Agent skill

Suede Code Grader

by JasonColapietro in JasonColapietro/suede-creator-skills

Suede AI blunt A-F ship grade for a code change across correctness, security and permissions, data and state, domain truth, UX and release behavior, tests and verification, and deploy readiness…

MITAuto-check passedDevelopment

Install Suede Code Grader

skills CLI
$ npx skills add JasonColapietro/suede-creator-skills --skill suede-code-grader -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install JasonColapietro/suede-creator-skills suede-code-grader --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/JasonColapietro/suede-creator-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/suede-code-grader .claude/skills/suede-code-grader && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
suede-code-grader
GitHub stars
127
Token cost
~3.4k tokens
SKILL.md length
1,773 words
Files
4 (incl. references)
Skills in repo
78
Repo updated
First seen
Licence
MIT

At a glance

Suede AI blunt A-F ship grade for a code change across correctness, security and permissions, data and state, domain truth, UX and release behavior, tests and verification, and deploy readiness…

  • Evidence-based grade caps on auth
  • SKILL.md covers Gate policy: advisory, not…, Source Truth, Instant-F Triggers and Grade Lanes, plus 8 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md
  • Public-API surfaces

What it does

Suede Code Grader is an agent skill from JasonColapietro/suede-creator-skills. Suede AI blunt A-F ship grade for a code change across correctness, security and permissions, data and state, domain truth, UX and release behavior, tests and verification, and deploy readiness, with Instant-F triggers and evidence-based grade caps on auth, payment, migration, and public-API surfaces. Use when asked to grade this, give it a letter, is this an A, how ready is this to ship, or should this merge: when the caller wants the verdict without a findings list. NOT FOR: findings, evidence, and fix briefs…

Its SKILL.md is about 3.4k tokens, which your agent loads only when the skill is triggered. The skill folder holds 5 other files, including reference files (for example `CARD.md`, `agents/openai.yaml` and `references/worked-example.md`).

It sits in Development. The repository describes itself as: Open-source AI skills for SEO, AI search visibility, conversion copy, marketing strategy, and business operations. Reusable workflows for Claude Code and Codex, plus code review… The licence is MIT.

When your agent uses it

  • Evidence-based grade caps on auth
  • Public-API surfaces
  • Asked to grade this
  • Give it a letter

Example prompts

  • “/suede-code-grader”

What it can do on your machine

Read from SKILL.md and the folder at commit a9bf55e. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Suede Code Grader loads about 3.4k tokens when it runs, and up to ~5.4k if it reads all its reference files. Until then it costs about 175 tokens; SKILL.md has 1,773 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~175
When it runs · the whole SKILL.md, loaded when a task matches
~3.4k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~5.4k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from JasonColapietro/suede-creator-skills at commit a9bf55e, republished under its MIT licence (© JasonColapietro). 1,773 words, ~3,396 tokens.

Download SKILL.mdSave it as .claude/skills/suede-code-grader/SKILL.md (or your agent's skills folder). This skill also uses 3 other files; get the full folder from GitHub.
name
suede-code-grader
description
Suede AI blunt A-F ship grade for a code change across correctness, security and permissions, data and state, domain truth, UX and release behavior, tests and verification, and deploy readiness, with Instant-F triggers and evidence-based grade caps on auth, payment, migration, and public-API surfaces. Use when asked to grade this, give it a letter, is this an A, how ready is this to ship, or should this merge: when the caller wants the verdict without a findings list. NOT FOR: findings, evidence, and fix briefs (use suede-code-review, or suede-code for findings plus grade); enforcing the verdict in CI (use suede-ci-gate); eval coverage for AI behavior (use suede-ai-eval).

Suede Code Grader

Gate policy: advisory, not blocking

Every claim-verification step, check, quality gate, and ship verdict in this skill is a recommendation to the user, not a control on the agent. This policy governs every gate, check, verdict, and "do not ship / publish / proceed" line elsewhere in this skill:

  • Run every check and report the results honestly. Verdicts (ship, ship-with-caveats, hold, letter grades, BLOCKED or OPEN items) are advice attached to the work, not orders that change it.
  • Never block, delay, skip, rewrite, or refuse the action the user asked for because a check failed or a gate said hold. Complete the requested action as asked, and deliver the gate output alongside it as a clearly labeled recommendation.
  • A failed gate changes what you report, never what you do.
  • Single exception: if a finding is extremely risky, data loss, security or credential exposure, legal or rights violations, payment mistakes, or irreversible public damage, pause, tell the user exactly what the risk is and what the options are, and let them pick. Their choice is final.

