Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add saffron-health/libretto --skill address-reviewgit clone --depth 1 https://github.com/saffron-health/librettoWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/saffron-health/libretto/address-review)<a href="https://agentmods.dev/skills/saffron-health/libretto/address-review"><img src="https://agentmods.dev/badge/skills/saffron-health/libretto/address-review/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/saffron-health/libretto/address-review"><img src="https://agentmods.dev/badge/skills/saffron-health/libretto/address-review.svg" alt="Reviewed on agentmods" width="80" height="20"></a>- NVIDIA SkillSpector pass
What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00021 | $0.00451 |
| Opus 5 | $0.00010 | $0.00226 |
| Sonnet 5 | $0.00004 | $0.00090 |
| Haiku 4.5 | $0.00002 | $0.00045 |
Grade A, and why
address-review scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 11d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
Copies of this mod
1 near-identical copy found in the catalogue:
- address-review — 100% identical, 0 lines differ
What it actually says
Address PR review comments systematically.
Process
-
Get review comments: Use
gh api graphqlto fetch all review threads and comments for the PR. (If a PR number is not provided in the input, look up the PR for the current branch). -
Analyze comments: Review all the feedback to understand what changes are needed
-
Address each comment systematically: For each review comment:
- Make the requested code changes
- Verify the changes fix the issue raised
- Add explanatory comments if the reviewer requested clarification
- Test changes to ensure they don't break existing functionality
-
Quality assurance: Run type-check, build, and lint to ensure all changes are correct
-
Commit and push: Stage and commit all changes with an appropriate message and push.
-
Mark comments resolved: Query PR review threads with
gh api graphqlto get thread IDs and outdated status. Resolve all addressed threads usingmutation { resolveReviewThread(input: {threadId: "THREAD_ID"}) { thread { isResolved } } }. Always resolve outdated threads.
Implementation Pattern
// Query review threads:
gh api graphql -f query='query { repository(owner: "owner", name: "repo") { pullRequest(number: N) { reviewThreads(first: 100) { nodes { id isResolved isOutdated comments { nodes { body } } } } } } }'
// Resolve thread:
gh api graphql -f query='mutation { resolveReviewThread(input: {threadId: "THREAD_ID"}) { thread { isResolved } } }'
Notes
- Only address reviews from human users; ignore bot reviews (e.g., Claude) unless explicitly requested
- Use sub-agents to handle independent review comments in parallel when possible
- Always verify changes don't introduce new issues
- If a review comment requires clarification, document the approach taken
- Focus on the specific issues raised rather than making additional changes
- Mark outdated comments as resolved automatically since they no longer apply to current code
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 11d ago First seen · 44 lines · 21 tokens per session scan A ba07c4f389ee
address-review is a skill published in the GitHub repository saffron-health/libretto (889 stars, last pushed 21d ago), licensed MIT. It adds 21 tokens to every session and 451 once invoked, about $0.0001 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other skills, from other repositories
hyperflow-audit
Hyperflow code review. Use when the user wants the current diff, a commit, branch, or PR reviewed — verbs like audit, review, "check for issues", "security check", "code review". Multi-level review (L1 quick → L5 exhaustive), writes findings to .hyperflow/audits/, then a fix-gate.
pr-review
Address feedback left on a GitHub pull request: fetch unresolved review threads, make agreed Elixir/Phoenix code fixes, reply, and resolve. Use for a PR URL/number or reviewer comments. NOT for pre-PR review, findings triage, or CI monitoring.
phx-pr-review
Address feedback left on a GitHub pull request: fetch unresolved review threads, make agreed Elixir/Phoenix code fixes, reply, and resolve. Use for a PR URL/number or reviewer comments. NOT for pre-PR review, findings triage, or CI monitoring.
pr-threshold
Track commit accumulation and trigger PR when thresholds crossed.
no-mistakes
Validate committed feature-branch changes through the no-mistakes pipeline: intent, rebase, review, test, docs, lint, push, PR, and CI. Use when the user asks to run no-mistakes, ship safely, validate before pushing, or gate a change before it reaches upstream.
code-review-github
GitHub PR workflow orchestration for code review — list PRs, post comments, apply labels, and guarded auto-merge.