Code Review Checklist
shareAI-lab/learn-claude-code
Reviews code against a five-part checklist covering security, correctness, performance, maintainability and testing, and reports findings in a fixed format.
Handle websites requiring JavaScript by using curl with browser headers and validating file types.
$ npx skills add HKUDS/OpenSpace --skill http-response-handling -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install HKUDS/OpenSpace http-response-handling --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/HKUDS/OpenSpace.git skills-src && mkdir -p .claude/skills && cp -r skills-src/benchmarks/gdpval/skills/http-response-handling .claude/skills/http-response-handling && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "http-response-handling" agent skill from https://github.com/HKUDS/OpenSpace/tree/main/benchmarks/gdpval/skills/http-response-handling into .claude/skills/http-response-handling/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "http-response-handling", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/HKUDS/OpenSpace/tree/main/benchmarks/gdpval/skills/http-response-handlingType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add HKUDS/OpenSpace --skill http-response-handling -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install HKUDS/OpenSpace http-response-handling --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/HKUDS/OpenSpace.git skills-src && mkdir -p .agents/skills && cp -r skills-src/benchmarks/gdpval/skills/http-response-handling .agents/skills/http-response-handling && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "http-response-handling" agent skill from https://github.com/HKUDS/OpenSpace/tree/main/benchmarks/gdpval/skills/http-response-handling into .agents/skills/http-response-handling/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "http-response-handling", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add HKUDS/OpenSpace --skill http-response-handling -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install HKUDS/OpenSpace http-response-handling --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/HKUDS/OpenSpace.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/benchmarks/gdpval/skills/http-response-handling .cursor/skills/http-response-handling && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "http-response-handling" agent skill from https://github.com/HKUDS/OpenSpace/tree/main/benchmarks/gdpval/skills/http-response-handling into .cursor/skills/http-response-handling/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "http-response-handling", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/HKUDS/OpenSpace.git --path benchmarks/gdpval/skills/http-response-handling--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add HKUDS/OpenSpace --skill http-response-handling -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install HKUDS/OpenSpace http-response-handling --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/HKUDS/OpenSpace.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/benchmarks/gdpval/skills/http-response-handling .gemini/skills/http-response-handling && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "http-response-handling" agent skill from https://github.com/HKUDS/OpenSpace/tree/main/benchmarks/gdpval/skills/http-response-handling into .gemini/skills/http-response-handling/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "http-response-handling", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install HKUDS/OpenSpace http-response-handlingInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add HKUDS/OpenSpace --skill http-response-handling -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/HKUDS/OpenSpace.git skills-src && mkdir -p .github/skills && cp -r skills-src/benchmarks/gdpval/skills/http-response-handling .github/skills/http-response-handling && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "http-response-handling" agent skill from https://github.com/HKUDS/OpenSpace/tree/main/benchmarks/gdpval/skills/http-response-handling into .github/skills/http-response-handling/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "http-response-handling", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add HKUDS/OpenSpace --skill http-response-handling -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install HKUDS/OpenSpace http-response-handling --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/HKUDS/OpenSpace.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/benchmarks/gdpval/skills/http-response-handling .opencode/skills/http-response-handling && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "http-response-handling" agent skill from https://github.com/HKUDS/OpenSpace/tree/main/benchmarks/gdpval/skills/http-response-handling into .opencode/skills/http-response-handling/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "http-response-handling", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
http-response-handlingHandle websites requiring JavaScript by using curl with browser headers and validating file types.
HTTP Response Handling is an agent skill from HKUDS/OpenSpace. Handle websites requiring JavaScript by using curl with browser headers and validating file types.
Its SKILL.md is about 1k tokens, which your agent loads only when the skill is triggered. The skill folder holds 1 other file.
It works with JavaScript. The repository describes itself as: "OpenSpace: The Skill Management Layer for AI Agents" -- https://open-space.cloud/. The licence is MIT.
4 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 3827781. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
curlFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use curl, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
HTTP Response Handling loads about 1k tokens when it runs. Until then it costs about 30 tokens; SKILL.md has 295 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from HKUDS/OpenSpace at commit 3827781, republished under its MIT licence (© HKUDS). 295 words, ~1,020 tokens.
.claude/skills/http-response-handling/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.Use this technique when you need to fetch content from websites that:
Use curl with a realistic User-Agent header to mimic a real browser:
curl -L -A "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36" -o output.html "https://example.com"Key flags:
-L — Follow redirects-A — Set User-Agent header to mimic a real browser-o — Save output to file for inspectionAfter fetching, check if you received a placeholder response instead of actual content:
# Check file size (placeholder responses are often very small)
wc -c output.html
# Check for common placeholder indicators
grep -i "javascript" output.html | head -5
grep -i "loading" output.html | head -5
grep -i "noscript" output.html | head -5Signs of a placeholder response:
Before attempting format-specific parsing, validate the file type:
# Check the file type
file output.html
# Check the actual content type (if you have the headers)
curl -I -A "Mozilla/5.0 ..." "https://example.com" | grep -i content-type
# Inspect first few lines
head -50 output.htmlCommon checks:
<!DOCTYPE or <html{ or [%PDFIf you got valid HTML content:
# Proceed with HTML parsing or extraction
grep -oP '(?<=<title>).*?(?=</title>)' output.htmlIf you got a placeholder/JS-dependent response:
If you got an unexpected file type:
# Check what was actually returned
file output.html
# Adjust your approach based on actual content
case $(file -b --mime-type output.html) in
"text/html")
# Parse as HTML
;;
"application/json")
# Parse as JSON
;;
"application/pdf")
# Handle as PDF
;;
*)
echo "Unexpected file type: $(file -b --mime-type output.html)"
;;
esac#!/bin/bash
# fetch-with-validation.sh
URL="$1"
OUTPUT="${2:-output.html}"
# Fetch with browser headers
curl -L -A "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36" -o "$OUTPUT" "$URL"
# Get file info
SIZE=$(wc -c < "$OUTPUT")
TYPE=$(file -b --mime-type "$OUTPUT")
echo "Downloaded: $OUTPUT"
echo "Size: $SIZE bytes"
echo "Type: $TYPE"
# Warn about potential issues
if [ "$SIZE" -lt 1000 ]; then
echo "WARNING: File is very small - may be a placeholder response"
fi
if [ "$TYPE" = "text/html" ]; then
if grep -qi "javascript\|loading\|spinner" "$OUTPUT"; then
echo "WARNING: Content may be JavaScript-dependent"
fi
fi© HKUDS, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 1 other file in benchmarks/gdpval/skills/http-response-handling of HKUDS/OpenSpace.
