Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add skills/sgaabdu4/hard-eng/code-reviewnpx skills add sgaabdu4/hard-eng --skill code-reviewgit clone --depth 1 https://github.com/sgaabdu4/hard-engWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/sgaabdu4/hard-eng/code-review)<a href="https://agentmods.dev/skills/sgaabdu4/hard-eng/code-review"><img src="https://agentmods.dev/badge/skills/sgaabdu4/hard-eng/code-review.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00022 | $0.00792 |
| Opus 5 | $0.00011 | $0.00396 |
| Sonnet 5 | $0.00004 | $0.00158 |
| Haiku 4.5 | $0.00002 | $0.00079 |
Grade A, and why
code-review scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 5d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 79 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Code Review
Target
- Base = user ref → upstream merge-base →
origin/main→main. - Prove base resolves + combined committed/WIP evidence is non-empty; else
FAIL.
| Scope | Evidence |
|---|---|
| Committed | git diff <base>...HEAD + git log <base>..HEAD --oneline; commit range → each patch + cumulative diff |
| WIP | cached diff + unstaged diff + every untracked in-scope file |
- Review full hunks + nearby owners; stats/names/subjects = insufficient.
Axes
| Axis | Question |
|---|---|
| Standards | Correct + safe + maintainable + tested + repo-compliant + gate-clean? |
| Spec | Originating behavior complete + faithful + no scope creep? |
- Behavioral source exists/likely → spec.md; confirmed absent/standards-only → skip Spec + why.
- One issue affecting both axes → distinct evidence per axis; never merge/rerank.
Review
- Standards = applicable repo rules/docs; repo rules override heuristics.
- Finding = exact file:line/hunk + code fact + risk + simpler fix + confidence.
- Coverage/blast radius = apply global
AGENTS.mdEvidence contract.
| Lens | Challenge |
|---|---|
| Architecture | codebase-design; report structural contract/ownership gaps |
| Tests | test-quality; report unproven behavior/strength gaps |
| Ripple | null/empty + concurrency/timezone + permission/network + downstream |
| Security | security-review; report confirmed/unknown security evidence |
| UI | atomic-ui; report token/component/visual-SSOT gaps |
| Specialist | touched stack + performance + DevOps only |
- Smells = mystery name + duplication + data clump/primitive obsession + repeated switch + shotgun/divergent change + message chain/middle man + speculative layer.
- Also challenge = wrong owner + scattered flags + casts/nullable modes + hidden fallback + non-atomic orchestration + oversized owner + implementation-detail test.
- Required change ≠ taste; prefer deletion + owner reuse + simpler invariant.
- Gates/hooks/pre-push =
deterministic-checks; report commands/exits/reports + suppression/wiring gaps. - Required real UI proof =
e2e; absent evidence = unknown, never reviewer-inferredPASS. - Final audit = reject uncited, preference-only, overstated, duplicate, or non-actionable candidates; retain unknowns.
What ships with it
2 files beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 5d ago First seen · 79 lines · 22 tokens per session scan A ac1ca71ae6a2
code-review is a skill published in the GitHub repository sgaabdu4/hard-eng (5 stars, last pushed today), licensed MIT. It adds 22 tokens to every session and 792 once invoked, about $0.0001 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other skills, from other repositories
agent-code-analyzer
Agent skill for code-analyzer - invoke with $agent-code-analyzer.
worker-integration
Worker-Agent integration for intelligent task dispatch and performance tracking.
agui-dotnet-streaming-chat
Get started with the AG-UI .NET SDK: bootstrap and run your first streaming-chat app (client + server) with the AG-UI .NET NuGet packages (AGUI.Client, AGUI.Server, AGUI.Formatting, AGUI.Abstractions). USE FOR: which packages to install and how to wire them; constructing an AGUIChatClient against an endpoint and…
agui-dotnet-protobuf
Use the protobuf wire transport (instead of the default Server-Sent Events) for an AG-UI connection with the AG-UI .NET SDK — a compact binary event stream negotiated via the Accept header. USE FOR: making an AGUIChatClient prefer protobuf by wiring an AGUIEventStreamHandler with ProtobufEventStreamFormatter (then…
investigate-issue
Investigate a GitHub issue by fetching details, analyzing the codebase, researching documentation, and presenting an actionable implementation plan with test guidance. Use when asked to investigate, analyze, triage, or plan work for a GitHub issue. Invoked with /investigate-issue or /investigate-issue (prompts for ID).
cog-knowledge-consolidation
Build structured knowledge frameworks from scattered vault notes with source attribution.