Install
$ agentstack add skill-octaviantocan-agy-review-agy-review ✓ scanned · ✓ verified — works with Claude Code, Cursor, and more.
Security review
✓ PassedNo issues found. Passed automated security review. · v0.1.0 How review works →
- ✓ Prompt-injection patterns
- ✓ Secret / credential exfiltration
- ✓ Dangerous shell & filesystem operations
- ✓ Untrusted network calls
- ✓ Known-malicious package signatures
What it can access
- ✓ Network access No
- ✓ Filesystem access No
- ✓ Shell / process execution No
- ✓ Environment & secrets No
- ✓ Dynamic code execution No
From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.
Verified badge
Passed review? Show it. Paste this badge into your README — it links to the public security report.
Reliability & compatibility
Declared compatibility
Compatibility is declared by the source manifest. End-to-end runtime verification is coming — see below.
We're building live execution health for every listing: tool-call success rate, median latency, uptime, and last-checked timestamps — measured, not self-reported. It isn't live yet, so we don't show numbers we can't stand behind.
How agent discovery & health will work →About
agy-review
Run anything past the agy CLI for a quick adversarial critique — questionable assumptions, flaws, risks, gaps, failure modes, and a SHIP/REVISE/RETHINK verdict — from a second, independent model. Use it to harden a thing before you commit to it, not to replace your own judgment.
It reviews whatever you give it — a plan or design is just one case. Also: a code change, an essay or doc, a product/architecture decision, an argument or pitch, a config, a prompt, a name, an idea. Raw code, numbered specs, prose — all fine.
What to review (arguments)
Invoked as /agy-review [text or file to review]. Interpret the argument — $ARGUMENTS — as what to critique:
- a file path → review its contents (pass it with
-f); - pasted text or an inline description → review that;
- nothing → review the most relevant artifact in the current context (e.g. the plan, draft, or decision you just produced), and state what you picked.
How to run it
One script does everything: scripts/agy-review.sh. Give it the content via stdin, a file, or an argument; add -c to say what the thing is so the critique is on-target.
# pipe content in (most common when reviewing your own draft)
printf '%s\n' "$THING" | scripts/agy-review.sh -
# from a file, with context about what it is / the goal
scripts/agy-review.sh -f design.md -c "B2B SaaS onboarding flow; must ship this sprint"
scripts/agy-review.sh -f rate-limiter.md -c "Node/Express service behind a load balancer"
It prints the critique to stdout and exits 0. Read the bullets, then weigh them — adopt the real ones, dismiss the off-base ones, and tell the user which is which.
Model
Defaults to Gemini 3.5 Flash (High) (Flash in its highest thinking mode), per preference. Override with AGY_REVIEW_MODEL="" (see agy models for exact strings) or -m.
Reading the result
The last line is VERDICT: SHIP / REVISE / RETHINK - . Treat it as input, not a verdict you must obey:
- SHIP — no blocking issues found; still skim the bullets.
- REVISE — fix the flagged issues, then proceed.
- RETHINK — it may be fundamentally off; reconsider before committing.
Always reconcile the critique with your own reasoning and the actual context. A second model is good at catching blind spots and bad at knowing your context — keep what's true, drop what isn't, and tell the user which is which.
Notes
- Needs the
agyCLI onPATH(agy --version). Missing → exit2. - The script runs
agyfrom a throwaway empty directory, so it never reads, edits, or crawls your repo — it just asksagya question and prints the answer. - Reviews typically run in ~5–20s.
- Env knobs:
AGY_REVIEW_MODEL·AGY_PRINT_TIMEOUT(2m) ·AGY_HARD_TIMEOUT(150s). - Exit codes:
0critique printed ·1usage error ·2agynot found or returned nothing.
Source & license
This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.
- Author: OctavianTocan
- Source: OctavianTocan/agy-review
- License: MIT
Install and usage instructions live in the source repository linked above.
Reviews
No reviews yet — be the first.
Write a review
Versions
- v0.1.0 Imported from the upstream source.