Agent skill

Review Userscript Change

by cyfung1031 in cyfung1031/userscript-supports

Review browser userscript changes in JavaScript userscript files, focusing on scripting content and its HTML/CSS behavior, with metadata as a binding gate plus DOM/CSS, userscript-manager APIs…

MITAuto-check passedDevelopment

Install Review Userscript Change

skills CLI
$ npx skills add cyfung1031/userscript-supports --skill review-userscript-change -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install cyfung1031/userscript-supports review-userscript-change --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/cyfung1031/userscript-supports.git skills-src && mkdir -p .claude/skills && cp -r skills-src/agent-skills/review-userscript-change .claude/skills/review-userscript-change && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
review-userscript-change
GitHub stars
121
Token cost
~1.8k tokens
SKILL.md length
742 words
Files
26 (incl. scripts, references)
Skills in repo
6
Repo updated
First seen
Licence
MIT

At a glance

Review browser userscript changes in JavaScript userscript files, focusing on scripting content and its HTML/CSS behavior, with metadata as a binding gate plus DOM/CSS, userscript-manager APIs…

  • Reviewing a userscript file diff
  • SKILL.md covers Activate and bind, Route only the material modules, Audit and simulate and Report and stop
  • Runs JavaScript scripts from its folder; calls node
  • Pull request and the review needs exact revision binding

What it does

Review Userscript Change is an agent skill from cyfung1031/userscript-supports. Review browser userscript changes in JavaScript userscript files, focusing on scripting content and its HTML/CSS behavior, with metadata as a binding gate plus DOM/CSS, userscript-manager APIs, persistence, network, security, asynchronous lifecycle, and compatibility seams. Use when reviewing a userscript file diff or pull request and the review needs exact revision binding, PickInvariant-scoped probes, deterministic simulation, and explicit runtime-evidence limits.

Its SKILL.md is about 1.8k tokens, which your agent loads only when the skill is triggered. The skill folder holds 29 other files, including scripts and reference files (for example `agents/openai.yaml`, `references/async-state.md` and `references/dom-css.md`).

It sits in Development, covering Async programming, Network security and Pull requests. It works with JavaScript. The repository describes itself as: This is for the userscripts created on GreasyFork.org. The licence is MIT.

When your agent uses it

  • Reviewing a userscript file diff
  • Pull request and the review needs exact revision binding
  • PickInvariant-scoped probes
  • Deterministic simulation

Example prompts

  • “/review-userscript-change”

Requirements

  • Node.js

What it can do on your machine

Read from SKILL.md and the folder at commit a6a319e. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (JavaScript, from the files we listed), which the agent can run.

    Shell commands in SKILL.md call:

    • node

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Review Userscript Change loads about 1.8k tokens when it runs, and up to ~7.9k if it reads all its reference files. Until then it costs about 124 tokens; SKILL.md has 742 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~124
When it runs · the whole SKILL.md, loaded when a task matches
~1.8k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~7.9k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from cyfung1031/userscript-supports at commit a6a319e, republished under its MIT licence (© cyfung1031). 742 words, ~1,809 tokens.

Download SKILL.mdSave it as .claude/skills/review-userscript-change/SKILL.md (or your agent's skills folder). This skill also uses 25 other files; get the full folder from GitHub.
name
review-userscript-change
description
Review browser userscript changes in JavaScript userscript files, focusing on scripting content and its HTML/CSS behavior, with metadata as a binding gate plus DOM/CSS, userscript-manager APIs, persistence, network, security, asynchronous lifecycle, and compatibility seams. Use when reviewing a userscript file diff or pull request and the review needs exact revision binding, PickInvariant-scoped probes, deterministic simulation, and explicit runtime-evidence limits.

Review userscript changes

Use this small activation kernel for any userscript diff. Bind the artifact, classify its changed seams, load only the matching module references, and produce a read-only, best-effort review. The main oracle is static proof within the declared written-source and specification scope; optional browser fixtures are a last-resort partial simulation, not a guarantee. Do not assume a browser, a userscript manager, or a specific host site is available.

