preflight

A pre-pull-request review that combines fixed scripts with human checks to find problems before another developer reviews the changes.

In plain words
What is it for?
Use it to check a branch for test failures, version drift, new dependencies, leaked private paths, missing tests, excessive changes, and scope problems.
Why use it?
It catches failed tests, mismatched versions, unwanted dependencies, private-file leaks, and judgment-based issues early, reducing avoidable review fixes.

Skill for Claude CodeCodex

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add skills/megaprompting/torque-loop/preflight
Any agent
npx skills add Megaprompting/torque-loop --skill preflight
Clone the repo
git clone --depth 1 https://github.com/Megaprompting/torque-loop

Made for: Claude Code, Codex.

Per session 93 Skills are progressive disclosure: only the name and description are preloaded; the body loads when the skill is used.
When invoked 1,220 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.00093 $0.01220
Opus 5 $0.00046 $0.00610
Sonnet 5 $0.00019 $0.00244
Haiku 4.5 $0.00009 $0.00122

Measured yesterday against content hash fc5510eaf61e, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade A, and why

preflight scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured yesterday.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

.claude/skills/preflight/SKILL.md · 83 lines

How it starts

The opening of the file, as written. The whole thing — 83 lines — stays where its author put it; the contents beside it link to each section on GitHub.

/preflight — embarrass the branch before the reviewer does

v0.7 shipped, got reviewed, and needed a same-day PATCH-THEN-KEEP hardening pass (fog write bypassed on --json, probe invariants convention-only, gated reasons unenforced). Every one was findable before the PR. This skill is that finding pass.

The mechanizable checks live in a script, not in prose — a discipline a model has to remember to run is weak. scripts/preflight.js owns the deterministic verdicts; this skill runs it, then does the judgment the script deliberately leaves open.

Step 1 — Run the mechanical pass

npm run preflight          # or: node scripts/preflight.js [base-ref]   (default base: main)

It prints all 12 checks in a fixed shape and exits non-zero if any MECHANICAL check fails. Trust its verdict on these five — they need no judgment:

  • 1 green worldnpm test + ratchet doctor both exit 0.
  • 4 version alignment — five version fields + README examples all match.
  • 7 dependency gate — no new dependencies/devDependencies (or a Danny quote in [Unreleased]).
  • 9 leak scan — no private paths (reference/PROBLEM-STATEMENT-*, *.private.md, .lucid/, .ratchet/, .sandbox-*) and no exact private-line quotes in the diff.
  • 10 trace tags — changed durable docs (CLAUDE.md, reference/*, handoffs) carry a Traced by: tag; commits carry a Co-authored-by footer. templates/ is exempt.

A MECHANICAL FAIL is real; fix it before anything else. The script's SMALLEST PATCHES block names each fix.

Step 2 — Rule on the checks the script only gathers evidence for

The script prints these as HUMAN: lines with the candidates it found. You make the call — it cannot. Read the gathered evidence, then decide PASS/FAIL for each:

  • 2 testless change (weak signal — distrust a clean line). The script's token-grep is noisy: common identifiers match half the suite, so "has test hits" is near-meaningless. For every src/|bin/ hunk, name the specific test that fails without it. No name → FAIL.
  • 3 weakened falsifier. The script flags removed asserts / newly-loose lines in test/. Decide whether any assertion was genuinely loosened without a commit-body reason. If so → FAIL.
  • 5 prose enforcement. The script lists new must/never/requires lines in SKILL.md/README. For each, point at the CLI line that enforces it + the test proving the refusal throws, OR confirm the CHANGELOG labels it prompt-level. Unlabeled invariant → FAIL.
  • 6 diff minimality. The script catches renames + whitespace-only files (the cheap cases) and is blind to elegance-churn (the expensive one). Map every remaining hunk to the locked target yourself. Any hunk that doesn't map → FAIL: revert this hunk.
  • 8 parked-decision creep. The script lists parked loop ids and any the diff mentions. Decide whether a hunk actually implements a parked loop (a mention alone is fine). If so → FAIL.
  • 11 scope + emptiness (weak signal). For any new score/read the script surfaced, confirm it exposes a scope: field and that new rendered sections state emptiness.
  • 12 changelog. The script shows whether [Unreleased] was touched and whether a CLI-enforced/prompt-level label is present. Decide if behavior changed and the entry is adequate.

Read the full file on GitHub · 83 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. yesterday First seen · 83 lines · 93 tokens per session scan A fc5510eaf61e

Subscribe to this mod's changes

preflight is a skill published in the GitHub repository Megaprompting/torque-loop (5 stars, last pushed 1mo ago), licensed MIT. It adds 93 tokens to every session and 1,220 once invoked, about $0.0005 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.

Related

Other skills, from other repositories

new-plugin

Factory line for adding a new HAR verification plugin (like playwright or rocketsim) for any framework — research the framework docs, build the template under src/templates/plugins/, register it everywhere, validate on a real repository, and open a PR. Use when asked to add/create a plugin, plugin template, or…

os-factory/har · 89 tokens

factory-line

Factory line for executing one station of a declared multi-station program — read the installed line bundle (har line status), plan parallel work into isolated HAR slots, run the cumulative gate with har line gate, and hand off for human review. Use when asked to "run a factory line", "run the next station", "execute…

os-factory/har · 101 tokens

v1-milestone

Factory line for executing one milestone of the HAR v1.0.0 refactor (epic os-factory/har#225) — plan the wave of parallel subagents, implement each issue in its own HAR slot, ship stacked PRs, run the fixture-e2e milestone gate, and hand off for review. Use when asked to "run the next v1 milestone", "work on v1.0.0"…

os-factory/har · 110 tokens

ctx

Codebase intelligence and evidence-driven governance with the indexed ctx CLI. Use when exploring an unfamiliar repository, locating symbols or callers, checking for existing implementations, estimating change impact, enforcing architecture rules, scoring a branch, finding hotspots or duplication, or analyzing…

agentis-tools/ctx · 60 tokens

ctx

Codebase intelligence and evidence-driven governance with the indexed ctx CLI. Use when exploring an unfamiliar repository, locating symbols or callers, checking for existing implementations, estimating change impact, enforcing architecture rules, scoring a branch, finding hotspots or duplication, or analyzing…

agentis-tools/ctx · 60 tokens

golden-rss

Use when testing the rss golden build.

yusufkaraaslan/Skill_Seekers · 12 tokens