Review a PR or working diff against this repo's intent layer (the AGENTS.md hierarchy), toolception pitfalls, and core invariants.

Apache-2.0Auto-check passedDevelopment

Install Code Review

skills CLI
$ npx skills add imbenrabi/Financial-Modeling-Prep-MCP-Server --skill code-review -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install imbenrabi/Financial-Modeling-Prep-MCP-Server code-review --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/imbenrabi/Financial-Modeling-Prep-MCP-Server.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/code-review .claude/skills/code-review && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
code-review
GitHub stars
150
Token cost
~2.6k tokens
SKILL.md length
1,126 words
Files
1
Skills in repo
1
Repo updated
First seen
Licence
Apache-2.0

At a glance

Review a PR or working diff against this repo's intent layer (the AGENTS.md hierarchy), toolception pitfalls, and core invariants.

  • Works in 6 steps: Load behavioral guidelines → Scope the diff → Load the intent layer (live read — do… → …
  • Checking changes before merge in the Financial Modeling Prep MCP server
  • SKILL.md covers 1. Load behavioral guidelines, 2. Scope the diff, 3. Load the intent layer (live… and 4. Toolception deep-check…, plus 2 more sections
  • Calls gh and git

What it does

Code Review is an agent skill from imbenrabi/Financial-Modeling-Prep-MCP-Server. Review a PR or working diff against this repo's intent layer (the AGENTS.md hierarchy), toolception pitfalls, and core invariants. Use when reviewing code, auditing a PR, or checking changes before merge in the Financial Modeling Prep MCP server. Triggers on: "review", "code review", "review this PR", "review the diff", "audit", "check this diff", "before merge", "pull request review", "PR review".

Its SKILL.md is about 2.6k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Development, covering Pull requests, Code review and Financial modeling. It works with Model Context Protocol. The repository describes itself as: A Model Context Protocol (MCP) implementation for Financial Modeling Prep, enabling AI assistants to access and analyze financial data, stock information, company fundamentals… The licence is Apache-2.0.

When your agent uses it

  • Checking changes before merge in the Financial Modeling Prep MCP server
  • Review the diff
  • Check this diff
  • Pull request review

Example prompts

  • “review”
  • “code review”
  • “review this PR”
  • “/code-review”

Requirements

  • Pre-approved tools (allowed-tools): Read, Grep, Glob, Bash(git:*), Bash(gh pr:*), Bash(gh api:*), Bash(gh search:*), Skill

Workflow steps

6 steps, taken from the step headings in SKILL.md.

  1. Load behavioral guidelines
  2. Scope the diff
  3. Load the intent layer (live read — do not rely on memory)
  4. Toolception deep-check (only when the diff touches the integration surface)
  5. Review across dimensions
  6. Output

What it can do on your machine

Read from SKILL.md and the folder at commit 17fbe04. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Read
    • Grep
    • Glob
    • Bash(git:*)
    • Bash(gh pr:*)
    • Bash(gh api:*)
    • Bash(gh search:*)
    • Skill

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • gh
    • git

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use gh and git, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Code Review loads about 2.6k tokens when it runs. Until then it costs about 103 tokens; SKILL.md has 1,126 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~103
When it runs · the whole SKILL.md, loaded when a task matches
~2.6k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from imbenrabi/Financial-Modeling-Prep-MCP-Server at commit 17fbe04, republished under its Apache-2.0 licence (© imbenrabi). 1,126 words, ~2,565 tokens.

Download SKILL.mdSave it as .claude/skills/code-review/SKILL.md (or your agent's skills folder).
name
code-review
description
Review a PR or working diff against this repo's intent layer (the AGENTS.md hierarchy), toolception pitfalls, and core invariants. Use when reviewing code, auditing a PR, or checking changes before merge in the Financial Modeling Prep MCP server. Triggers on: "review", "code review", "review this PR", "review the diff", "audit", "check this diff", "before merge", "pull request review", "PR review".
allowed-tools
Read, Grep, Glob, Bash(git:*), Bash(gh pr:*), Bash(gh api:*), Bash(gh search:*), Skill

Code Review — FMP MCP Server

You are reviewing changes to this repository. This server exposes 253+ read-only financial-data tools over MCP (HTTP/SSE) using toolception + Fastify. Most of the load-bearing rules here are non-obvious and live in the intent layer (the AGENTS.md hierarchy), not in the code. A generic review misses them. Your job is to catch real bugs and any violation of this repo's documented invariants.

