code-review-action: Skill for Claude Code

.agents/skills/update-agents/SKILL.md

update-agents is a skill for Claude Code, Codex from julien777z/code-review-action. It costs 24 tokens per session (917 once invoked), scanned A, a copy of update-agents, MIT.

A workflow for adding or updating the source files that guide coding agents, including agents, skills, and rules, inside a repository's `.agents` directory.

In plain words
What is it for?
Use it to create or update an agent, skill, or rule, and to implement the related product or code fix when requested.
Why use it?
It keeps agent guidance in the expected location and can address a concrete issue that prompted the guidance change.

Skill for Claude CodeCodex

Written for no agent in particular: nothing here depends on one. Also seen: installed under .agents/ (shared by several agents); mentions Codex.

This is julien777z/code-review-action's own configuration. It tells Claude Code and Codex how to work on code-review-action itself, so it is not a mod to install elsewhere. Copy it as a starting point and replace the rules that are about this project. Everything code-review-action configures →

Reuse

Borrowing it

Nothing to install: this file belongs to julien777z/code-review-action. Take a copy, put it at the same path in your own repository, and replace the rules that are about this project with yours.

Copy the file
curl -O https://raw.githubusercontent.com/julien777z/code-review-action/main/.agents/skills/update-agents/SKILL.md
Clone the repo
git clone --depth 1 https://github.com/julien777z/code-review-action

Made for: Claude Code, Codex.

Wrote this? Show the measurements

A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.

agentmods badge for update-agents

README.md
[![agentmods](https://agentmods.dev/badge/skills/julien777z/code-review-action/update-agents.svg)](https://agentmods.dev/skills/julien777z/code-review-action/update-agents)
Your own site
<a href="https://agentmods.dev/skills/julien777z/code-review-action/update-agents"><img src="https://agentmods.dev/badge/skills/julien777z/code-review-action/update-agents.svg" alt="Measured on agentmods" height="20"></a>
Per session 24 Skills are progressive disclosure: only the name and description are preloaded; the body loads when the skill is used.
When invoked 917 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. A grade says what 26 rules found in the file — not that it is safe.
Origin 100% copy Near-identical to another mod in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5.1 $0.00024 $0.00917
Opus 5 $0.00012 $0.00458
Sonnet 5 $0.00005 $0.00183
Haiku 4.5 $0.00002 $0.00092

Measured 6d ago against content hash 6868b5678abb, method: parsed. Prices are Anthropic first-party input rates as of 2026-09-06, from the pricing page.

Security

Grade A, and why

update-agents scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 6d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

Origin

This is a copy

100% identical to update-agents — 0 lines differ, which has more behind it and is treated as the original. This page carries a canonical link to it rather than competing with it.

.agents/skills/update-agents/SKILL.md · 58 lines

How it starts

The opening of the file, as written. The whole thing — 58 lines — stays where its author put it; the contents beside it link to each section on GitHub.

Update Agents Content

Upsert .agents source-of-truth files for agents, skills, or rules based on user input.

Behavior

  1. Validate input.

    • If input is missing or empty, ask: "What should I add or update in .agents?"
  2. Identify target type and name.

    • Supported types: agent, skill, rule.
    • If the user explicitly says the type, use it.
    • If type is not explicit, infer it only when confidence is high.
    • If not confident, ask: "Should this be an agent, skill, or rule?"
  3. Include the underlying issue.

    • When the user raises a concrete issue or provides evidence such as screenshots while requesting agent guidance, update the guidance and implement the underlying product or code fix in the same task.
    • Treat the issue and evidence as requested scope, not merely as background for the .agents update.
    • Skip the underlying fix only when the user explicitly requests an instruction-only change.
  4. Resolve the agent-content target path inside .agents only.

