Agent skill

Repo Conventions

by juspay in juspay/neurolink

NeuroLink's review standards — the critical rules to enforce, what NOT to comment on, the security bar, hot paths.

MITAuto-check passedAI & LLM Engineering

Install Repo Conventions

skills CLI
$ npx skills add juspay/neurolink --skill repo-conventions -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install juspay/neurolink repo-conventions --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/juspay/neurolink.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.yama/skills/repo-conventions .claude/skills/repo-conventions && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
repo-conventions
GitHub stars
148
Token cost
~1.3k tokens
SKILL.md length
620 words
Files
1
Skills in repo
3
Repo updated
First seen
Licence
MIT

At a glance

NeuroLink's review standards — the critical rules to enforce, what NOT to comment on, the security bar, hot paths.

  • Tasks that involve Text to speech and voice
  • SKILL.md covers Do NOT comment on — CI already…, The critical rules the review…, Security — the CRITICAL bar and What the review spends itself on, plus 3 more sections
  • Calls node

What it does

Repo Conventions is an agent skill from juspay/neurolink. NeuroLink's review standards — the critical rules to enforce, what NOT to comment on, the security bar, hot paths. Load before reviewing any change in this repository.

Its SKILL.md is about 1.3k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in AI & LLM Engineering, covering Text to speech and voice. It works with Model Context Protocol, OpenAI, Vercel AI SDK and TypeScript. The repository describes itself as: The pipe layer of an AI nervous system — one interface connecting provider neurons to your application, across three inference types: generate, stream, and a calibrated decide… The licence is MIT.

When your agent uses it

  • Tasks that involve Text to speech and voice

Example prompts

  • “/repo-conventions”

What it can do on your machine

Read from SKILL.md and the folder at commit 81f1070. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • node

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Repo Conventions loads about 1.3k tokens when it runs. Until then it costs about 46 tokens; SKILL.md has 620 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~46
When it runs · the whole SKILL.md, loaded when a task matches
~1.3k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from juspay/neurolink at commit 81f1070, republished under its MIT licence (© juspay). 620 words, ~1,344 tokens.

Download SKILL.mdSave it as .claude/skills/repo-conventions/SKILL.md (or your agent's skills folder).
name
repo-conventions
description
NeuroLink's review standards — the critical rules to enforce, what NOT to comment on, the security bar, hot paths. Load before reviewing any change in this repository.

Authoritative sources in this checkout (the repository root is ../):

  • ../CLAUDE.md — the engineering rules, long form. When a finding violates one, cite the specific rule (e.g. "Critical Rule 1: dynamic imports only in the registry").
  • ../CONTRIBUTING.md — contribution and commit conventions.

This skill is the review-focused digest; those files win on any conflict.

Do NOT comment on — CI already owns it

Formatting, lint and type errors — including CLAUDE.md rules 2 and 7–15 — are enforced by ESLint + Prettier + tsc and the custom AST rules in eslint-rules/ (interface vs type, type file locations, barrel rules, double assertions, e2e-only tests). Re-reporting mechanical violations buries the findings that matter. Also skip: performance micro-costs, naming and prose taste, dependency choice.

The critical rules the review DOES enforce (cite the rule number)

  • Rule 1 — dynamic imports only in the registry. Providers are imported dynamically inside factory functions in providerRegistry.ts; a static provider import is a circular-dependency bug.
  • Rule 3 — Gemini tools + JSON-schema structured output are mutually exclusive. Gated on isGeminiProvider in structuredOutputPolicy.ts, NOT on Vertex as a whole (Vertex Claude supports both). Claude paths must default max_tokens via resolveClaudeMaxTokens, never a hardcoded 4096; truncation must surface (jsonRepaired / jsonTruncated), never silently.
  • Rule 4 — CLI ≠ SDK. Manual MCP connections are CLI-only; CLI concerns must not leak into the SDK path.
  • Rule 5 — backward compatibility of the public SDK API. Non-negotiable. Name the unmodified callers a change breaks; use the code graph to find them.
  • Rule 6 — formatProviderError returns the error, never throws.
  • Rule 15 — tests are end-to-end only. Suites drive dist/index.js or the built CLI (node dist/cli/index.js); ONE module graph per suite — mixing src/ and dist/ imports breaks stubs/spies/instanceof silently. A determinism exception must be declared in the file header and in the ESLint allow list.
  • Provider executeStream goes through BaseProvider.stream() tool-merge.
  • Factory + Registry is the extension pattern (providers, processors, chunkers, rerankers) — a new extensible thing that bypasses it is a finding.

