Borrowing it
Nothing to install: this file belongs to Oolab-labs/claude-ide-bridge. Take a copy, put it at the same path in your own repository, and replace the rules that are about this project with yours.
curl -O https://raw.githubusercontent.com/Oolab-labs/claude-ide-bridge/main/.claude/skills/ide-review/SKILL.mdgit clone --depth 1 https://github.com/Oolab-labs/claude-ide-bridgeWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/oolab-labs/claude-ide-bridge/ide-review)<a href="https://agentmods.dev/skills/oolab-labs/claude-ide-bridge/ide-review"><img src="https://agentmods.dev/badge/skills/oolab-labs/claude-ide-bridge/ide-review/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/oolab-labs/claude-ide-bridge/ide-review"><img src="https://agentmods.dev/badge/skills/oolab-labs/claude-ide-bridge/ide-review.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00044 | $0.00828 |
| Opus 5 | $0.00022 | $0.00414 |
| Sonnet 5 | $0.00009 | $0.00166 |
| Haiku 4.5 | $0.00004 | $0.00083 |
Grade A, and why
ide-review scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 10d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
Copies of this mod
1 near-identical copy found in the catalogue:
- ide-review — 100% identical, 0 lines differ
How it starts
The opening of the file, as written. The whole thing — 82 lines — stays where its author put it; the contents beside it link to each section on GitHub.
IDE PR Review Workflow
Prerequisites
- Check if the
getToolCapabilitiesMCP tool is available to you.-
Not available (no MCP tool by that name): stop and tell the user: "This skill requires the Claude IDE Bridge with a connected VS Code extension. It uses LSP tools (hover, references, call hierarchy, diagnostics) and GitHub tools for deep PR analysis.
To use this skill:
- Start the bridge:
npm run start-all(in claude-ide-bridge/) - Ensure the Claude IDE Bridge extension is installed in your IDE
- Use the
claude --idesession (not remote-control)
Alternative: use
gh pr diff <number>for a basic diff review." - Start the bridge:
-
Available: call it. If
extensionConnectedisfalse: show the same message. Iftrue: proceed.
-
Review a pull request using the IDE bridge's full code intelligence stack. Goes beyond diff reading by using LSP to understand the impact of changes.
Workflow
Phase 1: Gather PR context
- Use
githubViewPRto get PR details (title, description, author, base branch):$ARGUMENTS - Use
githubGetPRDiffto get the full diff - Use
githubListRunsto check CI status on the PR branch
Phase 2: Deep code analysis
For each changed file in the diff:
- Use
openFileto open the file at the first changed line - Use
getDiagnosticsto check for any errors or warnings in modified files - For each modified function or class:
- Use
getHoverto verify type signatures are correct - Use
findReferencesto check if callers are affected by the change - Use
getCallHierarchy(incoming) to understand who depends on modified code - Use
goToDefinitionon any new types or imports to verify they exist
- Use
- For renamed symbols:
- Use
searchWorkspaceto check for any missed references (string literals, comments, config files that LSP doesn't cover)
- Use
- For deleted code:
- Use
findReferenceson deleted exports to verify nothing still imports them
- Use
Phase 3: Run quality checks
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 10d ago First seen · 82 lines · 44 tokens per session scan A 0a1a6b79ffc8
ide-review is a skill published in the GitHub repository Oolab-labs/claude-ide-bridge (38 stars, last pushed 4mo ago), licensed MIT. It adds 44 tokens to every session and 828 once invoked, about $0.0002 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other skills, from other repositories
lsp-inspect
Full code quality audit for a file, package, or directory. Supports batch mode (directory walk with --top ranking), comparison mode (--diff for branch-only issues), severity calibration by blast radius, fix suggestions, and confidence tiers. Applies a check taxonomy (dead symbols, silent failures, error wrapping…
lsp-dead-code
Enumerate exported symbols in a file and surface those with zero references across the workspace. Use when auditing for dead code, cleaning up APIs, or checking which exports are safe to remove.
lsp-impact
Blast-radius analysis for a symbol or file — shows all callers, type supertypes/subtypes, and reference count before you change it. Use when refactoring, deleting, or changing the signature of any function, type, or method. Also accepts a file path to surface all exported-symbol impact in one shot.
lsp-concurrency-audit
Concurrency safety audit for a type or file. Maps all fields, traces which are accessed from concurrent contexts (goroutines, threads, async tasks), and flags fields that lack synchronization. Produces a field-level safety report. Language-agnostic across 4 concurrency families.
go-testing
Trigger: Go tests, go test coverage, Bubbletea teatest, golden files. Apply focused Go testing patterns.
security-review
Perform a focused security review of pending git changes to identify high-confidence security vulnerabilities with real exploitation potential. Use this skill when the user asks for a security review, security audit, vulnerability scan, or wants to check pending changes on a branch for security issues before merging.…