skill-code-review

skill-code-review is a skill for Claude Code from nyldn/claude-octopus. It costs 22 tokens per session (2,746 once invoked), scanned A, original, MIT.

A multi-provider code-review process that collects several AI perspectives and combines them into inline pull-request comments. A pull request is a proposed set of code changes awaiting review.

In plain words
What is it for?
Use it for thorough reviews of code or pull requests, with a faster mode available for staged changes, small pull requests, or quick sanity checks.
Why use it?
It exposes quality and security problems that one reviewer might miss and enforces a structured review pipeline.

Skill for Claude Code

Written for Claude Code: disable-model-invocation in frontmatter. Also seen: agent in frontmatter; names the AskUserQuestion tool; mentions Codex.

Installs and runs on its own, but its text points at files inside its plugin — anything it tells you to read at a ${CLAUDE_PLUGIN_ROOT} path is only there once the plugin is installed. Installing the plugin gets both.

Part of the octo plugin — 69 skills, 106 commands, 10 agents, 20 hooks shipped together

About the project

Claude Octopus is an orchestration project that sends research, design, and coding tasks to Claude Code and other AI model providers so their results can be compared. Developers use it for multi-model work, disagreement detection, reviews, persistent context, and an optional workflow that moves from discovery through delivery. The catalogue entries are its commands, skills, agents, instructions, hooks, plugins, and settings.

nyldn/claude-octopus · 4,045 stars · on GitHub · reddit.com

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add skills/nyldn/claude-octopus/skill-code-review
Any agent
npx skills add nyldn/claude-octopus --skill skill-code-review
Clone the repo
git clone --depth 1 https://github.com/nyldn/claude-octopus

Made for: Claude Code.

Or install octo, the plugin that ships this one along with the rest of its 69 skills, 106 commands, 10 agents, 20 hooks.

Wrote this? Show the measurements

A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.

agentmods badge for skill-code-review

README.md
[![agentmods](https://agentmods.dev/badge/skills/nyldn/claude-octopus/skill-code-review.svg)](https://agentmods.dev/skills/nyldn/claude-octopus/skill-code-review)
Your own site
<a href="https://agentmods.dev/skills/nyldn/claude-octopus/skill-code-review"><img src="https://agentmods.dev/badge/skills/nyldn/claude-octopus/skill-code-review.svg" alt="Measured on agentmods" height="20"></a>
Per session 22 Skills are progressive disclosure: only the name and description are preloaded; the body loads when the skill is used.
When invoked 2,746 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5.1 $0.00022 $0.02746
Opus 5 $0.00011 $0.01373
Sonnet 5 $0.00004 $0.00549
Haiku 4.5 $0.00002 $0.00275

Measured 6d ago against content hash fa1464be5984, method: parsed. Prices are Anthropic first-party input rates as of 2026-09-05, from the pricing page.

Security

Grade A, and why

skill-code-review scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 6d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

Origin

Copies of this mod

1 near-identical copy found in the catalogue:

.claude/skills/skill-code-review/SKILL.md · 315 lines

How it starts

The opening of the file, as written. The whole thing — 315 lines — stays where its author put it; the contents beside it link to each section on GitHub.

Code Review Skill

MANDATORY COMPLIANCE — DO NOT SKIP

When this skill is invoked, you MUST execute the multi-LLM review pipeline. You are PROHIBITED from:

  • Doing a direct single-model code review without multi-provider synthesis
  • Deciding the scope is "too broad" and narrowing it without asking the user
  • Skipping the provider check or structured review phases
  • Substituting two background Sonnet agents for the full multi-provider pipeline
  • Rationalizing "a focused audit would be more effective" — the user wants multi-LLM perspectives

Your first output line MUST be: 🐙 **CLAUDE OCTOPUS ACTIVATED** - Multi-LLM Code Review

Invokes the code-reviewer persona for thorough code analysis during the ink (deliver) phase.

Quick Mode

For fast sanity checks (staged changes, small PRs), skip the full review pipeline and run just two phases:

# Quick: grasp (consensus on scope) → tangle (parallel review)
${HOME}/.claude-octopus/plugin/scripts/orchestrate.sh grasp "[review request]"
${HOME}/.claude-octopus/plugin/scripts/orchestrate.sh tangle "[synthesized scope]"

Use quick mode when user says "check this PR", "quick review", "sanity check my changes", or for pre-commit checks. Use the full review for PRs with security/architecture impact.

Usage

# Via orchestrate.sh
${HOME}/.claude-octopus/plugin/scripts/orchestrate.sh spawn code-reviewer "Review this pull request for security issues"

# Via auto-routing (detects review intent)
${HOME}/.claude-octopus/plugin/scripts/orchestrate.sh auto "review the authentication implementation"

Capabilities

  • AI-powered code quality analysis
  • Security vulnerability detection
  • Performance optimization suggestions
  • Architecture and design pattern review
  • TDD compliance and test-first evidence review
  • Autonomous code generation risk detection
  • Best practices enforcement

Persona Reference

This skill wraps the code-reviewer persona defined in:

  • agents/personas/code-reviewer.md
  • CLI: codex-review
  • Model: gpt-5.2-codex
  • Phases: ink

Read the full file on GitHub · 315 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 6d ago First seen · 315 lines · 22 tokens per session scan A fa1464be5984

Subscribe to this mod's changes

skill-code-review is a skill published in the GitHub repository nyldn/claude-octopus (4,045 stars, last pushed today), licensed MIT. It adds 22 tokens to every session and 2,746 once invoked, about $0.0001 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.

Related

Other skills, from other repositories

ai-context

Generates, updates, and audits AGENTS-first AI IDE context files. Builds canonical AGENTS.md plus thin bridges for Claude Code, Cursor (modern .cursor/rules/.mdc), Copilot, Cline (.clinerules/ directory), Windsurf, Gemini CLI, Codex CLI, and OpenCode. Use for creating, regenerating, fixing, or promoting context files…

littlebearapps/contextdocs · 86 tokens

architecture

This skill should be used when managing Architecture Decision Records or C4 diagrams.

jikig-ai/soleur · 17 tokens

linear-fetch

This skill should be used when a user input contains a Linear issue reference (e.g., SOL-39 or linear.app/.../issue/ ) and the downstream agent needs the screenshots embedded in the issue as visual context.

jikig-ai/soleur · 48 tokens

kb-search

This skill should be used when searching the knowledge base for files matching keywords or YAML frontmatter facets (tag, category) across domains.

jikig-ai/soleur · 30 tokens

legal-generate

This skill should be used when generating draft legal documents for a project or company. It gathers company context interactively, invokes the legal-document-generator agent, and writes markdown output.

jikig-ai/soleur · 39 tokens

growth-strategist

Use this agent when you need content strategy analysis including keyword research, content auditing for search intent alignment, content gap analysis, and GEO/AEO auditing at the content level. Use seo-aeo-analyst for technical SEO audits; use competitive-intelligence for strategic competitor monitoring; use…

jikig-ai/soleur · 78 tokens