Security — the CRITICAL bar

Hardcoded secrets or credentials in source; secrets leaking into logs (confirm transformParamsForLogging / secret stripping before logging provider params); injection, unsafe eval/innerHTML/dynamic require, SSRF, path traversal; unsafe handling of user or model input. Every CRITICAL claim must be anchored in the change: quote the exact added line(s) from the diff. Placeholder values (docs, tests, "sk-your-key-here", ${ENV_VAR} references) are NOT leaked secrets — a fabricated credential-leak report is worse than a missed real one.

Show full SKILL.md (228 more words)Show less

What the review spends itself on

Logic and correctness bugs, races, unhandled rejections; provider / MCP / streaming / proxy-pool changes; missing error handling; backward compatibility (rule 5); missing coverage in the matching test/continuous-test-suite-*.ts for new behaviour.

Out-of-diff impact — use the code graph when available

The diff alone does not show the damage a change does elsewhere. Orient once (architecture overview, impact radius of the changed files, affected flows), order the file-by-file pass by blast radius, and for each changed export check its callers and dependents — signature, return shape, nullability, thrown errors, async behaviour, side effects an UNMODIFIED caller does not handle. Name the exact out-of-diff call sites. If the graph is unavailable, say impact analysis was skipped — never fabricate impact claims.

Hot paths — report at MAJOR or higher, and name the blast radius

PathWhy
src/lib/core/baseProvider.tsCentral stream() tool-merge every provider rides
src/lib/factories/providerRegistry.tsDynamic-import registry — the circular-dep tripwire
src/lib/types/**The public surface rule 5 protects
src/lib/server/routes/*ProxyRoutes.tsPool engines holding subscription credentials
src/lib/auth/**Token stores, OAuth refresh
src/lib/mcp/**What tools an agent can reach
src/lib/context/**, src/lib/memory/**Compaction/memory — silent data loss lives here

Discipline

  • Review file by file; skip lockfiles, generated or minified assets, dist/, build/, coverage/, images.
  • Read code from THIS checkout — the platform is for the pull request's comments and metadata only.
  • Conventional Commits with a required scope; ONE commit per pull request (squash-merged). Releases are generated from commit history.

© juspay, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .yama/skills/repo-conventions of juspay/neurolink.

Open the folder on GitHubat commit 81f1070

Compare with similar skills

Repo Conventions next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Repo Conventions compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Repo Conventions this skilljuspay/neurolink148—~1.3kAutomated safety check: PassMIT
Azure AImicrosoft/GitHub-Copilot-for-Azure2551 repos~852Automated safety check: PassMIT
Agent Squad for TypeScript2FastLabs/agent-squad7.8k—~4.3kAutomated safety check: PassApache-2.0
Agent Inspectrajudandigam/agent-inspect165—~424Automated safety check: PassMIT
Ydc Openai Agent SDK IntegrationLeoYeAI/openclaw-master-skills2.2k—~4.4kAutomated safety check: NotesMIT
Claude APIKocoro-lab/Kocoro4147 repos~4.5kAutomated safety check: PassApache-2.0

Similar skills

  • Azure AI

    microsoft/GitHub-Copilot-for-Azure

    Official

    A skill your agent uses for Azure AI: Search, Speech, OpenAI, Document Intelligence.

    255 GitHub starsUsed in 1 repo~852 tokens
    Media & CreativeAuto-check passed
  • Agent Squad for TypeScript

    2FastLabs/agent-squad

    Guide to building Node.js and TypeScript apps on the agent-squad package: orchestrator, agent types, classifier routing, storage, retrievers and MCP tools.