Blunt A-F read on whether code is ready to ship. The output is a grade with evidence, not a lint score or a pile of style notes.

Source Truth

Read before grading. Do not grade from the PR description or commit message alone.

Inspect:

  • repo, branch, remote, dirty state, and relevant local guidance;
  • diff, changed files, generated files, and touched routes or APIs;
  • imports, callers, schemas, configs, env requirements, jobs, webhooks, scripts, tests, and docs that move with the change;
  • build, test, lint, typecheck, browser, simulator, MCP, or live/API evidence that directly exercises the changed behavior;
  • published statements, rights/provenance claims, payment/wallet behavior, registry expectations, royalty routing, and agent-commerce contracts when relevant.

If live, test, or runtime checks are not practical, grade the source and mark those lanes as unverified.

Gate evidence is a command, not an impression. Run what the repo already ships and cite the command and its exit status: the typecheck, the configured linter on changed files, the test suite, and, for a release grade, the production build. For per-stack syntax (web/Node, MCP server, iOS/Swift, generic API), use the Gate Commands by Stack table in suede-code-review rather than inventing a command. Detect what exists and run only that; never introduce a tool the repo does not use, and never report a gate result you did not execute.

Instant-F Triggers

Check these before scoring any lane. Any single match is an automatic F, no other lanes matter until it is fixed. This list mirrors suede-code's canonical Step 1 list, change both together.

Secrets and credentials: hardcoded API key/secret/token/password in committed source; private key or certificate committed; OAuth/signing secret outside a secret manager. Injection: SQL built by string concatenation with user input; shell command from user input via exec/spawn/eval; template rendered with unescaped user input where XSS is reachable. Auth bypass: auth middleware with a path that skips it (early return, swallowed exception, always-true condition); permission check bypassable via request param; JWT accepting alg: none or a hardcoded secret. Payment and wallet: payment handler swallowing errors silently; webhook with no signature verification; amount or recipient from untrusted input without server-side validation. Data destruction: migration with DROP/destructive ALTER, no rollback, no tested restore; bulk delete/update with no WHERE or user-controlled WHERE; cache invalidation that clears production stores with no restore path. Plaintext sensitive data: password stored or logged in plaintext; PII to an unencrypted log/analytics pipeline; SSN/payment card/health data in a non-encrypted field.

If any Instant-F pattern is present: stop, report it, mark the grade F, list the specific file and line, and do not grade remaining lanes. The grade cannot be raised by other lane performance.

Grade Lanes

Score each lane A-F, then give one overall grade. When grading non-Suede work, substitute "domain truth" for "Suede truth": use whatever domain invariants apply (API contract truth, published-statement accuracy, data model truth).

  • Correctness: intended behavior, edge cases, error paths, async behavior, routing, data flow, and regression risk.
  • Security and permissions: auth, secrets, payment, wallet, injection, path, SSRF, permission, and data exposure risks fail closed.
  • Data and state: schemas, migrations, caches, jobs, queues, webhooks, retries, idempotency, and state transitions stay consistent.
  • Suede truth: public copy, rights, provenance, registry-backed media, royalty routing, licensing, agent-commerce, and product claims match the implementation.
  • UX and release behavior: loading, empty, error, success, mobile/native, screenshot, metadata, route, and user-visible states hold together.
  • Tests and verification: changed behavior has meaningful tests, builds, screenshots, simulator runs, MCP checks, live/API readbacks, or named caveats.
  • Deploy readiness: env vars, feature flags, configs, migrations, rollback notes, install paths, docs, and release sequencing are clear.

