Borrowing it
Nothing to install: this file belongs to Smart-AI-Memory/attune-ai. Take a copy, put it at the same path in your own repository, and replace the rules that are about this project with yours.
curl -O https://raw.githubusercontent.com/Smart-AI-Memory/attune-ai/main/.agents/skills/cross-review/SKILL.mdgit clone --depth 1 https://github.com/Smart-AI-Memory/attune-aiWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/smart-ai-memory/attune-ai/cross-review)<a href="https://agentmods.dev/skills/smart-ai-memory/attune-ai/cross-review"><img src="https://agentmods.dev/badge/skills/smart-ai-memory/attune-ai/cross-review/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/smart-ai-memory/attune-ai/cross-review"><img src="https://agentmods.dev/badge/skills/smart-ai-memory/attune-ai/cross-review.svg" alt="Reviewed on agentmods" width="80" height="20"></a>- NVIDIA SkillSpector pass
What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00060 | $0.01107 |
| Opus 5 | $0.00030 | $0.00553 |
| Sonnet 5 | $0.00012 | $0.00221 |
| Haiku 4.5 | $0.00006 | $0.00111 |
Grade A, and why
cross-review scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 96 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Cross Review
IMPORTANT: Start your response by telling the user:
Cross review — one non-authoring seat reviews the real diff. Advisory only: findings inform you; they never gate anything.
Binding posture (spec requirement, not style)
Board-only ADVISORY. Never wire this skill's output into a merge
gate, CI check, exit code, or blocking path — that violates
docs/specs/cross-review/requirements.md (Binding posture). Only a
chair ruling backed by the spec's dogfood ledger can upgrade it.
What it does
Phase T2 of docs/specs/cross-review/: the moderator (this
session) resolves the current branch's diff vs its merge base
(default) or the staged diff, briefs ONE non-authoring seat with
the ACTUAL diff under an honest truncation manifest, posts the
reply to the board, renders findings as advisory items, and
appends a dogfood-ledger row. All mechanics live in
attune.roundtable.review — do not reimplement them inline.
Steps
- Spend gate: state seat + target (one line) and get a go
(session-durable, same rule as
/roundtable). An existing explicit review request is the go for that seat/target. For an explicitly requested Claude subscription review, useseat="claude", claude_auth="subscription". The launcher checks saved Pro/Max authentication in a child with API credentials removed, disables tools/custom integrations, and refuses ambiguous/API authentication. It does not raise or disable the API spend cap or modify interactive authentication. Subscription entitlement is not an invoice/overage receipt. - Run (module does target resolution, brief, invocation, lint, board post):
SEAT="codex" MODE="branch" python -c "import os, json; from attune.roundtable import Board; from attune.roundtable.review import run_review; b=None
try:
b=Board(); b.ensure_functions()
except Exception as e: print(f'board unavailable: {e}')
print(json.dumps(run_review('.', seat=os.environ['SEAT'], mode=os.environ['MODE'], board=b), ensure_ascii=False))"
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 2d ago Changed · +18 lines · +2 tokens per session c8244f44eb61
- 10d ago First seen · 78 lines · 58 tokens per session scan A 6b9e29957b53
cross-review is a skill published in the GitHub repository Smart-AI-Memory/attune-ai (10 stars, last pushed today), licensed Apache-2.0. It adds 60 tokens to every session and 1,107 once invoked, about $0.0003 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other skills, from other repositories
simplify
Review recent code changes for reuse, quality, and efficiency. Use when the user asks for a code-quality pass, requests "/simplify", or asks to audit recent changes for duplication or technical debt.
pr-reviewer
Reviews a diff or security scope read-only using evidence-tiered findings, structural and context-error rubrics, and repository review policy. Use when asked to "review my changes", "structural review", "review for AI patterns", or "security audit". For applying fixes use tidy; for UI defects use ui-design.
spawn-reviewers
Spawn and collect the reviewer fleet at stage20spawnreviewers. Consumes spawn.json.spec (the authoritative spawn spec from derive-spawn-spec / derive-static-spec), resolves GRAPHPROJECT, builds per-agent prompts from the per-agent template + role suffixes (Bug Hunter A/B, Unified Auditor, Domain Critics, Impact…
openclaw-github-dedupe
Investigate a cluster of GitHub issues and PRs, determine canonical candidates, post duplicate/related status, preserve contributor credit, and execute cleanup actions. Supports autonomous mode for provided-link-only closeout, merge/fix follow-through, changelog, and post-merge issue/PR cleanup.
pr-babysitter
Monitors or repairs an open GitHub PR: CI failures, conflicts, review threads, and merge readiness, reporting state changes. Use when asked to "watch this PR", "fix CI", "resolve conflicts", or "address review comments". For PR metadata use pr-creator; for npm release PRs use autoship.
github-commenting
How to post clean, rich, deduplicated GitHub PR review comments — suggestion blocks, multi-line anchors, markers, formatting rules. Load before posting or fixing any PR comment.