Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add Stanshy/AgentHub --skill pm-reviewgit clone --depth 1 https://github.com/Stanshy/AgentHubWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/stanshy/agenthub/pm-review)<a href="https://agentmods.dev/skills/stanshy/agenthub/pm-review"><img src="https://agentmods.dev/badge/skills/stanshy/agenthub/pm-review/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/stanshy/agenthub/pm-review"><img src="https://agentmods.dev/badge/skills/stanshy/agenthub/pm-review.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00014 | $0.00572 |
| Opus 5 | $0.00007 | $0.00286 |
| Sonnet 5 | $0.00003 | $0.00114 |
| Haiku 4.5 | $0.00001 | $0.00057 |
Grade A, and why
pm-review scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 9d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
What it actually says
PM Gate 審核
PM 審核 L1 提交的 Gate 回報,執行 6 項 checklist。
使用方式
/pm-review <gate-type>
參數
$0: Gate 類型(G2 / G3 / G4)
6 項 Checklist
| # | 檢查項 | 說明 |
|---|---|---|
| 1 | 交付物完整性 | Gate 要求的所有交付物是否齊全 |
| 2 | 數據正確性 | 報告中的數字是否與實際一致 |
| 3 | 驗收標準對照 | 逐項比對提案書/計畫書的驗收標準 |
| 4 | 流程合規 | 阻斷規則是否遵守、前置 Gate 是否已通過 |
| 5 | 計畫書紀錄 | 開發計畫書第 10 節是否已填寫 |
| 6 | 附帶問題 | 過程中發現的問題是否已記錄 |
執行步驟
-
讀取當前 dev-plan: 使用 Glob tool 搜尋
proposal/sprint*-dev-plan.md,取最新的,用 Read tool 讀取完整內容。 -
讀取提案書: 使用 Glob tool 搜尋
proposal/sprint*-proposal.md,取最新的,用 Read tool 讀取完整內容。 -
逐項執行 6 項 checklist
-
產出 PM 建議(供老闆決策時參考,不直接寫入 Gate 紀錄):
- 通過 — 建議老闆核准
- 駁回 — 建議老闆退回
- 附條件通過 — 建議老闆附條件核准
-
整理摘要報告供老闆決策
注意:PM 審核結果不直接寫入 dev-plan 第 10 節 Gate 紀錄。 Gate 紀錄由老闆決策後透過
/gate-record寫入,格式必須遵守 gate-record skill 的規範:| G{N} | YYYY-MM-DD | ✅ 通過 / ❌ 駁回 / ⚠️ 附條件通過 | 審核意見 |
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 9d ago First seen · 48 lines · 14 tokens per session scan A b5714062d671
pm-review is a skill published in the GitHub repository Stanshy/AgentHub (201 stars, last pushed 5mo ago), licensed MIT. It adds 14 tokens to every session and 572 once invoked, about $0.0001 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other skills, from other repositories
cross-campaign
Discover and reference other camps, projects, and files across camp boundaries. Use when the user mentions another camp or campaign by name, references work done "in another project/camp", or needs to find/copy/compare code across camps.
fest-execution
Execute active festival tasks. Use when finding the next task, marking tasks completed/blocked/reset, committing with festival traceability, advancing workflow steps, and validating sequence progress.
fest-planning
Plan and scaffold festivals. Use when creating festival/phase/sequence/task structure, enforcing naming rules, linking festivals to projects, and promoting lifecycle states.
issue-triage
3-phase issue backlog management with audit, deep analysis, and validated triage actions. Use when triaging GitHub issues, sorting bug reports, cleaning up stale tickets, or detecting duplicate issues. Args: 'all' to analyze all, issue numbers to focus (e.g. '42 57'), 'en'/'fr' for language, no arg = audit only.
camp-workitems
Find, filter, choose, create, or adopt camp work items with camp workitem, camp wi, or camp workitems. Use when a user wants current active work across intents, designs, explore notes, festivals, or tracked workflow directories; when agents need safe camp workitem --json output; or when creating/adopting tracked…
fest-methodology
Use when the user mentions festivals, the fest CLI, phases, sequences, or tasks, or when working inside a festivals/ directory. Provides the core Festival methodology model so Claude understands the planning system.