Work through the steps in order. Do not skip step 1 or step 3 — nor step 4 when the diff touches the toolception integration surface.

1. Load behavioral guidelines

Invoke the karpathy-guidelines skill first (via the Skill tool) and review through its four lenses:

  • Surgical changes — every changed line should trace to the PR's stated purpose. Flag drive-by refactors, reformatting, or "improvements" to untouched code.
  • Simplicity — flag speculative abstraction, unused config/flexibility, and error handling for impossible states.
  • Surfaced assumptions — flag silent decisions where multiple interpretations existed.
  • Verifiable success — flag behavior changes that arrive without a test proving them.

2. Scope the diff

Determine what changed.

  • Given a PR reference — CI passes it as owner/repo/pull/N. Extract the number N and run gh pr diff N (the repo is inferred from the checkout); a full PR URL also works.
  • Otherwise (local working branch) — diff against main:
git diff --merge-base main --stat
git diff --merge-base main

List the changed files and collapse them to the source directories touched — that set drives step 3.

3. Load the intent layer (live read — do not rely on memory)

Always read the root AGENTS.md (it defines the intent layer and its maintenance rules). Then, for each touched directory, read its matching doc. Read the area's FLOW.md too when one exists. Loading is hierarchical and T-shaped: root + the specific node.

Changed pathRead
src/ (startup, index.ts, Fastify wiring)docs/src/AGENTS.md, docs/src/FLOW.md
src/api/**docs/src/api/AGENTS.md
src/tools/**docs/src/tools/AGENTS.md
src/toolception-adapters/**docs/src/toolception-adapters/AGENTS.md
src/server-mode-enforcer/**docs/src/server-mode-enforcer/AGENTS.md
src/endpoints/**docs/src/endpoints/AGENTS.md, docs/src/endpoints/FLOW.md
__tests__/smoke/**docs/tests/smoke/AGENTS.md
Adding a tool/module/tool setdocs/GUIDE.md (the procedure to follow)

Directories without their own doc (src/constants, src/prompts, src/schemas, src/types, src/utils) inherit the root AGENTS.md plus the nearest parent that does have one — review them on general dimensions (step 5) and the invariants in scope.

The rules you cite in findings come from the docs you just read — quote the actual Key Rule / Anti-pattern / Pitfall, do not paraphrase from this skill.

4. Toolception deep-check (only when the diff touches the integration surface)

toolception is the core MCP layer, but node_modules/toolception ships compiled dist/ only — the readable source and the real API contracts live upstream at the public repo code-rabi/toolception. When the diff touches the integration surface, verify it against the actual upstream source, not memory.

Trigger when the diff touches any of: src/toolception-adapters/**, src/index.ts (the createMcpServer config), src/endpoints/*.ts (defineEndpoint), src/prompts/** (the McpServer.prompt() extension), or bumps toolception in package.json / package-lock.json.

Fetch the source with gh, pinned to the installed version:

  1. Read the installed version from node_modules/toolception/package.json (the version field) with the Read tool. The matching tag is v<version> (e.g. v0.6.3).
  2. Pull the relevant source — raw, no base64 decode. Substitute that version into ref:
gh api -H "Accept: application/vnd.github.raw" "/repos/code-rabi/toolception/contents/src/index.ts?ref=v<version>"
gh api "/repos/code-rabi/toolception/contents/src/<area>?ref=v<version>" --jq '.[].name'   # list a dir
gh search code --repo code-rabi/toolception "<symbol>"                                      # locate a symbol

Offline fallback for the type contracts: node_modules/toolception/dist/index.d.ts.

Fetch the area that matches the change:

Diff touchesFetch from toolception src/
createMcpServer config (src/index.ts)src/index.ts, src/server/**, src/types/**
startup mode / toolsets (ModeConfigMapper)src/mode/**
exposure policy / namespacing / allowlist / maxActiveToolsetssrc/permissions/**
session config / config query param / cache keysrc/session/**
defineEndpoint / custom endpoints / Fastify appsrc/http/**
ModuleLoader / McpToolDefinition shapessrc/types/**
McpServer.prompt() extension (src/prompts/**)src/server/**
meta-tools (enable/disable/list toolsets)src/meta/**

Verify the diff against the fetched contracts:

  • The config this repo passes to createMcpServer (catalog, moduleLoaders, startup{mode, toolsets}, context, sessionContext{queryParam}, exposurePolicy{namespaceToolsWithSetKey, maxActiveToolsets?, allowlist?}, createServer, http) still matches the upstream CreateMcpServerOptions type — flag renamed/removed/ retyped keys.
  • ModuleLoader is still (context?) => McpToolDefinition[] | Promise<McpToolDefinition[]> and the McpToolDefinition shape the adapters / ToolCollector emit still matches upstream.
  • McpServer.prompt() still exists upstream — a runtime extension reached via type cast that silently no-ops if dropped (list_mcp_assets then vanishes with no error).
  • On a toolception version bump: fetch the new tag's source and re-verify every contract above. Flag any breaking rename/removal/retype (precedent: initialToolsets → toolsets in 0.5.1).

