Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add skills/soulcodex/agentic/code-review-pythonnpx skills add soulcodex/agentic --skill code-review-pythongit clone --depth 1 https://github.com/soulcodex/agenticWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00059 | $0.00807 |
| Opus 5 | $0.00030 | $0.00404 |
| Sonnet 5 | $0.00012 | $0.00161 |
| Haiku 4.5 | $0.00006 | $0.00081 |
Grade A, and why
code-review-python scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured yesterday.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 105 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Code Review — Python
Apply Python-specific linting using the checklist in this skill directory.
Step 0 — Load Project Map
Check for .agentic/project-map.md:
- If present: read it. Use the layer structure, key modules table, and non-obvious conventions it defines to orient all findings. Skip redundant filesystem exploration.
- If absent: run lightweight auto-discovery:
- Read
pyproject.tomlto identify dependencies and build system - Detect framework (FastAPI, Django, Typer, etc.) from dependencies
- List top-level
src/or app directories - Suggest running the
project-mapskill after this review to avoid this overhead next time
- Read
Step 1 — Load Checklist
Read checklist.md in this skill directory and apply every item to the codebase.
Step 2 — Determine Scope
- If the user specifies files, review those.
- Otherwise review the current diff:
git diff HEADor staged changes. - Do not review files outside stated scope.
Step 3 — Analyze with Python-specific Lenses
Work through the checklist systematically. For each issue found, note:
- File path and line number
- Risk level:
critical/high/medium/low - Description of the issue
- Why it matters
- Verifiable source reference when the finding is non-obvious
Focus particularly on:
- Type annotation completeness and mypy strict mode violations
- Mutable default arguments
- Async/blocking I/O in coroutines
- Threading safety issues
- Domain modeling with dataclasses/Pydantic
Step 4 — Write the Review
Output the review in this exact format:
## Code Review — Python
### What Works Well
- [At least one specific positive observation with file reference]
### Findings
#### Critical
- `path/to/file.py:42` [critical] Description. Why it must change. *Source: [PEP 484 — Type Hints](https://peps.python.org/pep-0484/)*
#### High
- `path/to/file.py:18` [high] Description. Why it matters. *Source: ...*
#### Medium
- `path/to/file.py:7` [medium] Description.
#### Low
- `path/to/file.py:5` [low] Minor note.
### Suggested Improvements
[Concrete alternatives and solutions for the most impactful findings]
### Summary
[One paragraph: overall quality, main risks, merge recommendation]
What ships with it
1 file beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- yesterday First seen · 105 lines · 59 tokens per session scan A bd715a66f44b
code-review-python is a skill published in the GitHub repository soulcodex/agentic (10 stars, last pushed 2d ago), licensed MIT. It adds 59 tokens to every session and 807 once invoked, about $0.0003 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other skills, from other repositories
plugin-review
Review plugin quality with tiered checks and dependency scoping. Use for PR and pre-release audits.
critical-review
Radical-honesty architectural review — questions code, methodology, design, and operational fitness.
event-driven-design
When designing loosely coupled systems that react to state changes asynchronously.
webnovel-review
使用审查 Agent 评估章节质量,生成报告并写回审查指标。.
comprehensive-code-review
Use when performing code review on a PR, reviewing code changes before merge, or when a GitHub code review is requested or received - orchestrates parallel sub-agents for correctness and safety review.
fastapi-microservices-development
Comprehensive guide for building production-ready microservices with FastAPI including REST API patterns, async operations, dependency injection, and deployment strategies.