Borrowing it
Nothing to install: this file belongs to LUKAWI/super-plumber. Take a copy, put it at the same path in your own repository, and replace the rules that are about this project with yours.
curl -O https://raw.githubusercontent.com/LUKAWI/super-plumber/master/.pi/skills/plumber-review/SKILL.mdgit clone --depth 1 https://github.com/LUKAWI/super-plumberWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/lukawi/super-plumber/plumber-review)<a href="https://agentmods.dev/skills/lukawi/super-plumber/plumber-review"><img src="https://agentmods.dev/badge/skills/lukawi/super-plumber/plumber-review/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/lukawi/super-plumber/plumber-review"><img src="https://agentmods.dev/badge/skills/lukawi/super-plumber/plumber-review.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00184 | $0.01996 |
| Opus 5 | $0.00092 | $0.00998 |
| Sonnet 5 | $0.00037 | $0.00399 |
| Haiku 4.5 | $0.00018 | $0.00200 |
Grade A, and why
plumber-review scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 54 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Plumber Review — 纪律技能:节点产物的双轴交叉复核
Overview
- 定位:SP 自带纪律技能族成员(DEC-6,adr_0005)——服务图中节点的交叉复核手法,主要供三层验收成果层与
cross_reviewcheckpoint 使用:对(通常已 passed 的)节点 artifact 做第二双眼复核。无节点归属的全库审计/自由 code review 不适用本页(防蔓延:纪律技能只服务图中节点)。 - 纪律族不发 command(DEC-6 ②):触达靠触发语自动命中与节点 plan 指针,无斜杠命令、无入口编排。
- 统一入口边界:用户主动要求拷问/意图对齐时路由到 SP 自带
sp-grilling;diagnosing/prototype保留为 1.0.x 后续,本期不新增、不发命令。 - 交叉 = 复核者不是执行者:同一会话给刚写完的东西盖章不算交叉。复核者是编排方指派的另一 agent/会话。
- 本 skill 零派单权:
plumber-review只定义复核方法,绝不创建、委派或要求 subagent。它无法可靠判定当前会话在代理树中的层级,因此所有调用一律按叶子复核会话处理;独立复核的派发只能由本 skill 外持一次性、不可转授orchestrator授权的用户侧协调者直接完成,且该权限不可经本 skill 推断或继承。该协议消除 review 自身的递归触发;若宿主没有在工具层限制子会话派发,则无法把文档约束伪称为硬安全边界。 - 复核与裁决必须分离:reviewer 只做双轴取证,绝不更新 checkpoint、
verification.verdict或节点状态;独立的 Super Mario / 指定裁决者读完 reviewer 的证据后,才可裁决。纯读报告之后若没有独立裁决,就仍是未完成的审核链路。 - 铁律(手册 §8 成果层):不信报告信 artifact——直接读文件核实;execution_report 的 summary 只是线索,不是证据。
双轴(并行跑,互不污染)
| 轴 | 输入 | 只回答一个问题 |
|---|---|---|
| 规格轴(Spec) | graph_get_node 的 plan + DoD 全文 |
产物是否忠实落实了节点书?逐条 DoD 找可核验佐证;找缺失/走样、计划外夹带(干了 plan 没让干的)、看似做了但实现可疑的点 |
| 惯例轴(Standards) | 节点文件边界、仓库成文纪律(CONTEXT.md 术语、手册红线如「产物禁止手改」「先 verdict 后 passed」、测试基建既有约定) | 产物是否遵守了仓库的成文纪律?违反处引用纪律原文 + 产物位置 |
并行是外层编排,不是本 skill 的动作:需要两名独立复核者时,由用户侧协调者/编排器直接派两个叶子会话,一人只获派规格轴、一人只获派惯例轴;派单必须明写「叶子复核者:不得调用任何 subagent/delegation 工具」。每个叶子只读取这份 skill 并完成自己的一轴,因此不会再派生下一层。plumber-review 自身不因环境存在 subagent 而派人。
solo / 单轴派单:没有外层独立派发时,严格在本会话隔离两遍——先只备惯例轴输入跑完并写下结论,再开规格轴跑第二遍,绝不带着一轴的结论看另一轴;若外层明确只派一轴,则只完成该轴。两轴输入都在开工前各自备齐,中途互不互通。不得为了并行而再派 agent。
结论不合并
两轴结论分开呈现:## 规格轴、## 惯例轴 各列各的发现(每条带引用:DoD/纪律原文 + artifact 文件与引文),末行各给本轴最重问题。不跨轴合并、不再排序、不产出单一总裁决——一轴全绿另一轴有雷是完全可能的结果,分开报告才不让一轴掩盖另一轴。裁决(放行/打回/改 plan)归裁决方,不归本页。
复核者红线
- 不动图状态:reviewer 不得更新 checkpoint、execution report、
verification.verdict或节点状态,也不得代签;绝不触碰执行者已认领的源任务节点、其 checkpoint 或设计字段。发现缺陷或全部通过,都交给独立裁决者。 - 叶子不嵌套:任何复核会话都不得创建、委派、唤醒或要求另一个 agent 继续复核;只读 artifact、完成获派的一轴并把证据返还上层。需要第二轴时由本 skill 外的协调者直接安排,不能经由复核者转手。
- 检查点归属:
cross_reviewcheckpoint 的 passed/failed 由独立裁决者依据 reviewer 报告上报;若源任务需要独立审核状态,由协调者建立 review 节点或提供报告 artifact,不能让 reviewer 越权修改源任务。 - 发现本身要过安检:每条发现给出可复现的核实手法,不凭报告文本断言。
- 修复若涉及新测试/缺陷修复,修复者可参照测试先行纪律——若本环境存在 plumber-tdd 技能,按其约定执行;缺失则静默降级。
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 2d ago Changed · +1 lines · +10 tokens per session a6e82e1cf2bc
- 4d ago First seen · 53 lines · 174 tokens per session scan A e2f0480fd8ac
plumber-review is a skill published in the GitHub repository LUKAWI/super-plumber (3 stars, last pushed 2d ago), licensed MIT. It adds 184 tokens to every session and 1,996 once invoked, about $0.0009 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-09-05.
Other skills, from other repositories
autoreview
Pre-commit/ship code review: Codex default; optional Claude or Pi.
rework-rate
Measure and interpret PR rework rate — the emerging 5th DORA metric.
omh-code-review
This is a Hermes-native code-review workflow skill.
revdiff-plan
Review the last Codex assistant message (plan, analysis, or proposal) with inline annotations in a TUI overlay. Extracts the most recent response from Codex rollout files and opens it in revdiff for review and annotation. Activates on "revdiff-plan", "review plan with revdiff", "annotate plan", "review last response"…
code-reviewer
Code review specialist focused on patterns, bugs, security, and performance.
agent-teams-simplify-and-harden
Implementation + audit loop using parallel agent teams with structured simplify, harden, and document passes. Spawns implementation agents to do the work, then audit agents to find complexity, security gaps, and spec deviations, then loops until code compiles cleanly, all tests pass, and auditors find zero issues or…