Getting it into your agent
It runs from inside its repository, so the clone comes first — what it calls does not travel with the file alone.
git clone --depth 1 https://github.com/Stijnman/grok-custom-skillsnpx agentmods add skills/stijnman/grok-custom-skills/skill-rubric-reviewerWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/stijnman/grok-custom-skills/skill-rubric-reviewer)<a href="https://agentmods.dev/skills/stijnman/grok-custom-skills/skill-rubric-reviewer"><img src="https://agentmods.dev/badge/skills/stijnman/grok-custom-skills/skill-rubric-reviewer/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/stijnman/grok-custom-skills/skill-rubric-reviewer"><img src="https://agentmods.dev/badge/skills/stijnman/grok-custom-skills/skill-rubric-reviewer.svg" alt="Reviewed on agentmods" width="80" height="20"></a>- NVIDIA SkillSpector pass
What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00045 | $0.00638 |
| Opus 5 | $0.00023 | $0.00319 |
| Sonnet 5 | $0.00009 | $0.00128 |
| Haiku 4.5 | $0.00005 | $0.00064 |
Grade A, and why
skill-rubric-reviewer scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 9d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 85 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Skill Rubric Reviewer
When to Use
- User says review skill or task matches this capability
- User says skill rubric or task matches this capability
- User says audit SKILL.md or task matches this capability
- User says score skill quality or task matches this capability
Pre-publish validation loop
Run before publishing any skill:
python3 scripts/check_no_private_data.py
python3 scripts/publish_safety_check.py
python3 scripts/validate_collection.py
-
validate_collection.pycompletes successfully - Description includes what, when, and Triggers
- No private emails, paths, or LAN IPs
-
hitl-approverreferenced for destructive ops
Workflow
- Read SKILL.md and any references/, scripts/, assets/.
- Score 10 dimensions (frontmatter, description, conciseness, structure, clarity, freedom, errors, disclosure, scripts, completeness) 1-5 each.
- List issues for dimensions scoring 3 or below.
- Provide before/after rewrite suggestions; apply only if user requests.
- Flag publication blockers: secrets, harmful instructions, undeclared telemetry, PII in logs.
Integrations
skill-evolverhyper-skill-testerprivacy-redactor
Error Handling
| Failure | Response |
|---|---|
| Missing SKILL.md | Report path; do not score directory without file. |
Gotchas
- Rubric inspired by Agent Skills spec; independent implementation.
Safety & Ethics (Publication-Ready)
This skill is designed for public distribution. Constraints:
- Reviews content for safety before publish; blocks skills with harmful instructions.
- No automatic submission of reviews to external services without user consent.
- Does not exfiltrate skill contents to third parties.
Prohibited actions
- No unauthorized access, malware, or harmful automation
- No silent exfiltration of data, credentials, or telemetry
- No destructive system changes without hitl-approver
- No publication of user PII or environment secrets in outputs
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 9d ago First seen · 85 lines · 45 tokens per session scan A e8b7a2907b72
skill-rubric-reviewer is a skill published in the GitHub repository Stijnman/grok-custom-skills (9 stars, last pushed 2d ago), licensed MIT. It adds 45 tokens to every session and 638 once invoked, about $0.0002 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-09-03.
Other skills, from other repositories
goal-meta-skill
A guide for turning an unclear or complex task into a reviewable /goal instruction for coding agents.
workflow-to-skill
Turn a goal and existing CLI, MCP, HTTP, API, or external workflow capabilities into one reviewable reusable Agent Skill. Use when the user asks to create or revise a workflow SKILL.md without a dedicated interface for invocation or result presentation. A webpage, UI, image, or report produced as workflow output does…
rss-digest
Collect RSS or Atom sources and produce a traceable intelligence digest through the configured Weft workflow.
workflow-docs-sync
A project-documentation synchronisation workflow for rebuilding project facts from a local Git folder, GitHub repository, or current working directory, then updating core workflow documents.
workflow-to-skill-with-surface
Create or revise one reusable workflow Skill plus an optional harness-native Prompt Surface that maps a dedicated form, Page, button set, command UI, or result view to ordinary Skill messages and Harness results. Use only when the user explicitly requests a dedicated interface for invoking the Skill or presenting its…
setup-matt-pocock-skills
A setup skill that configures engineering skills for a repository, including its issue tracker, labels, and documentation layout. A repository is the project folder managed by version control.