    7.8k GitHub stars~4.3k tokensUpdated 3 days ago
    AI & LLM EngineeringAuto-check passed
  • Agent Inspect

    rajudandigam/agent-inspect

    Local evidence debugger and trajectory-test toolkit for TypeScript AI agents.

    165 GitHub stars~424 tokensUpdated today
    AI & LLM EngineeringAuto-check passed
  • Ydc Openai Agent SDK Integration

    LeoYeAI/openclaw-master-skills

    Integrate OpenAI Agents SDK with You.com MCP server - Hosted and Streamable HTTP support for Python and TypeScript.

    2.2k GitHub stars~4.4k tokensUpdated 2 mo ago
    AI & LLM EngineeringAuto-check: notes
  • Claude API

    Kocoro-lab/Kocoro

    Build apps with the Claude API or Anthropic SDK. An agent skill from Kocoro-lab/Kocoro.

    414 GitHub starsUsed in 7 repos~4.5k tokens
    AI & LLM EngineeringAuto-check passed
  • Opik

    comet-ml/opik-mcp

    Reference for the Opik SDK — tracing, span types, framework integrations, threads, and the prompt library (Python, TypeScript, REST).

    220 GitHub stars~2.1k tokensUpdated 2 days ago
    AI & LLM EngineeringAuto-check passed

More from juspay/neurolink

  • Neurolink Guide

    juspay/neurolink

    Guide for using the NeuroLink SDK and CLI. An agent skill from juspay/neurolink.

    148 GitHub stars~1.4k tokensUpdated today
    Auto-check passed
  • GitHub Commenting

    juspay/neurolink

    How to post clean, rich, deduplicated GitHub PR review comments — suggestion blocks, multi-line anchors, markers, formatting rules.

    148 GitHub stars~698 tokensUpdated today
    Auto-check passed

Questions about Repo Conventions

What does Repo Conventions do?

NeuroLink's review standards — the critical rules to enforce, what NOT to comment on, the security bar, hot paths. Repo Conventions is an agent skill from juspay/neurolink. NeuroLink's review standards — the critical rules to enforce, what NOT to comment on, the security bar, hot paths.

When should I use Repo Conventions?

Repo Conventions fits situations like: tasks that involve Text to speech and voice.

How do I install Repo Conventions in Claude Code?

Run `npx skills add juspay/neurolink --skill repo-conventions -a claude-code`. Or copy the skill folder (.yama/skills/repo-conventions in juspay/neurolink) into .claude/skills/repo-conventions in your project. Claude Code loads it when a task matches its description.

How do I install Repo Conventions in Codex?

Run `npx skills add juspay/neurolink --skill repo-conventions -a codex`. Or copy the skill folder (.yama/skills/repo-conventions in juspay/neurolink) into .agents/skills/repo-conventions in your project. Codex loads it when a task matches its description.

Can I use Repo Conventions in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add juspay/neurolink --skill repo-conventions -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/repo-conventions, .gemini/skills/repo-conventions, .github/skills/repo-conventions and .opencode/skills/repo-conventions in your project.

What does Repo Conventions need to run?

Going by SKILL.md and its folder, Repo Conventions needs the command-line tools its instructions call (node).

Does Repo Conventions access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Repo Conventions safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Repo Conventions use?

Repo Conventions is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Repo Conventions use?

About 1.3k tokens (SKILL.md is roughly 5.4k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Repo Conventions?

Skills that share tags, products or a category with Repo Conventions: Azure AI (microsoft/GitHub-Copilot-for-Azure, 255 stars), Agent Squad for TypeScript (2FastLabs/agent-squad, 7.8k stars), Agent Inspect (rajudandigam/agent-inspect, 165 stars) and Ydc Openai Agent SDK Integration (LeoYeAI/openclaw-master-skills, 2.2k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Repo Conventions?

juspay (a GitHub organization) maintains it in juspay/neurolink, which has 148 GitHub stars. The repository holds 3 skills in this directory. The repository was last updated on October 11, 2026.

Source: juspay/neurolink on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.