skill-reviewer

skill-reviewer is a skill for Codex from jqaisystems/jqai-ai-skills. It costs 36 tokens per session (998 once invoked), scanned B, original, MIT.

A security checker for AI skill files and folders before you install them. It reads the instructions and metadata, looks for dangerous patterns, and returns a safety report.

In plain words
What is it for?
Use it to review a SKILL.md file or skill folder, identify security warnings, and see the exact lines that caused each warning.
Why use it?
It helps you spot risky instructions before giving a skill access to your files or tools. The check is read-only, so reviewing a skill does not change or run it.

Skill for Codex

Written for Codex: agents/openai.yaml present.

Good fit Use it to review a SKILL.md file or skill folder, identify security warnings, and see the exact lines that caused each warning.

Compare 6 skills from other repositories ↓
Install with agentmods
npx agentmods add skills/jqaisystems/jqai-ai-skills/skill-reviewer
Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

Any agent
npx skills add jqaisystems/jqai-ai-skills --skill skill-reviewer
Clone the repo
git clone --depth 1 https://github.com/jqaisystems/jqai-ai-skills

Made for: Codex.

Wrote this? Show the measurements

A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.

agentmods badge for skill-reviewer

README.md
[![agentmods](https://agentmods.dev/badge/skills/jqaisystems/jqai-ai-skills/skill-reviewer/github.svg)](https://agentmods.dev/skills/jqaisystems/jqai-ai-skills/skill-reviewer)
Your own site
<a href="https://agentmods.dev/skills/jqaisystems/jqai-ai-skills/skill-reviewer"><img src="https://agentmods.dev/badge/skills/jqaisystems/jqai-ai-skills/skill-reviewer/github.svg" alt="Measured on agentmods" height="20"></a>

Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.

agentmods 80×15 button for skill-reviewer

Your own site · 80×15
<a href="https://agentmods.dev/skills/jqaisystems/jqai-ai-skills/skill-reviewer"><img src="https://agentmods.dev/badge/skills/jqaisystems/jqai-ai-skills/skill-reviewer.svg" alt="Reviewed on agentmods" width="80" height="20"></a>
Per session 36 Skills are progressive disclosure: only the name and description are preloaded; the body loads when the skill is used.
When invoked 998 The whole file, excluding the scripts and references it only reads on demand.
Security scan B 2 findings. A grade says what 26 rules found in the file — not that it is safe.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5.1 $0.00036 $0.00998
Opus 5 $0.00018 $0.00499
Sonnet 5 $0.00007 $0.00200
Haiku 4.5 $0.00004 $0.00100

Measured 12d ago against content hash a1a2017dd7aa, method: parsed. Prices are Anthropic first-party input rates as of 2026-09-12, from the pricing page.

Security

Grade B, and why

skill-reviewer scanned grade B with 2 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 12d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Recursive force deletemediumDestructive command

rm -rf with a variable or a broad path is one typo away from removing the wrong tree.

| Destructive commands | `rm -rf`, `git reset --hard`, `git push --force`, `git clean`, `del /s`, or similar |

Downgraded: this mod is about security review, or the phrase is quoted, so it is likely naming the pattern rather than instructing it.

Makes network callslowCapability

Not a fault in itself. Listed so you know the mod talks to something, and to what.

| Data exfiltration | References to `curl`, `wget`, `WebFetch`, `WebSearch`, or any external URL that data could be sent to |
skills/skill-reviewer/SKILL.md · 115 lines

How it starts

The opening of the file, as written. The whole thing — 115 lines — stays where its author put it; the contents beside it link to each section on GitHub.

Skill Reviewer

You are a security auditor for AI skill files and skill folders. Your only job is to read the skill instructions and related metadata, analyse them for dangerous patterns, and return a structured safety report.

You are strictly read-only. You must never modify, write, execute, or delete anything.

Input

Accept a skill file or skill folder path as an argument. If the input is a folder, inspect SKILL.md and agents/openai.yaml when present. If no path is provided, ask the user for the path to review.

Step 1: Parse Structure

Read the skill and extract:

  • YAML frontmatter fields (name, description, allowed-tools, or any other keys)
  • Markdown body (everything after the closing ---)
  • Agent metadata from agents/openai.yaml, if present

Step 2: Run Security Checks

Scan the full file content against three severity tiers. For every finding, quote the exact line(s) that triggered the flag.

Critical

Check What to look for
Unrestricted Bash Skill grants or encourages open Bash access without scoping to specific safe commands
Data exfiltration References to curl, wget, WebFetch, WebSearch, or any external URL that data could be sent to
Destructive commands rm -rf, git reset --hard, git push --force, git clean, del /s, or similar
Credential harvesting Reading .env, .ssh/, .aws/, credentials, API_KEY, tokens, or secrets
System modification Writing to .bashrc, .zshrc, .profile, startup folders, crontab, or global config

High

Check What to look for
Description mismatch The stated description does not match what the instructions actually tell Claude to do
Unbounded file writes Write or Edit tool usage with no restriction to specific project paths
Hidden secondary goals Instructions buried deep in the file that add tasks unrelated to the stated purpose
Social engineering Language that disguises destructive actions as helpful (e.g. "clean up" meaning "delete")

Read the full file on GitHub · 115 lines

Files

What ships with it

1 file beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 12d ago First seen · 115 lines · 36 tokens per session scan B a1a2017dd7aa

Subscribe to this mod's changes

skill-reviewer is a skill published in the GitHub repository jqaisystems/jqai-ai-skills (3 stars, last pushed 1mo ago), licensed MIT. It adds 36 tokens to every session and 998 once invoked, about $0.0002 per session on Opus 5. A static security scan graded it B with 2 findings (recursive force delete, makes network calls). No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.

Related

Other skills, from other repositories

reins

Drive the user's real, logged-in browser from the shell via the reins CLI. Because it's their actual browser, every site is already authenticated — so you can scrape behind logins, read cookies/tokens/localStorage, watch and replay live API traffic, call a site's own API as the signed-in user, and…

karnstack/reins · 98 tokens

baoyu-youtube-transcript

A tool for downloading the written captions, subtitles, chapter information, speaker labels, and cover image from a YouTube video using its URL or ID.

JimLiu/baoyu-skills · 107 tokens

skill-curator

A Chinese-language evaluator for deciding whether developer tools and agent resources are suitable for a curated collection. It checks real repositories, installation paths, activity, duplicates, and security boundaries using evidence.

laolaoshiren/claude-code-skills-zh · 75 tokens

git-workflow

A guide for handling Git repository work safely, including status checks, branches, commits, pushes, pull requests, and rebasing. Git is a version-control system that records code changes and coordinates work between developers.

laolaoshiren/claude-code-skills-zh · 73 tokens

i18n-helper

A helper for adding internationalization, which lets software show different languages and regional text. It finds user-visible text written directly in code and moves it into language files.

laolaoshiren/claude-code-skills-zh · 33 tokens

review-plan

Review a plan by running internal reviews and a peer review in parallel and returning combined findings. Use when the user asks to "review my plan", "check my plan", "critique my plan", or wants feedback on a plan.

tobihagemann/turbo · 50 tokens