Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add tommyvo/useful-prompts --skill react-review-checklistgit clone --depth 1 https://github.com/tommyvo/useful-promptsWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/tommyvo/useful-prompts/react-review-checklist)<a href="https://agentmods.dev/skills/tommyvo/useful-prompts/react-review-checklist"><img src="https://agentmods.dev/badge/skills/tommyvo/useful-prompts/react-review-checklist/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/tommyvo/useful-prompts/react-review-checklist"><img src="https://agentmods.dev/badge/skills/tommyvo/useful-prompts/react-review-checklist.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00039 | $0.03682 |
| Opus 5.5 | $0.00016 | $0.01473 |
| Sonnet 5.5 | $0.00008 | $0.00736 |
| Haiku 4.5 | $0.00004 | $0.00368 |
Grade A, and why
react-review-checklist scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 7d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
This is a copy
86% identical to gh-pr-react-review-checklist — 233 lines differ, which has more behind it and is treated as the original. This page carries a canonical link to it rather than competing with it.
How it starts
The opening of the file, as written. The whole thing — 191 lines — stays where its author put it; the contents beside it link to each section on GitHub.
React Review Checklist
Goal
Provide a focused second-pass report for uncommitted JavaScript/TypeScript, React, and Next.js changes, checking them against the checklists below. This complements local-code-review (general correctness, security, clarity); it does not repeat that review. The report lists checklist items the developer should address.
CRITICAL: MANDATORY FIRST STEP
YOU MUST run git diff HEAD as your ABSOLUTE FIRST action before doing ANYTHING else.
- DO NOT attempt to review code from context or memory
- DO NOT skip this step under any circumstances
- DO NOT proceed to the next step without running this command first
- DO NOT assume you know what changed
If you do not run git diff HEAD first, you are failing to follow instructions.
Process
Follow these steps IN ORDER. DO NOT skip any step:
- STEP 1 - Get Changes via Git (MANDATORY): Run
git diff HEADin the terminal to retrieve ALL uncommitted changes. This is your primary source of truth for what to review. You can read existing files in the current directory for additional context if needed. - STEP 2 - Check Scope: If the diff contains no JavaScript/TypeScript files (
.js,.jsx,.ts,.tsx,.mjs,.cjs,next.config.*), output a single line saying there are no JavaScript/TypeScript changes to check, and stop. - STEP 3 - Decide Which Checklists Apply:
- TypeScript / JavaScript and Testing - always apply.
- React - apply when the changed files use React (JSX/TSX, hooks,
reactimports). - Next.js - apply only if
nextis a dependency inpackage.json(read it). Note the Next.js major version: caching and rendering defaults differ between versions, so judge caching items against the version the project uses. Apply App Router items to files underapp/; for files underpages/, apply only the router-agnostic items.
- STEP 4 - Choose Review Mode: Check the size of the diff with
git diff HEAD --shortstat. If it touches more than 15 files or more than 800 changed lines, or the user asked for subagents, use parallel subagents as described in Large Reviews: Parallel Subagents below. Otherwise, or if the user asked not to use subagents, review it yourself in a single pass. - STEP 5 - Generate The Report: Review the changes against the applicable checklists and generate the report in markdown format. Only report items that actually appear in the diff. Rate each finding in terms of priority using the emoji system. Do not save the report in the filesystem. You should only output to chat.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 7d ago First seen · 191 lines · 39 tokens per session scan A fcc184d13696
react-review-checklist is a skill published in the GitHub repository tommyvo/useful-prompts (3 stars, last pushed 7d ago), licensed Unlicense. It adds 39 tokens to every session and 3,682 once invoked, about $0.0002 per session on Opus 5.5. A static security scan graded it A with 0 findings. It is 86% identical to gh-pr-react-review-checklist, differing in 233 lines, and is treated as a copy.
Other skills, from other repositories
next-cache-components-optimizer
Drive a Next.js route to instant navigation by setting up an agentic loop, under Cache Components / PPR, on initial load (hard navigation) and client-side navigation (soft navigation). Encode the goal as a failing @next/playwright instant() e2e and work it to green, one verified route at a time; the shipped test then…
react-patterns
React 18/19 patterns including hooks discipline, server/client component boundaries, Suspense + error boundaries, form actions, data fetching, state management decision trees, and accessibility-first composition. Use when writing or reviewing React components.
next-partial-prefetching-optimizer
Optimize what selected Next.js client navigations include before the click under Partial Prefetching. Use after Cache Components and Partial Prefetching are adopted when the user wants selected URL-specific UI to be instant, wants reusable content to wait for navigation, or needs to choose between default, viewport…
compiler-commit
Use when you want to verify compiler changes and commit with the correct convention. Runs tests, lint, and format, then commits with the [compiler] or [rust-compiler] prefix.
server-side-calls
Call tRPC procedures directly from server code using t.createCallerFactory() and router.createCaller(context) for integration testing, internal server logic, and custom API endpoints. Catch TRPCError and extract HTTP status with getHTTPStatusCodeFromError(). Error handling via onError option.
compiler-port
Port a compiler pass from TypeScript to Rust. Gathers context, plans the port, implements in a subagent with test-fix loop, then reviews.