Flowness: Skill for Claude Code

.claude/skills/meta-review/SKILL.md

meta-review is a skill for Claude Code from Towow-ai/Flowness. It costs 74 tokens per session (2,761 once invoked), scanned A, original, Apache-2.0.

A meta-reviewer that checks whether a review plan covers the right areas and gives reviewers specific standards for judging findings.

In plain words
What is it for?
Use it during review planning to assess coverage, the specificity of value criteria, and whether historical failures are represented.
Why use it?
It catches gaps in the review checklist before that checklist is used, including missing dimensions or overlooked past failure patterns.

Skill for Claude Code

Written for Claude Code: context: fork in frontmatter. Also seen: reads .claude/ paths; mentions subagents.

This is Towow-ai/Flowness's own configuration. It tells Claude Code how to work on Flowness itself, so it is not a mod to install elsewhere. Copy it as a starting point and replace the rules that are about this project. Everything Flowness configures →

Reuse

Borrowing it

Nothing to install: this file belongs to Towow-ai/Flowness. Take a copy, put it at the same path in your own repository, and replace the rules that are about this project with yours.

Copy the file
curl -O https://raw.githubusercontent.com/Towow-ai/Flowness/main/.claude/skills/meta-review/SKILL.md
Clone the repo
git clone --depth 1 https://github.com/Towow-ai/Flowness

Made for: Claude Code.

Wrote this? Show the measurements

A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.

agentmods badge for meta-review

README.md
[![agentmods](https://agentmods.dev/badge/skills/towow-ai/flowness/meta-review/github.svg)](https://agentmods.dev/skills/towow-ai/flowness/meta-review)
Your own site
<a href="https://agentmods.dev/skills/towow-ai/flowness/meta-review"><img src="https://agentmods.dev/badge/skills/towow-ai/flowness/meta-review/github.svg" alt="Measured on agentmods" height="20"></a>

Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.

agentmods 80×15 button for meta-review

Your own site · 80×15
<a href="https://agentmods.dev/skills/towow-ai/flowness/meta-review"><img src="https://agentmods.dev/badge/skills/towow-ai/flowness/meta-review.svg" alt="Reviewed on agentmods" width="80" height="20"></a>
Per session 74 Skills are progressive disclosure: only the name and description are preloaded; the body loads when the skill is used.
When invoked 2,761 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. A grade says what 26 rules found in the file — not that it is safe. Third-party audits
  • NVIDIA SkillSpector pass 7 Sept 2026
How audits are shown
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5.1 $0.00074 $0.02761
Opus 5 $0.00037 $0.01380
Sonnet 5 $0.00015 $0.00552
Haiku 4.5 $0.00007 $0.00276

Measured 12d ago against content hash 4afa2e0edcf7, method: parsed. Prices are Anthropic first-party input rates as of 2026-09-11, from the pricing page.

Security

Grade A, and why

meta-review scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 12d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

.claude/skills/meta-review/SKILL.md · 147 lines

How it starts

The opening of the file, as written. The whole thing — 147 lines — stays where its author put it; the contents beside it link to each section on GitHub.

Meta-Reviewer

tools 无 Edit / Write(V-02 物理隔离):我审 review_plan 但不直接改它——产 finding 让 design-time fork / author 改。

派发通道(给主 review session 读):派我走统一入口 ./tw fork dispatch --fork-skill-id meta-review --prompt-file <f>(T-FU-08,fail-closed + canonical 留痕;Agent 工具土法派发已被 CI 守卫封死)。prompt 里的待审 review_plan 给 canonical 原文——已落账的给投影路径(如 .towow/graph/review_plan.json),未落账的给原文件路径或逐字全文,不做手工摘要转抄(转抄损耗 会让我拿一把残缺的尺子去审,2026-07-02 已实证产出假 critical)。场景化 CLI 与 subagent 注册 路线待 owner 拍板(review 枢纽 P1 路 A/B)后升级本节。

我是谁

我不审设计内容,专门审 author 写的 review_plan 够不够——dimensions 覆盖完整吗?voi_criteria 具体吗(绑定 task context 还是泛化)?historical_failures_feed 漏了重要的吗?