Activate and bind

Use PickInvariant in PICK_AUDIT mode. Choose FOCUSED_AUDIT for one isolated semantic family and DELTA_AUDIT when the diff crosses families; use FULL_AUDIT only when completeness is explicitly required. Run SURVEY -> MAP -> CONTRAST -> PINPOINT and retain only distinctions that can change the review decision.

Record a compact activation receipt before loading modules: target and authority, base/head observables, Pick mode/depth, changed semantic families, available oracle, exclusions, and the Q_D review decision. Before a delta or full audit, load the installed PickInvariant references/audit_and_contrast.md and references/review_scope_and_coverage.md; do not reproduce their full theorem stack in this kernel.

Bind the exact base revision, head revision, changed path, and blob identities before making exact claims. Set review_skill_root to the directory containing this SKILL.md; its parent directory may be anywhere:

bash
review_skill_root="/path/to/review-userscript-change"
node "$review_skill_root/scripts/bind_review_target.js" \
  --repo /path/to/repo --base <base-ref> --head <head-ref> \
  --path path/to/script.user.js --json > review-manifest.json
node "$review_skill_root/scripts/audit_userscript_change.js" \
  --manifest review-manifest.json --json

If the head is unavailable, report INSUFFICIENT_EVIDENCE or BLOCKED_ON_ORACLE; do not substitute a synthetic fixture, a nearby commit, or an inferred patch. --source is for unit fixtures only and is always marked UNBOUND.

Route only the material modules

Run the auditor first. Load the direct reference only when its trigger appears in the changed source or diff:

  • userscript metadata, @grant, @require, @run-at, @inject-into, or @sandbox -> userscript-runtime.md and gm/index.md; load gm/compatibility.md only when a manager/version-specific portability claim is in scope;
  • GM_getValue, GM.setValue, listeners, or other storage calls -> gm/storage.md;
  • GM_xmlhttpRequest, GM.xmlHttpRequest, or privileged HTTP -> gm/network.md;
  • GM_addStyle, GM.addStyle, GM_addElement, or GM.addElement -> gm/dom.md;
  • menu commands, notifications, clipboard, tabs, or downloads -> gm/ui.md;
  • GM_info, resources, unsafeWindow, or context crossings -> gm/resources-context.md;
  • DOM, event listeners, observers, injected markup, styles, layout, or theme/appearance -> dom-css.md;
  • async, await, promises, timers, observers, cancellation, retries, open/close, or teardown -> async-state.md;
  • fetch, XHR, GM.xmlHttpRequest, storage, cache, IndexedDB, or cross-context messaging -> network-storage.md;
  • eval, Function, innerHTML, document.write, unsafeWindow, or untrusted HTML/code boundaries -> security-boundary.md.

Read evaluation-contract.md when choosing simulation cases or calibrating evidence claims. Read forward-testing.md only when validating or extending this skill. Do not load every module by default.

Show full SKILL.md (366 more words)Show less

Audit and simulate

Metadata and syntax checks are entry gates, not the substantive review. Trace the changed scripting content from inputs through state and control flow to DOM/HTML/CSS effects, manager calls, network/storage boundaries, and cleanup. The auditor performs syntax parsing, metadata-boundary checks, duplicate-directive checks, seam classification, changed-diff routing, and base-versus-head module comparison without executing the candidate userscript. It emits audit_result, a bounded written_source_status, review_disposition, evidence tiers, and typed runtime limitations. A static pass can prove selected written-source properties for the checked scope; it is not a guarantee that every manager/browser renders, schedules, or integrates it identically.

When content behavior is difficult to execute, prefer a small deterministic harness with manager-agnostic stubs for API boundaries, DOM nodes, timers, fetch/XHR, storage, and hostile inputs. Use it to separate success, rejection, timeout, duplicate, late-result, teardown, and reinjection paths. Manager-specific references are optional and may be stale; do not block the content review or package installation on them. Do not treat a passing stub as proof of the real manager or network; retain the exact stub contract and mark integration behavior UNVERIFIED.

