Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add skills/soulcodex/agentic/code-review-typescriptnpx skills add soulcodex/agentic --skill code-review-typescriptgit clone --depth 1 https://github.com/soulcodex/agenticWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00071 | $0.00840 |
| Opus 5 | $0.00036 | $0.00420 |
| Sonnet 5 | $0.00014 | $0.00168 |
| Haiku 4.5 | $0.00007 | $0.00084 |
Grade A, and why
code-review-typescript scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 106 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Code Review — TypeScript
Apply TypeScript-specific linting using the checklist in this skill directory.
Step 0 — Load Project Map
Check for .agentic/project-map.md:
- If present: read it. Use the layer structure, key modules table, and non-obvious conventions it defines to orient all findings. Skip redundant filesystem exploration.
- If absent: run lightweight auto-discovery:
- Read
package.jsonto identify dependencies and scripts - Inspect
tsconfig.jsonfor strict mode settings - Detect framework (Next.js, Hono, Vue, React, etc.) from dependencies
- List top-level
src/directories - Suggest running the
project-mapskill after this review to avoid this overhead next time
- Read
Step 1 — Load Checklist
Read checklist.md in this skill directory and apply every item to the codebase.
Step 2 — Determine Scope
- If the user specifies files, review those.
- Otherwise review the current diff:
git diff HEADor staged changes. - Do not review files outside stated scope.
Step 3 — Analyze with TypeScript-specific Lenses
Work through the checklist systematically. For each issue found, note:
- File path and line number
- Risk level:
critical/high/medium/low - Description of the issue
- Why it matters
- Verifiable source reference when the finding is non-obvious
Focus particularly on:
- Type safety gaps (
any, implicitany, missing strict mode) - ESM/CJS interop issues
- Async correctness (floating promises, Promise.all misuse)
- Money/precision issues
- Domain modeling boundary violations
Step 4 — Write the Review
Output the review in this exact format:
## Code Review — TypeScript
### What Works Well
- [At least one specific positive observation with file reference]
### Findings
#### Critical
- `path/to/file.ts:42` [critical] Description. Why it must change. *Source: [TypeScript Handbook — unknown](https://www.typescriptlang.org/docs/handbook/2/functions.html#unknown)*
#### High
- `path/to/file.ts:18` [high] Description. Why it matters. *Source: ...*
#### Medium
- `path/to/file.ts:7` [medium] Description.
#### Low
- `path/to/file.ts:5` [low] Minor note.
### Suggested Improvements
[Concrete alternatives and solutions for the most impactful findings]
### Summary
[One paragraph: overall quality, main risks, merge recommendation]
What ships with it
1 file beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 2d ago First seen · 106 lines · 71 tokens per session scan A 862cef4fa022
code-review-typescript is a skill published in the GitHub repository soulcodex/agentic (10 stars, last pushed 2d ago), licensed MIT. It adds 71 tokens to every session and 840 once invoked, about $0.0004 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other skills, from other repositories
plugin-review
Review plugin quality with tiered checks and dependency scoping. Use for PR and pre-release audits.
frontmcp-guides
Tutorials, end-to-end walkthroughs, and complete reference projects for FrontMCP. Use when you want a getting-started guide, a full worked example, or to learn best practices by following a step-by-step build rather than a single API reference. Includes a beginner weather-API server (tool plus static resource, Zod…
frontmcp-testing
Use for anything about testing FrontMCP servers: writing or running unit, integration, and E2E tests and reaching the 95%+ coverage bar. Covers Jest setup and coverage gating; unit-testing a ToolContext execute() with mock context, inputs, and Zod schema validation; testing resources and prompts; in-memory testing via…
critical-review
Radical-honesty architectural review — questions code, methodology, design, and operational fitness.
comprehensive-code-review
Use when performing code review on a PR, reviewing code changes before merge, or when a GitHub code review is requested or received - orchestrates parallel sub-agents for correctness and safety review.
code-review
Comprehensive code review for security, performance, and best practices.