Code Reviewer
jewbetcha/opentrace
Comprehensive code review skill for TypeScript, JavaScript, Python, Swift, Kotlin, Go.
Review browser userscript changes in JavaScript userscript files, focusing on scripting content and its HTML/CSS behavior, with metadata as a binding gate plus DOM/CSS, userscript-manager APIs…
$ npx skills add cyfung1031/userscript-supports --skill review-userscript-change -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install cyfung1031/userscript-supports review-userscript-change --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/cyfung1031/userscript-supports.git skills-src && mkdir -p .claude/skills && cp -r skills-src/agent-skills/review-userscript-change .claude/skills/review-userscript-change && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "review-userscript-change" agent skill from https://github.com/cyfung1031/userscript-supports/tree/main/agent-skills/review-userscript-change into .claude/skills/review-userscript-change/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "review-userscript-change", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/cyfung1031/userscript-supports/tree/main/agent-skills/review-userscript-changeType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add cyfung1031/userscript-supports --skill review-userscript-change -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install cyfung1031/userscript-supports review-userscript-change --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/cyfung1031/userscript-supports.git skills-src && mkdir -p .agents/skills && cp -r skills-src/agent-skills/review-userscript-change .agents/skills/review-userscript-change && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "review-userscript-change" agent skill from https://github.com/cyfung1031/userscript-supports/tree/main/agent-skills/review-userscript-change into .agents/skills/review-userscript-change/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "review-userscript-change", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add cyfung1031/userscript-supports --skill review-userscript-change -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install cyfung1031/userscript-supports review-userscript-change --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/cyfung1031/userscript-supports.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/agent-skills/review-userscript-change .cursor/skills/review-userscript-change && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "review-userscript-change" agent skill from https://github.com/cyfung1031/userscript-supports/tree/main/agent-skills/review-userscript-change into .cursor/skills/review-userscript-change/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "review-userscript-change", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/cyfung1031/userscript-supports.git --path agent-skills/review-userscript-change--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add cyfung1031/userscript-supports --skill review-userscript-change -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install cyfung1031/userscript-supports review-userscript-change --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/cyfung1031/userscript-supports.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/agent-skills/review-userscript-change .gemini/skills/review-userscript-change && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "review-userscript-change" agent skill from https://github.com/cyfung1031/userscript-supports/tree/main/agent-skills/review-userscript-change into .gemini/skills/review-userscript-change/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "review-userscript-change", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install cyfung1031/userscript-supports review-userscript-changeInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add cyfung1031/userscript-supports --skill review-userscript-change -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/cyfung1031/userscript-supports.git skills-src && mkdir -p .github/skills && cp -r skills-src/agent-skills/review-userscript-change .github/skills/review-userscript-change && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "review-userscript-change" agent skill from https://github.com/cyfung1031/userscript-supports/tree/main/agent-skills/review-userscript-change into .github/skills/review-userscript-change/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "review-userscript-change", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add cyfung1031/userscript-supports --skill review-userscript-change -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install cyfung1031/userscript-supports review-userscript-change --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/cyfung1031/userscript-supports.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/agent-skills/review-userscript-change .opencode/skills/review-userscript-change && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "review-userscript-change" agent skill from https://github.com/cyfung1031/userscript-supports/tree/main/agent-skills/review-userscript-change into .opencode/skills/review-userscript-change/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "review-userscript-change", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
review-userscript-changeReview browser userscript changes in JavaScript userscript files, focusing on scripting content and its HTML/CSS behavior, with metadata as a binding gate plus DOM/CSS, userscript-manager APIs…
Review Userscript Change is an agent skill from cyfung1031/userscript-supports. Review browser userscript changes in JavaScript userscript files, focusing on scripting content and its HTML/CSS behavior, with metadata as a binding gate plus DOM/CSS, userscript-manager APIs, persistence, network, security, asynchronous lifecycle, and compatibility seams. Use when reviewing a userscript file diff or pull request and the review needs exact revision binding, PickInvariant-scoped probes, deterministic simulation, and explicit runtime-evidence limits.
Its SKILL.md is about 1.8k tokens, which your agent loads only when the skill is triggered. The skill folder holds 29 other files, including scripts and reference files (for example `agents/openai.yaml`, `references/async-state.md` and `references/dom-css.md`).
It sits in Development, covering Async programming, Network security and Pull requests. It works with JavaScript. The repository describes itself as: This is for the userscripts created on GreasyFork.org. The licence is MIT.
Read from SKILL.md and the folder at commit a6a319e. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Ships 1 file in scripts/ (JavaScript, from the files we listed), which the agent can run.
Shell commands in SKILL.md call:
nodeFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Review Userscript Change loads about 1.8k tokens when it runs, and up to ~7.9k if it reads all its reference files. Until then it costs about 124 tokens; SKILL.md has 742 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.
The full file from cyfung1031/userscript-supports at commit a6a319e, republished under its MIT licence (© cyfung1031). 742 words, ~1,809 tokens.