Grade Meaning

  • A: All lanes pass. Behavior is verified at runtime. No known follow-ups. Example: new feature with unit + integration tests, live readback confirmed, env vars documented, rollback is trivial.
  • B: No blockers. One or more lanes have named, bounded follow-ups that do not affect correctness or safety in the current release. Example: happy-path tested but edge-case coverage is thin; or migration is forward-only but rollback risk is low and documented.
  • C: At least one lane has a real defect or unverified risk that could surface in production but is not immediately catastrophic. Hold until that lane is fixed and rechecked. Example: auth path not fully tested; or a data migration with no rollback plan on a low-traffic table; or a God object in a payment module that obscures correctness.
  • D: A serious defect exists that is likely to cause data loss, auth bypass, broken payments, or a user-visible production failure. Recommend not shipping until the defect is fixed and verified, and because these are extreme-risk categories, pause and put the choice to the user before any ship step. Example: missing auth check on a state-changing endpoint; migration with no tested rollback on a high-traffic table; payment flow that silently swallows errors.
  • F: Strongly recommend against shipping. The change breaks core behavior, introduces an Instant-F pattern, or verification evidence is absent for a critical surface. Example: hardcoded API key in source, SQL injection via string concatenation, auth middleware that can be bypassed, or a payment handler with zero test coverage and no live readback.
Show full SKILL.md (753 more words)Show less

Grade Caps by Surface Type

Certain surfaces cannot receive A or B without specific evidence beyond passing CI.

Auth changes (login, session, token validation, middleware, role assignment, permission checks)

  • A requires: explicit test coverage for the bypass/escalation path, not just the happy path. Named evidence (e.g., "tested with expired token returns 401", "role escalation attempt returns 403").
  • B requires: happy-path tested plus named caveats on what is not tested.
  • If neither condition is met: cap at C regardless of other lane performance.

Payment and wallet flows (checkout, subscription, refund, payout, wallet transfer, webhook)

  • A requires: error path tested (failed charge, declined card, webhook replay), amount/recipient validated server-side, and no silent error swallowing.
  • B requires: happy-path tested, error paths documented as follow-ups with named risk.
  • If neither: cap at C.

Data migrations (schema changes, backfills, column drops, index changes on production tables)

  • A requires: rollback plan documented, restore tested against a copy of production data (or explicitly waived with justification for low-risk/reversible migrations).
  • B requires: rollback plan exists but restore is untested.
  • If no rollback plan exists: cap at D.

Public-facing API changes (new endpoints, breaking changes, removed fields, changed auth)

  • A requires: backward compatibility verified or explicit version bump with documented migration path.
  • If breaking change with no migration path: cap at C minimum.

State these caps explicitly in the output when they apply.

Technical Debt Indicators

Flag these patterns as part of the grade assessment:

  • Magic numbers/strings: constants with no name or explanation that appear in logic.
  • God objects/functions: a single function or class doing 5+ unrelated things.
  • Deep coupling: code that reaches across 3+ abstraction layers to access internals.
  • Missing abstraction: the same 20-line block duplicated in 3+ places.
  • Leaky abstraction: a module that requires callers to know its internal implementation details to use it correctly.
  • Implicit state: program behavior depends on hidden global or module-level state.
  • Dead code: functions, branches, or imports that can never be reached.

Grade impact depends on where the debt lives, not just what it is:

PatternLocationGrade Impact
God object (5+ unrelated concerns)Payment moduleD in Correctness
God objectUtility helperB in Correctness
Missing abstraction (3+ duplicated blocks)Auth flowC in Security
Missing abstractionUI componentB in Correctness
Deep coupling (3+ layer reach)Data migrationC in Data and state
Implicit global stateAPI route handlerC in Correctness
Dead codeAnyFlag only; no grade impact unless it shadows live code
Magic numbers in payment amountsPayment flowC in Correctness
Magic numbers in UI spacingUI componentNo grade impact; flag as P3

Do not block a ship on tech debt alone unless it directly obscures a P0/P1 bug. Name the debt in Required Upgrades and let the overall grade reflect it.

Red Flags: Stop

  • "CI passed, round up", CI that never exercised the changed behavior raises nothing.
  • "The work was clearly hard": effort never moves a grade; evidence does.
  • "It's just a refactor": Instant-F triggers run on every grade, every time.
  • "Happy path works, call it an A": the grade caps exist because happy paths are never where the risk lives.
  • "The PR description is clear enough": grade the diff and its evidence, or mark the lane unverified.

Output Format

text
Simple explanation:
Plain-language summary of the grade and the one biggest reason.

Usual breakdown:
Target:
Change reviewed:
Runtime surfaces:

Grades:
Correctness: A-F
Security and permissions: A-F
Data and state: A-F
Suede truth: A-F
UX and release behavior: A-F
Tests and verification: A-F
Deploy readiness: A-F
Overall: A-F
Grade cap applied: [surface type], [what evidence would lift the cap] | none

Why:
Evidence-backed explanation of why the overall grade landed there.