我是"尺子的尺子"——review_plan 是 author-time / fix-after 的尺子,我验这把尺子本身造对了没。我只有 一条标准:每个 meta-finding 都得指名 review_plan 的哪个具体位置漏了 / 泛了,并对照一条 named error pattern 或一条历史 failure 说"这类问题这把尺子量不到"——拿不出"漏了哪个维度 / 哪条 voi 泛在 哪"的具体落点,就不是 meta-finding,是"plan 可以更全"的废话。"覆盖全了"不在我的词典里:没拿 named patterns 比对过的"全"等于没审。

我了解的判断世界

我是 falsification 角色(跟 review 一脉),但我 falsify 的不是 patch,是那把还没用的尺子—— review_plan 一旦定下,author-time / fix-after 都照它跑、不漫游,所以它漏了的维度 = 所有下游 review 都会系统性漏掉。我的活是趁它还没上场,拿"风险面 → 维度该有的映射"和"历史上栽过的 failure pattern"去对它,逼出它量不到的盲区。

判别尺(一个 meta-finding 真不真,过这几关):

  1. 强制维度漏没漏——这批改动的风险面,按 F-08b 映射该强制某维度(安全→red-team / 并发·状态机→execution-path / 跨文档·schema→consistency),plan 里有吗?漏了 = critical。 (F-08b 映射表与 F-08f schema-level 强制的真身: harness/.claude/skills/review/knowledge/risk-surface-driven-triggering.md。)
  2. voi 是泛还是具体——voi_criterion 绑到了 task 的具体 context("spec 第 X 条" / 某隐含约束), 还是写成"任何改善都算"这种等于没限制的话?完全泛化 = critical。
  3. 历史 failure 喂了没——这批触及的风险面,历史上栽过的 failure pattern 进 historical_failures_feed 了吗?关键的没喂 = author 会重蹈覆辙。
  4. 是真漏还是锦上添花——任何 plan 都能更全;我只标"量不到真盲区",不标"再加一维更保险"。

我手里有什么

  • 输入 capsule(主 review session 投喂):review_plan(design-time review_plan_creator fork 的 proposal——dimensions + voi_criteria + historical_failures_feed + known_gaps)+ 它关联的 frozen 共识 / brief / 风险面节点(判断该有哪些维度的依据)。
  • 先核原料的 provenance:capsule 里缺某字段 ≠ 原文缺该字段。拿到的 review_plan 若是转述摘要 而非 canonical 原文(落账投影 / 原文件路径 / 逐字全文),"字段缺失 / 内容泛化"类结论先向派发方 索要原文核对;索不到就标注"基于转述,provenance 未核",不判 critical。(2026-07-02 一轮转抄漏了 author_address、voi 被压成一行摘要,fork 对着损耗判出假 critical、差点驱动错误的 v2——尺子的 尺子,先核自己拿到的是不是真尺子。)
  • 能查:Read/Grep/Glob 读 F-08b 风险面→维度映射、historical_failure_by_risk_surface(这批风险 面历史上栽过什么;真身:harness/.claude/skills/review/knowledge/historical-failure-feed.md)、 概念图上 task 涉及概念 attach 的风险面(核对 plan 的风险面 enumeration 全不全)。
  • 工具就 Read/Grep/Glob/Bash,没有 Edit/Write(V-02 物理隔离)——我产 meta-finding 让 design-time fork / author 改 review_plan,不自己改。没有别的隐藏能力。

Read the full file on GitHub · 147 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 12d ago First seen · 147 lines · 74 tokens per session scan A 4afa2e0edcf7

Subscribe to this mod's changes

meta-review is a skill published in the GitHub repository Towow-ai/Flowness (102 stars, last pushed 1mo ago), licensed Apache-2.0. It adds 74 tokens to every session and 2,761 once invoked, about $0.0004 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.