.claude/skills/review-userscript-change/SKILL.md (or your agent's skills folder). This skill also uses 25 other files; get the full folder from GitHub.Use this small activation kernel for any userscript diff. Bind the artifact, classify its changed seams, load only the matching module references, and produce a read-only, best-effort review. The main oracle is static proof within the declared written-source and specification scope; optional browser fixtures are a last-resort partial simulation, not a guarantee. Do not assume a browser, a userscript manager, or a specific host site is available.
Use PickInvariant in PICK_AUDIT mode. Choose FOCUSED_AUDIT for one isolated semantic family and DELTA_AUDIT when the diff crosses families; use FULL_AUDIT only when completeness is explicitly required. Run SURVEY -> MAP -> CONTRAST -> PINPOINT and retain only distinctions that can change the review decision.
Record a compact activation receipt before loading modules: target and authority, base/head observables, Pick mode/depth, changed semantic families, available oracle, exclusions, and the Q_D review decision. Before a delta or full audit, load the installed PickInvariant references/audit_and_contrast.md and references/review_scope_and_coverage.md; do not reproduce their full theorem stack in this kernel.
Bind the exact base revision, head revision, changed path, and blob identities before making exact claims. Set review_skill_root to the directory containing this SKILL.md; its parent directory may be anywhere:
review_skill_root="/path/to/review-userscript-change"
node "$review_skill_root/scripts/bind_review_target.js" \
--repo /path/to/repo --base <base-ref> --head <head-ref> \
--path path/to/script.user.js --json > review-manifest.json
node "$review_skill_root/scripts/audit_userscript_change.js" \
--manifest review-manifest.json --jsonIf the head is unavailable, report INSUFFICIENT_EVIDENCE or BLOCKED_ON_ORACLE; do not substitute a synthetic fixture, a nearby commit, or an inferred patch. --source is for unit fixtures only and is always marked UNBOUND.
Run the auditor first. Load the direct reference only when its trigger appears in the changed source or diff:
@grant, @require, @run-at, @inject-into, or @sandbox -> userscript-runtime.md and gm/index.md; load gm/compatibility.md only when a manager/version-specific portability claim is in scope;GM_getValue, GM.setValue, listeners, or other storage calls -> gm/storage.md;GM_xmlhttpRequest, GM.xmlHttpRequest, or privileged HTTP -> gm/network.md;GM_addStyle, GM.addStyle, GM_addElement, or GM.addElement -> gm/dom.md;GM_info, resources, unsafeWindow, or context crossings -> gm/resources-context.md;async, await, promises, timers, observers, cancellation, retries, open/close, or teardown -> async-state.md;fetch, XHR, GM.xmlHttpRequest, storage, cache, IndexedDB, or cross-context messaging -> network-storage.md;eval, Function, innerHTML, document.write, unsafeWindow, or untrusted HTML/code boundaries -> security-boundary.md.Read evaluation-contract.md when choosing simulation cases or calibrating evidence claims. Read forward-testing.md only when validating or extending this skill. Do not load every module by default.
Metadata and syntax checks are entry gates, not the substantive review. Trace the changed scripting content from inputs through state and control flow to DOM/HTML/CSS effects, manager calls, network/storage boundaries, and cleanup. The auditor performs syntax parsing, metadata-boundary checks, duplicate-directive checks, seam classification, changed-diff routing, and base-versus-head module comparison without executing the candidate userscript. It emits audit_result, a bounded written_source_status, review_disposition, evidence tiers, and typed runtime limitations. A static pass can prove selected written-source properties for the checked scope; it is not a guarantee that every manager/browser renders, schedules, or integrates it identically.
When content behavior is difficult to execute, prefer a small deterministic harness with manager-agnostic stubs for API boundaries, DOM nodes, timers, fetch/XHR, storage, and hostile inputs. Use it to separate success, rejection, timeout, duplicate, late-result, teardown, and reinjection paths. Manager-specific references are optional and may be stale; do not block the content review or package installation on them. Do not treat a passing stub as proof of the real manager or network; retain the exact stub contract and mark integration behavior UNVERIFIED.
For every material family, choose the cheapest reachable contrast that can change acceptance: prefer a source check or deterministic fixture; use a local browser runtime only as a last-resort partial simulation; and treat the actual userscript manager as an unavailable or external oracle unless observed. For async work, simulate duplicate actions, late results, teardown, retry, and identity/generation guards. For DOM/CSS work, exercise long content, narrow viewports, scroll ownership, first paint, focus, and clipping only when a visual oracle is available. Label absent, fragile, or prospective observations UNVERIFIED.
Report the bound revision and scope, module routing, one coverage row per material semantic family, findings with source locators and reproducible states, commands and evidence tiers, unresolved limitations, and a final READY, NOT_READY, or BLOCKED_ON_ORACLE disposition. Keep audit_result, written_source_status, runtime_validation, and review_disposition separate: SOURCE_READY describes only bounded written-source checks; overall READY requires every decision-relevant runtime seam to have an available oracle. If any required manager/browser/network seam is unverified, retain SOURCE_READY where justified but set overall NOT_READY.