Don't restate the intent layer — docs/src/toolception-adapters/AGENTS.md and docs/src/AGENTS.md / FLOW.md already hold this repo's toolception pitfalls; cite them. Upstream toolception ships its own AGENTS.md files too (e.g. src/session/AGENTS.md) — fetch them for its documented intent when a change is subtle.

Show full SKILL.md (433 more words)Show less

5. Review across dimensions

For each, cite the specific source (file:line for code, and the exact rule from the loaded AGENTS.md for invariants).

A. General correctness & security. Logic bugs, unhandled edge cases and error paths, secret/token exposure in logs or responses, injection, and obvious performance traps. This makes the skill a complete reviewer, not just an overlay.

B. Intent-layer invariants & toolception pitfalls. Validate the diff against the rules in the docs loaded in step 3. The recurring high-cost ones to anchor on:

  • API key travels as the ?apikey= query param — never a header (docs/src/api/AGENTS.md).
  • Token precedence is Instance (constructor-injected session token) > Environment; don't invert it, and don't reintroduce a per-request "context" tier.
  • Tools never throw — handlers return { content: [...], isError: true }, message formatted Error: ${message} (docs/src/tools/AGENTS.md).
  • Tool names are globally unique across all modules — a duplicate silently overwrites.
  • Toolception integration pitfalls (session cache key, base64 config query param, MODULE_ADAPTERS ↔ TOOL_SETS sync, no session-level toolset config) live in docs/src/toolception-adapters/AGENTS.md — and when the integration surface is touched, run the step 4 deep-check against upstream source.
  • Startup order (docs/src/AGENTS.md / FLOW.md): the preHandler hook is registered before createMcpServer(); a custom Fastify app must call app.listen().
  • Server-mode enforcer: initialize() precedes getInstance(); invalid tool sets fail-fast via process.exit(1).
  • Don't infer request success from HTTP status — FMP returns error bodies with HTTP 200.

C. AGENTS.md sync. The intent layer's own maintenance rule (root AGENTS.md): if the diff changes behavior documented in an AGENTS.md, that file must be updated in the same PR. If a touched area's documented rule no longer matches the code and its AGENTS.md is untouched, flag it. (Also: a new major directory with distinct concerns should add an AGENTS.md wired into the navigation table.)

D. TypeScript standards. Invoke the typescript-standards skill (Skill tool) and apply it to the changed .ts files; report what it flags. It covers no-any (prefer unknown), TSDoc on exports, pure functions / single responsibility, readonly, and preferring interface — defer to the skill for the exact rules rather than restating them here.

E. Test expectations. Per docs/tests/smoke/AGENTS.md: smoke tests run dist/ so a build must precede them; responses are SSE (event: message\ndata: {json}) — never parsed as raw JSON; resetSession() runs between tests (global clientId/sessionId). New tools or modules should ship with tests.

6. Output

Report high-signal findings only. For each:

  • Severity — Blocker / High / Medium / Low.
  • Location — file:line.
  • Rule — the exact invariant or bug, with its citation (e.g. docs/src/tools/AGENTS.md → never-throw).
  • Fix — concrete and minimal.

Do not raise nits that trace to neither a documented rule nor a real defect. If the diff is clean, say so and name what you checked. Group findings by severity, Blockers first.

© imbenrabi, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .claude/skills/code-review of imbenrabi/Financial-Modeling-Prep-MCP-Server.

Open the folder on GitHubat commit 17fbe04

Compare with similar skills

Code Review next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Code Review compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Code Review this skillimbenrabi/Financial-Modeling-Prep-MCP-Server150—~2.6kAutomated safety check: PassApache-2.0
Code Reviewsbroenne/mcp-windows105—~1.6kAutomated safety check: PassMIT
Code Reviewoaslananka/kicad-mcp-pro119—~3.9kAutomated safety check: PassMIT
Review PRPrefectHQ/fastmcp28k—~3.1kAutomated safety check: PassApache-2.0
ObservalObserval/Observal4.1k—~2.2kAutomated safety check: PassApache-2.0
Mariadb Operator PR Reviewmariadb-operator/mariadb-operator1k—~3.3kAutomated safety check: PassApache-2.0

Similar skills

  • Code Review

    sbroenne/mcp-windows

    Review pull requests in mcp-windows for concrete bugs in MCP and CLI contracts, Windows UI automation, element identity, snapshots, bounded searches, and service lifetime.

