffmpeg. Use for feature demos, workflow explainers, announcements, launch videos, and full-release roundups.
hunk-release
Prepares, publishes, verifies, and curates Hunk releases. Use for release metadata, benchmarks, tags, publishing, release videos, backports, or recovery.
hunk-review
Interacts with live Hunk diff review sessions via CLI. Inspects review focus, navigates files, hunks, and exact lines, reloads session contents, adds inline review comments, and paints attention marks on character ranges. Use when the user has a Hunk session running or wants to review diffs interactively.
md-audit
Read-only code quality audit — scan the current working directory for common issues (bugs, dead code, security hotspots, missing error handling) and return a prioritised findings report. No files are edited. Use when asked to "audit the code", "quick audit", "find issues", "code scan", or "what's wrong with this…
hatch3r-refactor
Internal code quality improvement workflow without changing external behavior. Use when refactoring code structure, simplifying modules, or improving maintainability.