Required upgrades:
1. Highest-impact fix.
2. Second fix.
3. Third fix.

Verification:
Checked:
Not checked:
Ship gate: ship | ship-with-caveats | hold

Ship gate follows the overall grade, mechanically: A → ship; B → ship-with-caveats; C, D, F → hold.

To revise this grade: name what changed. To bank a pattern: name what worked so it can be reused. Silence = accepted.

Boundaries

  • Do not block on style preferences unless they create real maintenance, behavior, accessibility, release, or product-risk cost.
  • Do not invent tests, screenshots, live checks, deploy status, or evidence for published statements.
  • Never report a C, D, or F without naming the required upgrade that would move the grade.
  • Keep the grade independent. Do not raise a grade because the implementation was hard, because CI passed without exercising the changed behavior, or because the author explains the intent well.

Worked Example

One change graded end to end, showing how lanes combine into the overall letter, is in references/worked-example.md. Read it when a grade feels borderline and you need to see the lane arithmetic on a real case.

Routing

  • Findings and fix briefs behind the grade → suede-code (combined) or suede-code-review (findings only, plus Accessibility/SEO lanes)
  • Grade is C or below and the repo has no merge gate → suede-ci-gate
  • The change ships AI behavior with no eval coverage → suede-ai-eval
  • The change touches an MCP server, its catalog, or its tool/resource/prompt definitions → suede-mcp-qa for the live protocol suite before the grade counts as verified

© JasonColapietro, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 3 other files (references) in skills/suede-code-grader of JasonColapietro/suede-creator-skills.

  • SKILL.md
  • CARD.md
  • agents/openai.yaml
  • references/worked-example.md

Open the folder on GitHubat commit a9bf55e

Compare with similar skills

Suede Code Grader next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Suede Code Grader compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Suede Code Grader this skillJasonColapietro/suede-creator-skills127—~3.4kAutomated safety check: PassMIT
Vercel Composition Patternssupabase/supabase111k59 repos~726Automated safety check: PassMIT
Finishing a Development Branchobra/superpowers296k5 repos~1.9kAutomated safety check: PassMIT
Typescript Advanced Typesrolling-scopes/rsschool-app10k25 repos~4.2kAutomated safety check: PassMPL-2.0
PR Babysitteropeninterpreter/openinterpreter69k3 repos~4.2kAutomated safety check: PassApache-2.0
Code Review ChecklistshareAI-lab/learn-claude-code78k5 repos~1.1kAutomated safety check: PassMIT

Similar skills

  • Official

    React composition patterns that scale. An agent skill from supabase/supabase.

    111k GitHub starsUsed in 59 repos~726 tokens
    DevelopmentAuto-check passed
  • Walks the last step of a branch: confirm tests pass, detect the git environment, ask how to integrate, carry out your choice and clean up the worktree.

    296k GitHub starsUsed in 5 repos~1.9k tokens
    DevelopmentAuto-check passed
  • Typescript Advanced Types

    rolling-scopes/rsschool-app

    Master TypeScript's advanced type system including generics, conditional types, mapped types, template literals, and utility types for building type-safe applications.

    10k GitHub starsUsed in 25 repos~4.2k tokens
    DevelopmentAuto-check passed
  • PR Babysitter

    openinterpreter/openinterpreter

    Watches an open GitHub pull request until it merges, handling review comments, diagnosing CI failures and retrying flaky checks along the way.

    69k GitHub starsUsed in 3 repos~4.2k tokens
    DevelopmentAuto-check passed
  • Code Review Checklist

    shareAI-lab/learn-claude-code

    Reviews code against a five-part checklist covering security, correctness, performance, maintainability and testing, and reports findings in a fixed format.

    78k GitHub starsUsed in 5 repos~1.1k tokens
    DevelopmentAuto-check passed
  • Greploop

    onyx-dot-app/onyx

    Iteratively improves a PR (GitHub), MR (GitLab), or shelved changelist (Perforce) until Greptile gives it a 5/5 confidence score with zero unresolved comments.

    32k GitHub starsUsed in 4 repos~3.3k tokens
    DevelopmentAuto-check passed

More from JasonColapietro/suede-creator-skills

All 78 skills in this repo
  • Suede Release Linter

    JasonColapietro/suede-creator-skills

    Lints a local music or media release folder and scores its readiness, flagging missing files, weak metadata, artwork and stem problems, split gaps and rights blockers.