    • agent -> .agents/agents/<name>.md
    • rule -> .agents/rules/<name>.md
    • skill -> .agents/skills/<name>/SKILL.md
    • Never read or write .cursor/*, .claude/*, .codex/*, or any other non-.agents agent or provider folder.
    • Do not manually create, update, or sync mirrored command/skill/rule files in those folders; repository automation propagates changes from .agents to Cursor, Claude, Codex, and similar targets.
    • This path restriction applies to the agent-content update, not to source changes required to fix an underlying issue from step 3.
  5. Upsert behavior.

    • If target file exists, read it completely before updating it in place with the requested changes.
    • If target file does not exist, create it with a concise structure matching existing style.
    • Place new guidance under the broadest existing subject section that fits. Use durable topic headings rather than creating a heading for one requirement.
    • Express each independent requirement once, usually as one concise bullet. Merge overlapping or synonymous guidance without losing distinct criteria or exceptions.
    • Normalize the touched file's nearby structure when needed: combine narrow sections, remove redundant wording, and order foundational guidance before specialized concerns.
    • When adding a new restriction or rule, keep the wording concise—one clear statement or bullet per idea; do not pad with redundant sentences or multiple bullets that restate the same requirement.
    • Stable guidance: Do not embed concrete repository file paths or copy code examples from the current codebase into .agents files; those go stale when files move or refactors land. Prefer generic placeholders (for example services/<name>/...), short pattern descriptions, or minimal invented examples that are not tied to live paths or current line-level code.
    • Retain examples only when they clarify a non-obvious distinction; remove examples that merely repeat the prose.
    • Keep topic-specific restrictions with their topic. Keep an existing ## Guardrails section at the bottom, and create one only for cross-cutting safety or preservation constraints.

Read the full file on GitHub · 58 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 6d ago First seen · 58 lines · 24 tokens per session scan A 6868b5678abb

Subscribe to this mod's changes

update-agents is a skill published in the GitHub repository julien777z/code-review-action (2 stars, last pushed 2d ago), licensed MIT. It adds 24 tokens to every session and 917 once invoked, about $0.0001 per session on Opus 5. A static security scan graded it A with 0 findings. It is 100% identical to update-agents, differing in 0 lines, and is treated as a copy.

Related

Other skills, from other repositories

systematic-debugging

Use when encountering any bug, test failure, or unexpected behavior, before proposing fixes.

obra/superpowers · 21 tokens

local-ai-agents

Build local-first AI agents that run entirely on a developer workstation with Microsoft Foundry Local and Qwen function-calling models. Covers Small Language Models (SLMs), the OpenAI-compatible local endpoint, sandboxed local tools, local RAG with Chroma, local MCP servers, hybrid cloud/local routing, and the…

microsoft/ai-agents-for-beginners · 200 tokens

next-cache-components-adoption

Turn on Cache Components in a Next.js app and resolve the blocking routes it surfaces. Use when the user wants to enable, adopt, or migrate to Cache Components, flip the cacheComponents flag, work through a flood of blocking-prerender / instant validation errors, run the cache-components-instant-false codemod, or…

vercel/next.js · 95 tokens

chat-pet-sprite-creation

Use when creating or changing VS Code chat pet sprite art, sprite sheets, state animations, eye treatments, Stable/Insiders variants, or pet transitions under src/vs/workbench/contrib/chat/browser/widget/media/chatPet.

microsoft/vscode · 53 tokens

cpu-profile-analysis

Analyze V8/Chrome CPU profiles (.cpuprofile) and DevTools trace files (Trace-.json). Use when: profiling performance, investigating slow functions, comparing code paths, finding bottlenecks, analyzing timeToRequest, understanding call trees from sampling profiler data, analyzing layout/paint/rendering, investigating…

microsoft/vscode · 71 tokens

insight-error-page

Write or audit an insight-kind error page for the Next.js dev overlay. Use when creating a new errors/ .mdx page, auditing an existing one, or checking that a page matches the framework fix cards. Covers page structure, title alignment, FixCard cards with Copy prompt button, code snippets, terminology verification…

vercel/next.js · 83 tokens