dev-skills-review

dev-skills-review is a skill for Claude Code, Codex from RelationalAI/rai-agent-skills. It costs 48 tokens per session (2,004 once invoked), scanned A, original, Apache-2.0.

A review guide for checking whether an AI-agent skill is clear, well structured, correctly scoped, and usable on its own. It covers triggers, navigation, examples, instructions, and boundaries.

In plain words
What is it for?
Use it when creating, reviewing, or auditing skills for RAI agent projects. It helps assess prompts, examples, structure, and practical agent usability.
Why use it?
It helps find instructions that are hard for an agent to discover, follow, or adapt. It also catches missing guidance for tasks that are outside the skill’s scope.

Skill for Claude CodeCodex

Written for no agent in particular: nothing here depends on one.

Good fit Use it when creating, reviewing, or auditing skills for RAI agent projects. It helps assess prompts, examples, structure, and practical agent usability.

Compare 6 skills from other repositories ↓
Install with agentmods
npx agentmods add skills/relationalai/rai-agent-skills/dev-skills-review
Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

Any agent
npx skills add RelationalAI/rai-agent-skills --skill dev-skills-review
Clone the repo
git clone --depth 1 https://github.com/RelationalAI/rai-agent-skills

Made for: Claude Code, Codex.

Wrote this? Show the measurements

A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.

agentmods badge for dev-skills-review

README.md
[![agentmods](https://agentmods.dev/badge/skills/relationalai/rai-agent-skills/dev-skills-review/github.svg)](https://agentmods.dev/skills/relationalai/rai-agent-skills/dev-skills-review)
Your own site
<a href="https://agentmods.dev/skills/relationalai/rai-agent-skills/dev-skills-review"><img src="https://agentmods.dev/badge/skills/relationalai/rai-agent-skills/dev-skills-review/github.svg" alt="Measured on agentmods" height="20"></a>

Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.

agentmods 80×15 button for dev-skills-review

Your own site · 80×15
<a href="https://agentmods.dev/skills/relationalai/rai-agent-skills/dev-skills-review"><img src="https://agentmods.dev/badge/skills/relationalai/rai-agent-skills/dev-skills-review.svg" alt="Reviewed on agentmods" width="80" height="20"></a>
Per session 48 Skills are progressive disclosure: only the name and description are preloaded; the body loads when the skill is used.
When invoked 2,004 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. A grade says what 26 rules found in the file — not that it is safe.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5.1 $0.00048 $0.02004
Opus 5 $0.00024 $0.01002
Sonnet 5 $0.00010 $0.00401
Haiku 4.5 $0.00005 $0.00200

Measured 12d ago against content hash bc56befa2e5d, method: parsed. Prices are Anthropic first-party input rates as of 2026-09-12, from the pricing page.

Security

Grade A, and why

dev-skills-review scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 12d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

contrib/dev-skills-review/SKILL.md · 108 lines

How it starts

The opening of the file, as written. The whole thing — 108 lines — stays where its author put it; the contents beside it link to each section on GitHub.

RAI Skills Review

Litmus Test: Agent Usability

The ultimate quality gate. Everything below serves this — if an agent can't discover, navigate, adapt, and execute from the skill alone, the skill isn't done.

  • Discovery: Given a realistic user task, does the skill's description cause it to trigger (and not trigger for unrelated tasks)?
  • Navigation: Can an agent find the right section/example within the skill in 1-2 lookups (not wandering)?
  • Pattern adaptation: Given a novel problem, can an agent locate a relevant example pattern and adapt it to a new domain without hallucinating API calls?
  • Self-sufficiency: Can an agent go from skill content to working code without needing external docs, clarification, or guessing?
  • Negative test: Does the skill clearly redirect the agent when the task is out of scope (via "When NOT to use" pointers)?

Structure

  • YAML frontmatter with name and description (one line, imperative mood, trigger-ready, under 1024 characters)
  • Description answers two questions: (1) WHAT the skill covers, framed from user-intent angle not implementation mechanics; (2) WHEN Claude should invoke it, including cases where the user doesn't name the domain directly ("even if they don't mention X"). One sentence, both halves present.
  • SKILL.md at root, references/ for deep-dive, examples/ if applicable
  • ## Summary with What, When to use, When NOT to use, Overview
  • ## Quick Reference near top — tables/code blocks, not prose
  • ## Common Pitfalls table (Mistake / Cause / Fix) captures counterintuitive, environment-specific facts the agent would get wrong without being told — not generic advice
  • ## Examples table linking to example files
  • ## Reference files with "when to use" framing
  • Stability classification (v1-STABLE or v1-SENSITIVE) below title

Content Quality

  • SKILL.md body under 500 lines
  • One term per concept throughout (no synonym alternation)
  • Examples don't contradict any documented rule/pattern
  • Reference files use same API style as SKILL.md
  • Progressive disclosure: metadata (L1) -> instructions (L2) -> bundled resources (L3)
  • References one level deep from SKILL.md (no deep nesting)
  • Degrees of freedom match task fragility (narrow bridge = specific; open field = general)
  • No explaining the obvious: omit what the agent already knows (general concepts, standard libraries, common protocols) — every token should earn its place
  • Concise over exhaustive: stepwise guidance with a working example beats encyclopedic coverage — if content covers every edge case, check whether most are better left to agent judgment
  • Defaults over menus: when multiple tools/approaches apply, one is the default with brief escape hatch — not equal-weight lists of options
  • Short, generic parentheticals: keep inline "e.g." examples short and generic. Drop overly-specific example phrases unless they disambiguate a rule — when in doubt, cut them.
  • Extracted content keeps an entry point: when content moves to a reference file (line-count, depth, or scope reasons), SKILL.md retains (a) an inline summary or canonical table for the extracted topic, (b) a specific load-trigger pointer naming what's in the reference file, AND (c) a Reference Files table row. The agent must still discover the topic from SKILL.md alone.
  • Grounded, not generic: guidance reflects specific APIs, conventions, and failure modes — if a paragraph could apply to any project ("follow best practices", "handle errors appropriately"), cut or replace it with the project-specific rule it's standing in for

Read the full file on GitHub · 108 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 12d ago First seen · 108 lines · 48 tokens per session scan A bc56befa2e5d

Subscribe to this mod's changes

dev-skills-review is a skill published in the GitHub repository RelationalAI/rai-agent-skills (4 stars, last pushed 2d ago), licensed Apache-2.0. It adds 48 tokens to every session and 2,004 once invoked, about $0.0002 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.