Open the folder on GitHubat commit 3827781
HTTP Response Handling next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| HTTP Response Handling this skillHKUDS/OpenSpace | 7.7k | — | ~1k | Automated safety check: Pass | MIT | |
| Code Review ChecklistshareAI-lab/learn-claude-code | 78k | 5 repos | ~1.1k | Automated safety check: Pass | MIT | |
| Tailwindcss Developmentanonaddy/anonaddy | 4.9k | 10 repos | ~865 | Automated safety check: Pass | MIT | |
| Figma use_figma Plugin API Ruleswarpdotdev/warp | 65k | 4 repos | ~4.4k | Automated safety check: Pass | AGPL-3.0 | |
| GSAP Core Animationgreensock/gsap-skills | 16k | 4 repos | ~3.7k | Automated safety check: Pass | MIT | |
| JavaScript Concept Fact Checkerleonardomso/33-js-concepts | 67k | 1 repos | ~5k | Automated safety check: Pass | MIT |
shareAI-lab/learn-claude-code
Reviews code against a five-part checklist covering security, correctness, performance, maintainability and testing, and reports findings in a fixed format.
anonaddy/anonaddy
Always invoke when the user's message includes 'tailwind' in any form.
warpdotdev/warp
Required groundwork before any use_figma call: the rules and reference files for running JavaScript in a Figma file through the Plugin API without common failures.
greensock/gsap-skills
Covers the GSAP core API for tweens, easing, staggers, defaults and matchMedia, and when to choose GSAP over CSS animations or other JavaScript animation libraries.
leonardomso/33-js-concepts
Verifies the technical accuracy of JavaScript concept pages by checking code examples, MDN and ECMAScript claims and external links through a five-phase method.
oso95/scroll-world
Builds a scroll-driven landing page where a pre-rendered camera flies through connected AI-generated scenes, using Higgsfield for stills and video clips.
HKUDS/OpenSpace
Walks through producing a master audio track plus stems in Python, from checking a reference file and timing sections by BPM to effects, a zip archive and final verification.
HKUDS/OpenSpace
Handle cascading data retrieval tool failures by falling back to embedded knowledge generation
HKUDS/OpenSpace
Gives an agent a workaround when its code-execution sandbox keeps failing: save the Python script to a file and run it through the shell instead.
HKUDS/OpenSpace
A recovery routine for agents whose sandboxed code runner keeps failing: save the Python script to disk, then run it through the shell and read the output.
HKUDS/OpenSpace
Fallback ladder for failed sandboxed code runs, plus the habit of fixing the working directory first so generated files land in the right place.
HKUDS/OpenSpace
Fallback workflow for executing Python code when executecodesandbox fails repeatedly
Works with
Handle websites requiring JavaScript by using curl with browser headers and validating file types. HTTP Response Handling is an agent skill from HKUDS/OpenSpace. Handle websites requiring JavaScript by using curl with browser headers and validating file types.
Run `npx skills add HKUDS/OpenSpace --skill http-response-handling -a claude-code`. Or copy the skill folder (benchmarks/gdpval/skills/http-response-handling in HKUDS/OpenSpace) into .claude/skills/http-response-handling in your project. Claude Code loads it when a task matches its description.
Run `npx skills add HKUDS/OpenSpace --skill http-response-handling -a codex`. Or copy the skill folder (benchmarks/gdpval/skills/http-response-handling in HKUDS/OpenSpace) into .agents/skills/http-response-handling in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add HKUDS/OpenSpace --skill http-response-handling -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/http-response-handling, .gemini/skills/http-response-handling, .github/skills/http-response-handling and .opencode/skills/http-response-handling in your project.
Going by SKILL.md and its folder, HTTP Response Handling needs the command-line tools its instructions call (curl).
SKILL.md contains no URLs. Its commands use curl, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
HTTP Response Handling is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 1k tokens (SKILL.md is roughly 4.1k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with HTTP Response Handling: Code Review Checklist (shareAI-lab/learn-claude-code, 78k stars), Tailwindcss Development (anonaddy/anonaddy, 4.9k stars), Figma use_figma Plugin API Rules (warpdotdev/warp, 65k stars) and GSAP Core Animation (greensock/gsap-skills, 16k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
HKUDS (a GitHub organization) maintains it in HKUDS/OpenSpace, which has 7,743 GitHub stars. The repository holds 199 skills in this directory. The repository was last updated on August 12, 2026.
Source: HKUDS/OpenSpace on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.