Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add Swih/mistral-mcp --skill codestral-reviewgit clone --depth 1 https://github.com/Swih/mistral-mcpWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/swih/mistral-mcp/codestral-review)<a href="https://agentmods.dev/skills/swih/mistral-mcp/codestral-review"><img src="https://agentmods.dev/badge/skills/swih/mistral-mcp/codestral-review/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/swih/mistral-mcp/codestral-review"><img src="https://agentmods.dev/badge/skills/swih/mistral-mcp/codestral-review.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00063 | $0.00589 |
| Opus 5 | $0.00032 | $0.00295 |
| Sonnet 5 | $0.00013 | $0.00118 |
| Haiku 4.5 | $0.00006 | $0.00059 |
Grade A, and why
codestral-review scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 10d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
What it actually says
Codestral code review
You drive a focused code review of a diff using the Mistral codestral-latest model.
Workflow
Step 1 — Fetch the diff
If $ARGUMENTS contains a unified diff, use it. Otherwise:
- Check
git diff --stagedfirst (most likely intent) - If empty, fall back to
git diff HEAD~1..HEAD(last commit) - If still empty, ask the user which range to review
Step 2 — Auto-detect the review focus
Inspect file paths and diff content to pick the most relevant lens:
| Signal | Focus |
|---|---|
Files touching auth/, crypto/, secrets, .env, JWT/OAuth code, SQL queries with string concat, eval, file uploads |
security |
| Hot loops, big-O changes, async/parallelism, caching layer, DB queries, benchmark files | performance |
| Public API surface: exported symbols, route handlers, schemas/contracts, breaking signature changes | api_design |
| Anything else (refactor, bug fix, feature work) | correctness |
If multiple apply, ask the user which to prioritize, or run two passes with different focus values.
Step 3 — Run the review
Call the MCP prompt codestral_review from the mistral server with:
diff: the diff from step 1focus: the lens from step 2
Pass the resulting messages to mistral_chat:
model:codestral-latesttemperature:0.2(deterministic critique)max_tokens:1500
Output format
The review must end with a verdict: ship, change-requested, or block.
Findings should be:
- Concrete: cite exact lines or token ranges from the diff
- High-signal: prefer 3 strong findings over 10 shallow ones
- No invented issues: only flag real risks visible in the diff
Examples
/mistral-mcp:codestral-review— auto-detect fromgit diff --staged/mistral-mcp:codestral-review security— force the security lens/mistral-mcp:codestral-review <diff text>— review a pasted diff
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 10d ago First seen · 57 lines · 63 tokens per session scan A 745afd3fda7e
codestral-review is a skill published in the GitHub repository Swih/mistral-mcp (15 stars, last pushed today), licensed MIT. It adds 63 tokens to every session and 589 once invoked, about $0.0003 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other skills, from other repositories
output-eval-error-analysis
Systematically review workflow traces to identify failure modes before building evaluators. Use when starting an eval project, after significant pipeline changes, or when production quality drops.
review-harness
Use when reviewing implementation work that ran through a /tmp Pi task harness. Checks contract drift, unsafe shortcuts, validation evidence, and status honesty.
fluent-development
This skill should be used when the user asks to "build a fluent app", "create a servicenow app in typescript", or mentions "servicenow sdk", "now-sdk", "fluent", "scoped app as code", or "pro-code development" — or when the working directory contains a now.config.json or .now.ts files.
code-review
Review ServiceNow server-side scripts for ES5 violations, ACL/injection/XSS issues, N+1 queries, missing setLimit/error handling, hard-coded sysids, and business-rule recursion risks.
model-context
MCP (Model Context Protocol) - Build AI-native servers with tools, resources, and prompts. TypeScript/Python SDKs for Claude Desktop integration.
skill-author
Package and validate an existing skill draft for AutoVault when its frontmatter, resources, capabilities, or admission result need review.