Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add skills/hackbyrd/orbital-express/review-conventionsnpx skills add Hackbyrd/orbital-express --skill review-conventionsgit clone --depth 1 https://github.com/Hackbyrd/orbital-expressWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/hackbyrd/orbital-express/review-conventions)<a href="https://agentmods.dev/skills/hackbyrd/orbital-express/review-conventions"><img src="https://agentmods.dev/badge/skills/hackbyrd/orbital-express/review-conventions.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00065 | $0.01274 |
| Opus 5 | $0.00032 | $0.00637 |
| Sonnet 5 | $0.00013 | $0.00255 |
| Haiku 4.5 | $0.00006 | $0.00127 |
Grade A, and why
review-conventions scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 5d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 62 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Review against conventions (self-audit)
Run this against the files you created/changed BEFORE saying a task is done, or when reviewing a diff. Go through every applicable item; for each, point to the file:line and fix violations. The authoritative rules are docs/conventions.txt and the README — this is the fast checklist.
First run dependency-free yarn conventions:check. This self-audit remains mandatory even when the automated check passes.
Feature structure
- Plan/sign-off happened before scaffolding or edits.
- Every
app/<Feature>has complete standard structure; no model-only/table-only exceptions. Extra domain files are allowed. -
yarn repair <Feature> --dry-runwas reviewed before repair; repair did not overwrite existing files; reported wiring ambiguity was resolved manually. - Root routes/models/workers/errors rely on auto-discovery; actions live in
actions/.
Every JS file
- Header comment →
'use strict'→ env → built-ins → third-party → services → helpers → models → queues (queue.get('XQueue')instances, right after models) → consts →module.exports(before methods) → methods. - Imports ordered by increasing length; plain requires before destructured.
- Every named function closed with
// END <name>. - No
requireof a feature's ownservices/socketfrom an action it's called by (use the context object).
Actions / controllers / routes
- Action name
V{version}{Action}[By{Role}][On{Device}]; file matches. - JSDoc lists route, auth,
Roles,req.args,Success, and everyError:code. - Uses
req.args(neverreq.body/req.query); POST/GET only;req.args = valueafter Joi (type coercion). - Joi-validates args; HTTP action returns
errorResponse(req, ...)(orerrorResponseRollback(t, ...)inside a transaction); socket/task throws;catchre-throws (no manual 500). - Returned records exclude sensitive fields (
attributes: { exclude: models.x.getSensitiveData() }). - Action AND controller have JSDoc headers (route, auth,
Roles, args, Success, every Error). - Flat success
{ status, success: true, ...payload }; status 200/201/202 correct; nodatanesting. - Controller is thin (role → action →
res.status(result.status).json(result),next(error)); route is registered in the feature (root discovery is automatic). - Role/device variants are separate methods (no role
if/elsein one); pure logic extracted tohelper.js. - Generated via
yarn gen(not hand-created); existing source/test/mailer targets were not overwritten; action/task indexes are deduplicated and deterministic.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 5d ago First seen · 62 lines · 65 tokens per session scan A 38eb02ebb767
review-conventions is a skill published in the GitHub repository Hackbyrd/orbital-express (14 stars, last pushed 16d ago), licensed MIT. It adds 65 tokens to every session and 1,274 once invoked, about $0.0003 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other skills, from other repositories
systematic-debugging
Use when encountering any bug, test failure, or unexpected behavior, before proposing fixes.
local-ai-agents
Build local-first AI agents that run entirely on a developer workstation with Microsoft Foundry Local and Qwen function-calling models. Covers Small Language Models (SLMs), the OpenAI-compatible local endpoint, sandboxed local tools, local RAG with Chroma, local MCP servers, hybrid cloud/local routing, and the…
next-cache-components-adoption
Turn on Cache Components in a Next.js app and resolve the blocking routes it surfaces. Use when the user wants to enable, adopt, or migrate to Cache Components, flip the cacheComponents flag, work through a flood of blocking-prerender / instant validation errors, run the cache-components-instant-false codemod, or…
next-cache-components-optimizer
Drive a Next.js route to instant navigation by setting up an agentic loop, under Cache Components / PPR, on initial load (hard navigation) and client-side navigation (soft navigation). Encode the goal as a failing @next/playwright instant() e2e and work it to green, one verified route at a time; the shipped test then…
next-partial-prefetching-adoption
Turn on Partial Prefetching in a Next.js app and work through the insights it surfaces. Use when the user wants to enable or adopt Partial Prefetching, flip the partialPrefetching flag, opt routes in with export const prefetch = 'partial', audit Link prefetch={true} behavior, preserve existing prefetched UI with…
chronicle
Analyze Copilot session history for standup reports, usage tips, session search, and session reindexing. Use when the user asks for a standup, daily summary, usage tips, workflow recommendations, wants to search or find past sessions by keyword/file/PR, wants to reindex their session store, or asks about deleting…