For every material family, choose the cheapest reachable contrast that can change acceptance: prefer a source check or deterministic fixture; use a local browser runtime only as a last-resort partial simulation; and treat the actual userscript manager as an unavailable or external oracle unless observed. For async work, simulate duplicate actions, late results, teardown, retry, and identity/generation guards. For DOM/CSS work, exercise long content, narrow viewports, scroll ownership, first paint, focus, and clipping only when a visual oracle is available. Label absent, fragile, or prospective observations UNVERIFIED.

Report and stop

Report the bound revision and scope, module routing, one coverage row per material semantic family, findings with source locators and reproducible states, commands and evidence tiers, unresolved limitations, and a final READY, NOT_READY, or BLOCKED_ON_ORACLE disposition. Keep audit_result, written_source_status, runtime_validation, and review_disposition separate: SOURCE_READY describes only bounded written-source checks; overall READY requires every decision-relevant runtime seam to have an available oracle. If any required manager/browser/network seam is unverified, retain SOURCE_READY where justified but set overall NOT_READY.

Do not post review comments, modify the PR, push, or install dependencies unless the user separately authorizes that outward or state-changing action.

© cyfung1031, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 25 other files (scripts, references) in agent-skills/review-userscript-change of cyfung1031/userscript-supports.

  • SKILL.md
  • agents/openai.yaml
  • references/async-state.md
  • references/dom-css.md
  • references/evaluation-contract.md
  • references/forward-testing.md
  • references/gm/compatibility.md
  • references/gm/dom.md
  • references/gm/index.md
  • references/gm/network.md
  • references/gm/resources-context.md
  • references/gm/storage.md
  • references/gm/ui.md
  • references/network-storage.md
  • references/security-boundary.md
  • references/userscript-runtime.md
  • scripts/audit_userscript_change.js
  • … and 9 more

Open the folder on GitHubat commit a6a319e

Compare with similar skills

Review Userscript Change next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Review Userscript Change compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Review Userscript Change this skillcyfung1031/userscript-supports121—~1.8kAutomated safety check: PassMIT
Code Reviewerjewbetcha/opentrace1162 repos~1.1kAutomated safety check: NotesMIT
Markbind Typescript MigrationMarkBind/markbind158—~2kAutomated safety check: PassMIT
Coding Agentmastra-ai/mastra29k—~2.3kAutomated safety check: PassCustom licence
Modern JavaScript Patternswshobson/agents40k12 repos~548Automated safety check: PassMIT
Review PRGEOLYTIX/xyz133—~4.1kAutomated safety check: PassMIT

Similar skills

  • Code Reviewer

    jewbetcha/opentrace

    Comprehensive code review skill for TypeScript, JavaScript, Python, Swift, Kotlin, Go.

    116 GitHub starsUsed in 2 repos~1.1k tokens
    DevelopmentAuto-check: notes
  • Complete guide for migrating JavaScript files to TypeScript in the MarkBind project, including the two-commit strategy, import/export syntax conversion, and best practices.

    158 GitHub stars~2k tokensUpdated 1 mo ago
    DevelopmentAuto-check passed
  • Coding Agent

    mastra-ai/mastra

    Authoring playbook for building agents that write, edit, review, or refactor code.

    29k GitHub stars~2.3k tokensUpdated today
    DevelopmentAuto-check passed
  • Covers ES6+ syntax and functional patterns for refactoring older JavaScript: async/await, destructuring, spread, modules, generators and data pipelines.

    40k GitHub starsUsed in 12 repos~548 tokens
    DevelopmentAuto-check passed
  • Review PR

    GEOLYTIX/xyz

    A skill your agent uses when reviewing a pull request, a branch, or uncommitted working changes in the XYZ/MAPP repository — whether the user asks to "review this PR", "check my changes before I…

    133 GitHub stars~4.1k tokensUpdated 2 days ago
    DevelopmentAuto-check passed
  • Create Pull Request

    honeybadger-io/honeybadger-js

    Pre-submission checklist for opening pull requests in honeybadger-js.

    116 GitHub stars~275 tokensUpdated 2 days ago
    DevelopmentAuto-check passed

More from cyfung1031/userscript-supports

  • Pick Invariant

    cyfung1031/userscript-supports

    Default first-line, domain-agnostic meta-reasoning control for choosing the right path.

