Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add skills/rtazima/claude-proj-blueprint/code-reviewnpx skills add rtazima/claude-proj-blueprint --skill code-reviewgit clone --depth 1 https://github.com/rtazima/claude-proj-blueprintWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/rtazima/claude-proj-blueprint/code-review)<a href="https://agentmods.dev/skills/rtazima/claude-proj-blueprint/code-review"><img src="https://agentmods.dev/badge/skills/rtazima/claude-proj-blueprint/code-review.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00024 | $0.00469 |
| Opus 5 | $0.00012 | $0.00234 |
| Sonnet 5 | $0.00005 | $0.00094 |
| Haiku 4.5 | $0.00002 | $0.00047 |
Grade A, and why
code-review scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 6d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
What it actually says
Code Review
Default checklist
- Correctness: does the code do what it should?
- Tests: coverage for happy path + edge cases
- Naming: descriptive variables and functions
- Security: no hardcoded secrets, inputs validated
- Performance: no N+1 queries, no unnecessary loops
- Docs: docstrings on public functions
Active spec checklist
[SPEC] Add checklist items for each active spec module:
- Compliance: legal basis documented for personal data?
- Security: OWASP Top 10 verified?
- Observability: metrics and logs instrumented?
- Scalability: performance impact assessed?
- Accessibility: WCAG verified?
- [Add per active specs]
Output format
- 🔴 Blocker — must fix before merge
- 🟡 Suggestion — recommended improvement
- 🟢 Nit — cosmetic, non-blocking
Racionalizações comuns
| Racionalização | Realidade |
|---|---|
| "É só um refactor pequeno, não precisa de review" | Refactors pequenos introduzem bugs sutis. Review sempre. |
| "Os testes passam, então o código está correto" | Testes cobrem cenários escritos. Review encontra cenários não testados. |
| "Esse padrão é idiomático, não precisa comentar" | Idiomático pra quem? Docstring em função pública é obrigatório. |
| "Performance não importa agora, é MVP" | N+1 query em MVP vira incidente em produção. Revise sempre. |
Red Flags
- Aprovou sem verificar se testes existem para os cenários alterados
- Ignorou warning de
anytype ou@ts-ignore - Não verificou se secrets estão hardcoded
- Pulou checklist de spec ativo (segurança, compliance, etc.)
References
- Conventions: see
CLAUDE.mdat the root - ADRs: see
docs/architecture/ - Specs: see
docs/specs/
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 6d ago First seen · 51 lines · 24 tokens per session scan A bc746d8cd8d1
code-review is a skill published in the GitHub repository rtazima/claude-proj-blueprint (20 stars, last pushed 3mo ago), licensed MIT. It adds 24 tokens to every session and 469 once invoked, about $0.0001 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other skills, from other repositories
sparc-methodology
SPARC (Specification, Pseudocode, Architecture, Refinement, Completion) comprehensive development methodology with multi-agent orchestration.
architecture-diagram
Dark-themed SVG architecture/cloud/infra diagrams as HTML.
studio
Architecture Studio control plane — initialize or inspect a studio workspace, create and register projects, or route an architecture/AEC task to the right agent or skill. Use when the user runs /as:studio, asks to set up or open their studio, manage its projects, or describes a task without naming a skill.
modular-skills
Build composable skill modules with hub-and-spoke loading. Use when token budget is tight.
product-image-processor
Download, resize, and remove backgrounds from product images at scale. Use when the user asks to "process product images", batch-download images from the schedule, strip backgrounds, or standardize product photos.
tool-catalog
Show the available Architecture Studio skills and their host-appropriate commands, plus Claude Code's native Architecture Studio agents. Use when the user invokes tool-catalog, asks "what can you do" or "what skills are available", or wants a directory of plugin commands. Do not use for a host's native skill-list…