Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add skills/huzaifa525/claude-code-optimizer/reviewnpx skills add huzaifa525/claude-code-optimizer --skill reviewgit clone --depth 1 https://github.com/huzaifa525/claude-code-optimizerWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/huzaifa525/claude-code-optimizer/review)<a href="https://agentmods.dev/skills/huzaifa525/claude-code-optimizer/review"><img src="https://agentmods.dev/badge/skills/huzaifa525/claude-code-optimizer/review.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00021 | $0.01176 |
| Opus 5 | $0.00010 | $0.00588 |
| Sonnet 5 | $0.00004 | $0.00235 |
| Haiku 4.5 | $0.00002 | $0.00118 |
Grade A, and why
review scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 4d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 144 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Review all current code changes using two-stage review.
Iron Law
Two stages. In order. No shortcuts. Stage 1 (Spec Compliance) MUST pass before Stage 2 (Code Quality) begins. These are different questions: "Did you build the right thing?" vs "Did you build it well?"
Stage 1: Spec Compliance
Question: Does the code do what was intended?
-
Get the diff
git diff git diff --cached -
Identify the intent — What was the goal of these changes? Check:
- Commit messages
- Related issue/PR descriptions
- task_plan.md if it exists
- Ask the user if intent is unclear
-
Verify spec compliance:
- Does the implementation match the stated goal?
- Are all requirements addressed?
- Are edge cases from the spec handled?
- Were the correct files modified (not random unrelated changes)?
- Do new features have corresponding tests?
-
Stage 1 Verdict:
- PASS — Implementation matches intent. Proceed to Stage 2.
- FAIL — Implementation misses requirements. List what's missing. STOP HERE.
Stage 2: Code Quality
Question: Is the code well-written? (Only after Stage 1 PASSES)
Read each changed file in full to understand context, then check:
Security
- Hardcoded secrets, API keys, passwords
- SQL injection, XSS, command injection
- Unsanitized user input
- Missing authentication/authorization checks
- Sensitive data in logs or error messages
Performance
- N+1 query patterns
- Missing database indexes on new columns
- Unnecessary re-renders (React)
- Large synchronous operations blocking event loop
- Missing pagination on list endpoints
- Memory leaks (unclosed resources, event listeners)
Code Quality
- Dead code or unused imports
- Duplicated logic (DRY violations)
- Functions too long (> 50 lines)
- Deeply nested conditionals (> 3 levels)
- Magic numbers or hardcoded strings
- Inconsistent naming with rest of codebase
- Missing error handling on external calls
Convention Compliance
- Does it follow existing codebase patterns?
- Consistent with CLAUDE.md rules?
- Test coverage for new code?
- Consistent file/function naming?
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 4d ago First seen · 144 lines · 21 tokens per session scan A ea90434b6953
review is a skill published in the GitHub repository huzaifa525/claude-code-optimizer (9 stars, last pushed 5mo ago), licensed MIT. It adds 21 tokens to every session and 1,176 once invoked, about $0.0001 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other skills, from other repositories
throughline
Use when the user asks to use Throughline from Codex, continue or restore Throughline memory, export read-only handoff context for a local launcher, prepare a new Codex thread handoff, summarize a captured Codex session, or check whether the Throughline Codex Stop hook captured the current session. Hide long…
critical-review
Use when you want structured feedback on a plan or document before implementation.
save
Save all session progress to status tracking files. Use when you want to checkpoint work mid-session or before ending.
code-review
Use when you want a thorough code review of files, changes, or the entire project before shipping.
implement-batch
Use when you want to implement the next batch of a plan. Handles module implementation, testing, and validation.
audit-orchestrator
Universal Pre-Scan → Analysis → Optimization → Report orchestrator for ANY project type — web apps (Astro/SvelteKit/Next), infrastructure/homelab repos, CLI tools, libraries, backend services, monorepos, data/ML projects, docs. Self-detects project type and runs the matching analysis track. Session state lives in…