Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add tranhieutt/software_development_department --skill code-review-checklistgit clone --depth 1 https://github.com/tranhieutt/software_development_departmentWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/tranhieutt/software_development_department/code-review-checklist)<a href="https://agentmods.dev/skills/tranhieutt/software_development_department/code-review-checklist"><img src="https://agentmods.dev/badge/skills/tranhieutt/software_development_department/code-review-checklist.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00042 | $0.00765 |
| Opus 5 | $0.00021 | $0.00382 |
| Sonnet 5 | $0.00008 | $0.00153 |
| Haiku 4.5 | $0.00004 | $0.00076 |
Grade A, and why
code-review-checklist scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 7d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 97 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Code Review Checklist
Pre-review (always start here)
- Read PR description and linked issue — understand the why
- Check CI passes before spending time on review
- Pull branch locally if logic is complex
Functionality
- Solves stated problem and meets acceptance criteria
- Edge cases: null/empty inputs, concurrent calls, network failure
- Error handling: errors caught, message doesn't expose internals
- No off-by-one, loop termination, or race conditions
Security (block if any fail)
- No SQL injection — use parameterized queries, not string concat
- No XSS — escape all user-controlled output in DOM
- No hardcoded secrets — use environment variables
- Authentication required on all protected routes
- Authorization checks presence AND ownership (not just auth)
- File uploads validated: type, size, content
// ❌ SQL injection
const q = `SELECT * FROM users WHERE email = '${email}'`;
// ✅ Parameterized
db.query("SELECT * FROM users WHERE email = $1", [email]);
// ❌ Hardcoded secret
const KEY = "sk_live_abc123";
// ✅ Env variable
const KEY = process.env.API_KEY;
if (!KEY) throw new Error("API_KEY is required");
Performance
- No N+1 queries — check ORM calls inside loops
- Database queries use indexes for filter/sort columns
- No unbounded queries — always paginate or limit
- No blocking main thread with sync I/O (Node.js)
- Caching used for repeated expensive operations
Code quality
- Names describe intent (
calculateTotalPricenotcalc) - Functions have single responsibility (< ~30 lines is a signal)
- No dead code or commented-out blocks
- DRY — no copy-paste of more than 3 lines
- Follows existing project conventions and patterns
- Abstractions are deep enough to justify themselves; thin pass-through wrappers fail the deletion test
Tests
- New behavior has test coverage
- Happy path + at least 1 failure/edge case tested
- Tests use real assertions, not just "doesn't throw"
- No brittle tests that break on unrelated changes
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 7d ago First seen · 97 lines · 42 tokens per session scan A 788b8b53781b
code-review-checklist is a skill published in the GitHub repository tranhieutt/software_development_department (72 stars, last pushed 3mo ago), licensed MIT. It adds 42 tokens to every session and 765 once invoked, about $0.0002 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other skills, from other repositories
review
Plan-aware graph-enhanced code review before merge. CRITICAL issues block merge. Use after fix/verify.
flutter-dart-code-review
Library-agnostic Flutter/Dart code review checklist covering widget best practices, state management patterns (BLoC, Riverpod, Provider, GetX, MobX, Signals), Dart idioms, performance, accessibility, security, and clean architecture.
verify-multispec
A verification workflow for major releases or large code refactors. It uses four specialist teammates to review the change, question each other’s findings, and then shut down cleanly.
verify-second-opinion
A workflow for getting a second AI review when changes affect the rules and tools that coordinate other workflows.
verify-code-review
A code-review workflow that sends a change to several independent reviewers at the same time. The reviewers work in separate contexts and return their findings to the main review.
verify-paranoid
A conditional review workflow for critical modules before a pull request, which is a proposed code change awaiting review. It uses a strict senior-engineer review for important code and skips ordinary modules.