Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add skills/griffinwork40/agent-framework/reviewnpx skills add griffinwork40/agent-framework --skill reviewgit clone --depth 1 https://github.com/griffinwork40/agent-frameworkWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00100 | $0.06671 |
| Opus 5 | $0.00050 | $0.03335 |
| Sonnet 5 | $0.00020 | $0.01334 |
| Haiku 4.5 | $0.00010 | $0.00667 |
Grade A, and why
review scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 3d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
This is a copy
100% identical to review — 0 lines differ, which has more behind it and is treated as the original. This page carries a canonical link to it rather than competing with it.
How it starts
The opening of the file, as written. The whole thing — 172 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Read-only — hard constraint
This skill analyzes and reports; it never mutates the repository, the PR/MR, or anything external. After you emit the merge recommendation, STOP.
Never — not for a real bug, not for a blocking defect, not even when there is no human reviewer and "someone has to fix it":
- edit, create, or delete files (no
write/edit-style mutations); git add/commit/stash/reset,git checkoutto discard changes, orgit push;gh pr comment/review/edit/merge/create, or post or edit any PR/MR body, comment, or description;- run any other write- or network-mutating shell command.
The only shell permitted is read-only inspection: git diff / git show / gh pr diff, grep / rg, and file reads — plus dispatching the review sub-agents. Resolving findings, fixing bugs, resolving merge conflicts, and "making the branch mergeable" are explicitly out of scope: a fixable defect is a finding to report (file:line + a one-line fix in the suggestion field), never a license to act.
Sub-agent contract
/contract
Skip for: lock files (package-lock.json, go.sum, yarn.lock), auto-generated files (*.generated.*), pure-docs diffs, vendored deps.
Resolve target → diff (inline). The review target argument is: $ARGUMENT (empty = review working-tree/HEAD changes). Map this argument to a diff source, then capture the diff text plus a one-line target descriptor for the triage header. Also capture the reviewed ref (branch HEAD SHA or equivalent) — this is required for citation verification later:
--staged→git diff --staged; reviewed ref =git write-tree(snapshots the staged index to a throwaway tree so citations resolve against the staged content under review, not HEAD)--heador no arg →git diff HEAD; reviewed ref =git stash create(snapshots worktree + index to a throwaway commit so citations resolve against the content under review; empty output = no local changes → fall back togit rev-parse HEAD)- arg matches
^https?://.*/pull/\d+(GitHub/GitLab PR URL) →gh pr diff <url>(orglab mr diff); reviewed ref = head SHA fromgh pr view <url> --json headRefOid -q .headRefOid; record PR title + base/head refs - arg matches
^#?\d+$(bare PR number, optionally#-prefixed) → resolve in current repo withgh pr diff <n>; reviewed ref = head SHA fromgh pr view <n> --json headRefOid -q .headRefOid; ifghis unavailable or repo has no PR matching, abort withAsking(one question: which repo/PR) - arg matches
^[0-9a-f]{7,40}$(commit SHA) →git show <sha>; reviewed ref =<sha> - arg matches a known ref (
git rev-parse --verify <arg>succeeds) →git diff <merge-base>...<arg>against the repo's default branch; reviewed ref =git rev-parse <arg> - arg is a path or
*.diff/*.patchfile → read file contents as the diff; reviewed ref =unknown (patch file — no live ref available) - otherwise → abort with
Askingnaming the ambiguous arg
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 3d ago First seen · 172 lines · 100 tokens per session scan A a669d27cb892
review is a skill published in the GitHub repository griffinwork40/agent-framework (23 stars, last pushed 8d ago), licensed Apache-2.0. It adds 100 tokens to every session and 6,671 once invoked, about $0.0005 per session on Opus 5. A static security scan graded it A with 0 findings. It is 100% identical to review, differing in 0 lines, and is treated as a copy.
Other skills, from other repositories
systematic-debugging
Use when encountering any bug, test failure, or unexpected behavior, before proposing fixes.
brainstorming
You MUST use this before any creative work - creating features, building components, adding functionality, or modifying behavior. Explores user intent, requirements and design before implementation.
auto-perf-optimize
Run agent-driven VS Code performance or memory investigations. Use when asked to launch Code OSS, automate a VS Code scenario, run the Chat memory smoke runner, capture renderer heap snapshots, take workflow screenshots, compare run summaries, or drive a repeatable scenario before heap-snapshot analysis.
chat-perf
Run chat perf benchmarks and memory leak checks against the local dev build or any published VS Code version. Use when investigating chat rendering regressions, validating perf-sensitive changes to chat UI, or checking for memory leaks in the chat response pipeline.
chat-pet-sprite-creation
Use when creating or changing VS Code chat pet sprite art, sprite sheets, state animations, eye treatments, Stable/Insiders variants, or pet transitions under src/vs/workbench/contrib/chat/browser/widget/media/chatPet.
cpu-profile-analysis
Analyze V8/Chrome CPU profiles (.cpuprofile) and DevTools trace files (Trace-.json). Use when: profiling performance, investigating slow functions, comparing code paths, finding bottlenecks, analyzing timeToRequest, understanding call trees from sampling profiler data, analyzing layout/paint/rendering, investigating…