Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add skills/jhd3197/cachibot/code-reviewnpx skills add jhd3197/CachiBot --skill code-reviewgit clone --depth 1 https://github.com/jhd3197/CachiBotWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/jhd3197/cachibot/code-review)<a href="https://agentmods.dev/skills/jhd3197/cachibot/code-review"><img src="https://agentmods.dev/badge/skills/jhd3197/cachibot/code-review.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00056 | $0.01837 |
| Opus 5 | $0.00028 | $0.00919 |
| Sonnet 5 | $0.00011 | $0.00367 |
| Haiku 4.5 | $0.00006 | $0.00184 |
Grade A, and why
code-review scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 4d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 204 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Code Review — 8-Agent Sweep
Run a full-codebase audit of CachiBot using 8 parallel review agents. Each agent focuses on a specific quality concern and reports findings with file paths and line numbers. Results are compiled into a single dated report.
Instructions
- Note today's date for the report header.
- Spawn all 8 review agents in parallel using the Task tool (subagent_type:
Explore). Each agent scans its focus area and returns findings rated Fix, Improve, or Note. - After all agents complete, compile their findings into a single report file at
.reviews/YYYY-MM-DD-review.md(create the.reviews/directory if it doesn't exist). - Print a summary to the user with totals per severity.
Agent Definitions
1. Tina — The DRY Enforcer
Scope: cachibot/ and frontend/src/
Looks for: Duplicated logic, copy-pasted code, missed shared abstractions
- Functions or blocks that appear in 2+ files with identical or near-identical logic (same body, different name counts)
- Pydantic models in
models/that share 80%+ of their fields — candidates for a base class - Repeated inline patterns: .env read/write, response formatting, validation checks, error response construction
- React components that duplicate rendering logic instead of extracting a shared component
- Zustand stores with duplicated fetch/loading/error patterns that could use a shared factory or helper
- Constants or config values hardcoded in multiple places instead of a single source of truth
2. Marcus — The Security Auditor
Scope: Full codebase Looks for: Auth gaps, injection vectors, data leaks, OWASP top 10
- Endpoints missing auth dependencies (
Depends(get_current_user)or role checks) — every route should require auth unless explicitly public - Route guards on the frontend — can a non-admin navigate to admin pages by typing the URL directly?
- Injection risks in any string interpolation touching .env files, database queries, shell commands, or file paths
- API keys or secrets that could leak in response payloads, error messages, or logs
- CORS configuration — is it locked to expected origins or wide open?
- WebSocket auth — does the WS handshake validate tokens the same way REST endpoints do?
- Hardcoded secrets, tokens, or passwords anywhere in the codebase
- File operation paths — can user input escape the workspace sandbox?
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 4d ago First seen · 204 lines · 56 tokens per session scan A 884c03311882
code-review is a skill published in the GitHub repository jhd3197/CachiBot (19 stars, last pushed 6mo ago), licensed MIT. It adds 56 tokens to every session and 1,837 once invoked, about $0.0003 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other skills, from other repositories
docx
Use this skill whenever the user wants to create, read, edit, or manipulate Word documents (.docx files). Triggers include: any mention of 'Word doc', 'word document', '.docx', or requests to produce professional documents with formatting like tables of contents, headings, page numbers, or letterheads. Also use when…
workspace-organizing
Use whenever the agent creates, writes, moves, or renames a file in a team/delegate (shared) workspace, OR when the user asks to organize, clean up, restructure, audit, or find files in any workspace or the Vault, OR when starting a multi-file task or named project. Enforces a purpose-based folder convention (flat…
xlsx
Use this skill any time a spreadsheet file is the primary input or output. This means any task where the user wants to: open, read, edit, or fix an existing .xlsx, .xlsm, .csv, or .tsv file (e.g., adding columns, computing formulas, formatting, charting, cleaning messy data); create a new spreadsheet from scratch or…
goclaw
Use this skill when administering, operating, or debugging a GoClaw gateway through the GoClaw CLI/runtime package. It covers CLI discovery, safe command inspection, gateway health/config diagnostics, agents, skills, MCP/tools, runtime packages, credentials, traces, sessions, channels, providers, cron/jobs, and…
pptx
Use this skill any time a .pptx file is involved in any way — as input, output, or both. This includes: creating slide decks, pitch decks, or presentations; reading, parsing, or extracting text from any .pptx file (even if the extracted content will be used elsewhere, like in an email or summary); editing, modifying…
Use this skill whenever the user wants to do anything with PDF files. This includes reading or extracting text/tables from PDFs, combining or merging multiple PDFs into one, splitting PDFs apart, rotating pages, adding watermarks, creating new PDFs, filling PDF forms, encrypting/decrypting PDFs, extracting images, and…