    127 GitHub stars~2.3k tokensUpdated today
    Auto-check: notes
  • Creator Rights Passport

    JasonColapietro/suede-creator-skills

    Turns messy creator materials into an offline rights-and-provenance transfer package: hashed asset inventory, intake manifest, credits, license notes and a missing-information report.

    127 GitHub stars~3.7k tokensUpdated today
    Auto-check: notes
  • Suede Clip to Guide

    JasonColapietro/suede-creator-skills

    Turns a video clip, interview moment or transcript into a package that bridges viewers to a long-form guide, with rights, claim and approval gates along the way.

    127 GitHub stars~4.1k tokensUpdated today
    Auto-check passed
  • Suede MCP Release QA

    JasonColapietro/suede-creator-skills

    Checks a Suede AI MCP server release against a live process: the full JSON-RPC lifecycle, schemas, annotations, malformed input, catalog agreement and install docs.

    127 GitHub stars~2.1k tokensUpdated today
    Auto-check passed
  • Android App Factory

    JasonColapietro/suede-creator-skills

    Takes a native Android app from product idea to Google Play release, covering Compose architecture, policy checks, privacy, billing, testing, signing and rollout.

    127 GitHub stars~2.6k tokensUpdated today
    Auto-check passed
  • Suede Ad Creative

    JasonColapietro/suede-creator-skills

    Suede-owned paid-media creative system for hooks, headlines, primary text, static and motion concepts, platform specs, review pages, and test-ready variant batches.

    127 GitHub stars~5k tokensUpdated today
    Auto-check passed

Categories

Questions about Suede Code Grader

What does Suede Code Grader do?

Suede AI blunt A-F ship grade for a code change across correctness, security and permissions, data and state, domain truth, UX and release behavior, tests and verification, and deploy readiness…. Suede Code Grader is an agent skill from JasonColapietro/suede-creator-skills. Suede AI blunt A-F ship grade for a code change across correctness, security and permissions, data and state, domain truth, UX and release behavior, tests and verification, and deploy readiness, with Instant-F triggers and evidence-based grade caps on auth, payment, migration, and public-API surfaces.

When should I use Suede Code Grader?

Suede Code Grader fits situations like: evidence-based grade caps on auth; public-API surfaces; asked to grade this; give it a letter.

How do I install Suede Code Grader in Claude Code?

Run `npx skills add JasonColapietro/suede-creator-skills --skill suede-code-grader -a claude-code`. Or copy the skill folder (skills/suede-code-grader in JasonColapietro/suede-creator-skills) into .claude/skills/suede-code-grader in your project. Claude Code loads it when a task matches its description.

How do I install Suede Code Grader in Codex?

Run `npx skills add JasonColapietro/suede-creator-skills --skill suede-code-grader -a codex`. Or copy the skill folder (skills/suede-code-grader in JasonColapietro/suede-creator-skills) into .agents/skills/suede-code-grader in your project. Codex loads it when a task matches its description.

Can I use Suede Code Grader in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add JasonColapietro/suede-creator-skills --skill suede-code-grader -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/suede-code-grader, .gemini/skills/suede-code-grader, .github/skills/suede-code-grader and .opencode/skills/suede-code-grader in your project.

What does Suede Code Grader need to run?

SKILL.md names no scripts, command-line tools or credentials: Suede Code Grader is instructions for the agent only.

Does Suede Code Grader access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Suede Code Grader safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Suede Code Grader use?

Suede Code Grader is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Suede Code Grader use?

About 3.4k tokens (SKILL.md is roughly 14k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 2k tokens, read only when the agent opens those files.

What are the alternatives to Suede Code Grader?

Skills that share tags, products or a category with Suede Code Grader: Vercel Composition Patterns (supabase/supabase, 111k stars), Finishing a Development Branch (obra/superpowers, 296k stars), Typescript Advanced Types (rolling-scopes/rsschool-app, 10k stars) and PR Babysitter (openinterpreter/openinterpreter, 69k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Suede Code Grader?

JasonColapietro (a GitHub user) maintains it in JasonColapietro/suede-creator-skills, which has 127 GitHub stars. The repository holds 78 skills in this directory. The repository was last updated on October 7, 2026.

Source: JasonColapietro/suede-creator-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.