    121 GitHub stars~2.2k tokensUpdated 2 days ago
    Auto-check passed
  • Prompt For Update 482487 Greasyfork Dark

    cyfung1031/userscript-supports

    Update the Greasy Fork Dark userscript's existing hard-coded // general CSS snapshot to the latest Greasy Fork application CSS while preserving the owner's dark palette, comments, selector-specific…

    121 GitHub stars~1k tokensUpdated 2 days ago
    Auto-check passed
  • Source Preserving CSS

    cyfung1031/userscript-supports

    Preserve-source CSS transformation for standalone CSS and CSS embedded in JavaScript, TypeScript, HTML, or user scripts.

    121 GitHub stars~764 tokensUpdated 2 days ago
    Auto-check passed
  • GitHub PR Publish Safe

    cyfung1031/userscript-supports

    Safe authenticated GitHub pull-request publication and review.

    121 GitHub stars~1.5k tokensUpdated 2 days ago
    Auto-check passed
  • Subagent Coordination

    cyfung1031/userscript-supports

    Coordinate bounded subagent work for analysis, coding, review, simulation, research, and handoff tasks.

    121 GitHub stars~1.2k tokensUpdated 2 days ago
    Auto-check passed

Works with

Categories

Questions about Review Userscript Change

What does Review Userscript Change do?

Review browser userscript changes in JavaScript userscript files, focusing on scripting content and its HTML/CSS behavior, with metadata as a binding gate plus DOM/CSS, userscript-manager APIs…. Review Userscript Change is an agent skill from cyfung1031/userscript-supports. Review browser userscript changes in JavaScript userscript files, focusing on scripting content and its HTML/CSS behavior, with metadata as a binding gate plus DOM/CSS, userscript-manager APIs, persistence, network, security, asynchronous lifecycle, and compatibility seams.

When should I use Review Userscript Change?

Review Userscript Change fits situations like: reviewing a userscript file diff; pull request and the review needs exact revision binding; pickInvariant-scoped probes; deterministic simulation.

How do I install Review Userscript Change in Claude Code?

Run `npx skills add cyfung1031/userscript-supports --skill review-userscript-change -a claude-code`. Or copy the skill folder (agent-skills/review-userscript-change in cyfung1031/userscript-supports) into .claude/skills/review-userscript-change in your project. Claude Code loads it when a task matches its description.

How do I install Review Userscript Change in Codex?

Run `npx skills add cyfung1031/userscript-supports --skill review-userscript-change -a codex`. Or copy the skill folder (agent-skills/review-userscript-change in cyfung1031/userscript-supports) into .agents/skills/review-userscript-change in your project. Codex loads it when a task matches its description.

Can I use Review Userscript Change in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add cyfung1031/userscript-supports --skill review-userscript-change -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/review-userscript-change, .gemini/skills/review-userscript-change, .github/skills/review-userscript-change and .opencode/skills/review-userscript-change in your project.

What does Review Userscript Change need to run?

Going by SKILL.md and its folder, Review Userscript Change needs JavaScript for the scripts in its folder and the command-line tools its instructions call (node). Our summary lists: Node.js.

Does Review Userscript Change access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Review Userscript Change safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Review Userscript Change use?

Review Userscript Change is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Review Userscript Change use?

About 1.8k tokens (SKILL.md is roughly 7.2k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 6.1k tokens, read only when the agent opens those files.

What are the alternatives to Review Userscript Change?

Skills that share tags, products or a category with Review Userscript Change: Code Reviewer (jewbetcha/opentrace, 116 stars), Markbind Typescript Migration (MarkBind/markbind, 158 stars), Coding Agent (mastra-ai/mastra, 29k stars) and Modern JavaScript Patterns (wshobson/agents, 40k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Review Userscript Change?

cyfung1031 (a GitHub user) maintains it in cyfung1031/userscript-supports, which has 121 GitHub stars. The repository holds 6 skills in this directory. The repository was last updated on October 8, 2026.

Source: cyfung1031/userscript-supports on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.