Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add skills/omergocmen/vibe-coder-kit/code-reviewnpx skills add omergocmen/vibe-coder-kit --skill code-reviewgit clone --depth 1 https://github.com/omergocmen/vibe-coder-kitWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00047 | $0.01763 |
| Opus 5 | $0.00023 | $0.00881 |
| Sonnet 5 | $0.00009 | $0.00353 |
| Haiku 4.5 | $0.00005 | $0.00176 |
Grade A, and why
code-review scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 191 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Code Review Skill
İki Mod
Bu skill iki farklı durumda devreye girer:
| Mod | Ne Zaman | Ne Yapar |
|---|---|---|
| A — Pre-Commit Review | Commit öncesi, kendi kendinle | Checklist çalıştır, commit'e hazır mı karar ver |
| B — Feedback Response | Başkası review yaptı, feedback geldi | Her yorumu sınıflandır, yanıtla, düzelt |
MOD A: Pre-Commit Review (Kendi Kendine)
1. Diff'i Çek ve Analiz Et
git diff HEAD # staged olmayan değişiklikler
git diff --staged # staged değişiklikler
git diff main...HEAD # branch'in tüm değişiklikleri
Her değişen dosyayı gözden geçir. PR'da yorum almak istemediğin şeyleri şimdi düzelt.
2. Checklist — Sırayla Uygula
🔴 Kritik (bunlar varsa commit yok)
- Hardcoded secret, API key, password var mı?
git grep -i "password\|secret\|api_key\|token" -- '*.ts' '*.js' '*.py' '*.env' - SQL injection vektörü var mı? (raw query + user input)
- Authentication veya authorization bypass riski var mı?
- Testler geçiyor mu?
npm test - Build kırılıyor mu?
npm run build - Başka modülleri kıran breaking change var mı? (notify et)
🟡 Önemli (bunlar varsa ya düzelt ya bilinçli geç)
- Yeni public fonksiyon/endpoint'in JSDoc veya tipi var mı?
- Hata yönetimi yapıldı mı? (try-catch, error boundary, 404/500 handling)
- Konsola debug log bırakıldı mı? (
console.log,print,debugger) - Yeni env variable varsa
.env.example'a eklendi mi? - Herhangi bir TODO veya FIXME bırakıldı mı? (bilinçliyse ticket numarası ekle)
- Code coverage düştü mü?
npm test -- --coverage - Yeni bağımlılık eklendiyse güvenlik kontrolü yapıldı mı?
npm audit
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 2d ago First seen · 191 lines · 47 tokens per session scan A 25f99305c3c0
code-review is a skill published in the GitHub repository omergocmen/vibe-coder-kit (91 stars, last pushed 2mo ago), licensed MIT. It adds 47 tokens to every session and 1,763 once invoked, about $0.0002 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other skills, from other repositories
tdd
Use for every coding task. Enforce strict TDD workflow: activate Serena, investigate first, clarify+confirm requirements, write per-task REQUIREMENTS.md in .requirements/ /, verify APIs via web search, then implement in tiny test-verified steps.
electron-desktop-builder
Converts a web app (Express, React, Vite, Next.js) into an Electron desktop app. Use when starting a new Electron project from an existing web app, when setting up electron-builder for the first time, when creating main.ts/preload.ts boilerplate, when generating icon assets, or when configuring NSIS installers.…
ai-skill-auditor
A universal, dependency-free Node.js tool to statically audit AI Skills and local agents for malicious patterns.
design
Comprehensive design skill: brand identity, design tokens, UI styling, logo generation (55 styles, Gemini or Atlas Cloud AI), corporate identity program (50 deliverables, CIP mockups), HTML presentations (Chart.js), banner design (22 styles, social/ads/web/print), icon design (15 styles, SVG, Gemini 3.1 Pro), social…
ui-styling
Create beautiful, accessible user interfaces with shadcn/ui components (built on Radix UI + Tailwind), Tailwind CSS utility-first styling, and canvas-based visual designs. Use when building user interfaces, implementing design systems, creating responsive layouts, adding accessible components (dialogs, dropdowns…
banner-design
Design banners for social media, ads, website heroes, creative assets, and print. Multiple art direction options with optional generated or supplied visuals. Actions: design, create, generate banner. Platforms: Facebook, Twitter/X, LinkedIn, YouTube, Instagram, Google Display, website hero, print. Styles: minimalist…