    105 GitHub stars~1.6k tokensUpdated yesterday
    DevelopmentAuto-check passed
  • Code Review

    oaslananka/kicad-mcp-pro

    A skill your agent uses for GitHub Copilot pull request and code reviews in oaslananka/kicad-mcp-pro.

    119 GitHub stars~3.9k tokensUpdated today
    DevelopmentAuto-check passed
  • Review PR

    PrefectHQ/fastmcp

    Assess a FastMCP pull request for justified behavior, compatibility, and correctness, then follow CI and review feedback to a revision-specific verdict.

    28k GitHub stars~3.1k tokensUpdated today
    DevelopmentAuto-check passed
  • Observal

    Observal/Observal

    A skill your agent uses when starting any task the organization may already have an approved skill, prompt, MCP server, or Agent for: reviewing code, a commit, a diff, or a pull request; writing…

    4.1k GitHub stars~2.2k tokensUpdated today
    DevelopmentAuto-check passed
  • Mariadb Operator PR Review

    mariadb-operator/mariadb-operator

    Perform a structured maintainer-style PR review for the mariadb-operator repository.

    1k GitHub stars~3.3k tokensUpdated 2 days ago
    DevelopmentAuto-check passed
  • Fix Issue

    PrefectHQ/fastmcp

    Carry a selected FastMCP bug from reproduction through a scoped fix, compatibility review, validation, and a monitored pull request.

    28k GitHub stars~842 tokensUpdated today
    DevelopmentAuto-check passed

Questions about Code Review

What does Code Review do?

Review a PR or working diff against this repo's intent layer (the AGENTS.md hierarchy), toolception pitfalls, and core invariants. Code Review is an agent skill from imbenrabi/Financial-Modeling-Prep-MCP-Server.md hierarchy), toolception pitfalls, and core invariants.

When should I use Code Review?

Code Review fits situations like: checking changes before merge in the Financial Modeling Prep MCP server; review the diff; check this diff; pull request review.

How do I install Code Review in Claude Code?

Run `npx skills add imbenrabi/Financial-Modeling-Prep-MCP-Server --skill code-review -a claude-code`. Or copy the skill folder (.claude/skills/code-review in imbenrabi/Financial-Modeling-Prep-MCP-Server) into .claude/skills/code-review in your project. Claude Code loads it when a task matches its description.

How do I install Code Review in Codex?

Run `npx skills add imbenrabi/Financial-Modeling-Prep-MCP-Server --skill code-review -a codex`. Or copy the skill folder (.claude/skills/code-review in imbenrabi/Financial-Modeling-Prep-MCP-Server) into .agents/skills/code-review in your project. Codex loads it when a task matches its description.

Can I use Code Review in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add imbenrabi/Financial-Modeling-Prep-MCP-Server --skill code-review -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/code-review, .gemini/skills/code-review, .github/skills/code-review and .opencode/skills/code-review in your project.

What does Code Review need to run?

Going by SKILL.md and its folder, Code Review needs the command-line tools its instructions call (gh and git). Its frontmatter pre-approves these tools: Read, Grep, Glob, Bash(git:*), Bash(gh pr:*), Bash(gh api:*), Bash(gh search:*), Skill.

Does Code Review access the network?

SKILL.md contains no URLs. Its commands use gh and git, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Code Review safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Code Review use?

Code Review is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Code Review use?

About 2.6k tokens (SKILL.md is roughly 10k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Code Review?

Skills that share tags, products or a category with Code Review: Code Review (sbroenne/mcp-windows, 105 stars), Code Review (oaslananka/kicad-mcp-pro, 119 stars), Review PR (PrefectHQ/fastmcp, 28k stars) and Observal (Observal/Observal, 4.1k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Code Review?

imbenrabi (a GitHub user) maintains it in imbenrabi/Financial-Modeling-Prep-MCP-Server, which has 150 GitHub stars. The repository was last updated on July 2, 2026.

Source: imbenrabi/Financial-Modeling-Prep-MCP-Server on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.