Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add louisbrulenaudet/monorepo-template --skill review-syncpackgit clone --depth 1 https://github.com/louisbrulenaudet/monorepo-templateWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/louisbrulenaudet/monorepo-template/review-syncpack)<a href="https://agentmods.dev/skills/louisbrulenaudet/monorepo-template/review-syncpack"><img src="https://agentmods.dev/badge/skills/louisbrulenaudet/monorepo-template/review-syncpack/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/louisbrulenaudet/monorepo-template/review-syncpack"><img src="https://agentmods.dev/badge/skills/louisbrulenaudet/monorepo-template/review-syncpack.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00066 | $0.00966 |
| Opus 5 | $0.00033 | $0.00483 |
| Sonnet 5 | $0.00013 | $0.00193 |
| Haiku 4.5 | $0.00007 | $0.00097 |
Grade A, and why
review-syncpack scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 11d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 61 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Review syncpack
Review the syncpack setup for alignment with current official best practices - dependency specifier enforcement (catalog: vs workspace:*), version-drift detection across workspaces, and package.json hygiene automation. Your reply must be a plan of suggested changes: concise, actionable, structured - not only prose.
Invocation
Text after the slash command is additional scope/focus (e.g. "lint rules only", "formatting") - narrow the review accordingly.
Ground truth (mandatory)
Your pre-trained knowledge of syncpack may be outdated (major versions changed config shape significantly). Do not draft suggestions from memory alone.
- Resolve "syncpack" via the Context7 MCP (
resolve-library-id→query-docs) at the installed major: config file name/schema, lint rule set (specifiers,versions,semverRange), filter/sort/format options, CLI commands (lint,fix,format) and flags. - For anything Context7 lacks, use Firecrawl search/scrape restricted to the official domain (
jamiemason.github.io/syncpack) - config reference and release notes for the pinned major. - Version currency: catalog
syncpackin pnpm-workspace.yaml vs latest stable; confirm config format matches the pinned major (older JSON configs break on newer majors). - Cite the retrieved source next to every finding; label anything unverifiable as Unverified.
Scope artifacts
- syncpack config file at repo root (
.syncpackrc/syncpack.config.*- locate actual file) - Root scripts in package.json:
deps:check(syncpack lint),deps:fix(syncpack fix),deps:format(syncpack format) and their gate position insidepnpm run ci - pnpm-workspace.yaml
catalog:as the canonical source; per-package specifiers (catalog:third-party,workspace:*internal, peer-range exemptions) .claude/rules/quality/dependency-workflow documentation ↔.cursortwin
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 11d ago First seen · 61 lines · 66 tokens per session scan A f378a88e948c
review-syncpack is a skill published in the GitHub repository louisbrulenaudet/monorepo-template (19 stars, last pushed 10d ago), licensed Apache-2.0. It adds 66 tokens to every session and 966 once invoked, about $0.0003 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other skills, from other repositories
resolve-fixed-pr-comments
Verify what PR review comments have been addressed (committed/pushed OR uncommitted local changes) and resolve the threads that are genuinely fixed or no longer relevant.
review-local-changes
Review your local uncommitted working-tree changes (git diff plus untracked files) and return actionable improvement suggestions. Use before committing, when nothing has been pushed yet.
attach-review-to-pr
Add line-specific review comments to pull requests using GitHub CLI API.
critique
Comprehensive multi-perspective review using specialized judges with debate and consensus building.
review-pr
Review an existing GitHub pull request and post inline review comments on its diff. Use when the changes are on an opened PR rather than your local working tree.
load-pr-comments
Use to load open/unresolved PR review comments then aggregate them as tasks in .specs/comments/.md for parallel agents to fix.