Do not post review comments, modify the PR, push, or install dependencies unless the user separately authorizes that outward or state-changing action.
© cyfung1031, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 25 other files (scripts, references) in agent-skills/review-userscript-change of cyfung1031/userscript-supports.
Open the folder on GitHubat commit a6a319e
Review Userscript Change next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Review Userscript Change this skillcyfung1031/userscript-supports | 121 | — | ~1.8k | Automated safety check: Pass | MIT | |
| Code Reviewerjewbetcha/opentrace | 116 | 2 repos | ~1.1k | Automated safety check: Notes | MIT | |
| Markbind Typescript MigrationMarkBind/markbind | 158 | — | ~2k | Automated safety check: Pass | MIT | |
| Coding Agentmastra-ai/mastra | 29k | — | ~2.3k | Automated safety check: Pass | Custom licence | |
| Modern JavaScript Patternswshobson/agents | 40k | 12 repos | ~548 | Automated safety check: Pass | MIT | |
| Review PRGEOLYTIX/xyz | 133 | — | ~4.1k | Automated safety check: Pass | MIT |
jewbetcha/opentrace
Comprehensive code review skill for TypeScript, JavaScript, Python, Swift, Kotlin, Go.
MarkBind/markbind
Complete guide for migrating JavaScript files to TypeScript in the MarkBind project, including the two-commit strategy, import/export syntax conversion, and best practices.
mastra-ai/mastra
Authoring playbook for building agents that write, edit, review, or refactor code.
wshobson/agents
Covers ES6+ syntax and functional patterns for refactoring older JavaScript: async/await, destructuring, spread, modules, generators and data pipelines.
GEOLYTIX/xyz
A skill your agent uses when reviewing a pull request, a branch, or uncommitted working changes in the XYZ/MAPP repository — whether the user asks to "review this PR", "check my changes before I…
honeybadger-io/honeybadger-js
Pre-submission checklist for opening pull requests in honeybadger-js.
cyfung1031/userscript-supports
Default first-line, domain-agnostic meta-reasoning control for choosing the right path.
cyfung1031/userscript-supports
Update the Greasy Fork Dark userscript's existing hard-coded // general CSS snapshot to the latest Greasy Fork application CSS while preserving the owner's dark palette, comments, selector-specific…
cyfung1031/userscript-supports
Preserve-source CSS transformation for standalone CSS and CSS embedded in JavaScript, TypeScript, HTML, or user scripts.
cyfung1031/userscript-supports
Safe authenticated GitHub pull-request publication and review.
cyfung1031/userscript-supports
Coordinate bounded subagent work for analysis, coding, review, simulation, research, and handoff tasks.
Works with
Categories
Review browser userscript changes in JavaScript userscript files, focusing on scripting content and its HTML/CSS behavior, with metadata as a binding gate plus DOM/CSS, userscript-manager APIs…. Review Userscript Change is an agent skill from cyfung1031/userscript-supports. Review browser userscript changes in JavaScript userscript files, focusing on scripting content and its HTML/CSS behavior, with metadata as a binding gate plus DOM/CSS, userscript-manager APIs, persistence, network, security, asynchronous lifecycle, and compatibility seams.
Review Userscript Change fits situations like: reviewing a userscript file diff; pull request and the review needs exact revision binding; pickInvariant-scoped probes; deterministic simulation.
Run `npx skills add cyfung1031/userscript-supports --skill review-userscript-change -a claude-code`. Or copy the skill folder (agent-skills/review-userscript-change in cyfung1031/userscript-supports) into .claude/skills/review-userscript-change in your project. Claude Code loads it when a task matches its description.
Run `npx skills add cyfung1031/userscript-supports --skill review-userscript-change -a codex`. Or copy the skill folder (agent-skills/review-userscript-change in cyfung1031/userscript-supports) into .agents/skills/review-userscript-change in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add cyfung1031/userscript-supports --skill review-userscript-change -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/review-userscript-change, .gemini/skills/review-userscript-change, .github/skills/review-userscript-change and .opencode/skills/review-userscript-change in your project.
Going by SKILL.md and its folder, Review Userscript Change needs JavaScript for the scripts in its folder and the command-line tools its instructions call (node). Our summary lists: Node.js.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.
Review Userscript Change is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 1.8k tokens (SKILL.md is roughly 7.2k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 6.1k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Review Userscript Change: Code Reviewer (jewbetcha/opentrace, 116 stars), Markbind Typescript Migration (MarkBind/markbind, 158 stars), Coding Agent (mastra-ai/mastra, 29k stars) and Modern JavaScript Patterns (wshobson/agents, 40k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
cyfung1031 (a GitHub user) maintains it in cyfung1031/userscript-supports, which has 121 GitHub stars. The repository holds 6 skills in this directory. The repository was last updated on October 8, 2026.
Source: cyfung1031/userscript-supports on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.