Agent skill

Vex Review Before It Runs

by myICOR in myICOR/myPKA

Review a plugin, MCP server, script, expansion pack, OAuth flow, webhook or dependency before it runs, and return a pinned verdict.

MITAuto-check passedBackend & APIs

Install Vex Review Before It Runs

skills CLI
$ npx skills add myICOR/myPKA --skill vex-review-before-it-runs -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install myICOR/myPKA vex-review-before-it-runs --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/myICOR/myPKA.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/vex-review-before-it-runs .claude/skills/vex-review-before-it-runs && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
vex-review-before-it-runs
GitHub stars
308
Token cost
~289 tokens
SKILL.md length
72 words
Files
1
Skills in repo
9
Repo updated
First seen
Licence
MIT

At a glance

Review a plugin, MCP server, script, expansion pack, OAuth flow, webhook or dependency before it runs, and return a pinned verdict.

  • The user says: is this safe to install
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md
  • Check this before I run it
  • Is this plugin safe

What it does

Vex Review Before It Runs is an agent skill from myICOR/myPKA. Review a plugin, MCP server, script, expansion pack, OAuth flow, webhook or dependency before it runs, and return a pinned verdict. Use when the user says: "is this safe to install", "check this before I run it", "is this plugin safe", "review this MCP server", "security check this pack".

Its SKILL.md is about 290 tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Backend & APIs, covering Webhooks. It works with Model Context Protocol. The repository describes itself as: AI-powered Personal Knowledge Assistance in a folder. Built on the ICOR methodology. Plain markdown. Any LLM. Yours forever. The licence is MIT.

When your agent uses it

  • The user says: is this safe to install
  • Check this before I run it
  • Is this plugin safe
  • Review this MCP server

Example prompts

  • “is this safe to install”
  • “check this before I run it”
  • “is this plugin safe”
  • “/vex-review-before-it-runs”

What it can do on your machine

Read from SKILL.md and the folder at commit 9b31da9. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Vex Review Before It Runs loads about 289 tokens when it runs. Until then it costs about 79 tokens; SKILL.md has 72 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~79
When it runs · the whole SKILL.md, loaded when a task matches
~289

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from myICOR/myPKA at commit 9b31da9, republished under its MIT licence (© myICOR). 72 words, ~289 tokens.

Download SKILL.mdSave it as .claude/skills/vex-review-before-it-runs/SKILL.md (or your agent's skills folder).
name
vex-review-before-it-runs
description
Review a plugin, MCP server, script, expansion pack, OAuth flow, webhook or dependency before it runs, and return a pinned verdict. Use when the user says: "is this safe to install", "check this before I run it", "is this plugin safe", "review this MCP server", "security check this pack".
user-invocable
true
<!-- GENERATED by scaffold-init.py from `06 AI Team/AI Team Knowledge/SOPs/EP-SOP-2031-review-third-party-code-before-it-runs.md`. content-hash:c0bb21b90910. Do not hand-edit: change the source and re-run the generator. -->

You are Vex. If you are the orchestrator, hand this to the specialist vex; if you are already Vex, act directly.

Read 06 AI Team/AI Team Knowledge/SOPs/EP-SOP-2031-review-third-party-code-before-it-runs.md now and follow it exactly. That file is the procedure; this file is the door.

Resources (open only when a step names them):

  • 06 AI Team/Agents/Vex/AGENT.md
  • 06 AI Team/AI Team Knowledge/SOPs/EP-SOP-2031-review-third-party-code-before-it-runs.md

Return the completion evidence the procedure's last step names, and nothing it does not.

© myICOR, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .claude/skills/vex-review-before-it-runs of myICOR/myPKA.

Open the folder on GitHubat commit 9b31da9

Compare with similar skills

Vex Review Before It Runs next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Vex Review Before It Runs compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Vex Review Before It Runs this skillmyICOR/myPKA308—~289Automated safety check: PassMIT
X Twitter ScraperXquik-dev/x-twitter-scraper2111 repos~2.6kAutomated safety check: PassMIT
Zalo AgentPhucMPham/zalo-agent-cli166—~2.3kAutomated safety check: PassMIT
Xquikunderstudy-ai/understudy462—~1kAutomated safety check: PassMIT
Yolfi Paymentsyolfinance/yolfi-agent178—~1.2kAutomated safety check: PassMIT
Frontmcp Channelsagentfront/frontmcp146—~3.7kAutomated safety check: PassApache-2.0

Similar skills

  • X Twitter Scraper

    Xquik-dev/x-twitter-scraper

    Use Xquik to fetch X (Twitter) data or act through a connected account: search, profiles, followers, replies, threads, timelines, media downloads, bulk exports, trends, monitors, signed webhooks…

    211 GitHub starsUsed in 1 repo~2.6k tokens
    Backend & APIsAuto-check passed
  • Zalo Agent

    PhucMPham/zalo-agent-cli

    Automate Zalo messaging, Official Account (OA), and MCP server integration via zalo-agent-cli.

    166 GitHub stars~2.3k tokensUpdated 1 mo ago
    Backend & APIsAuto-check passed
  • Xquik

    understudy-ai/understudy

    Use Xquik REST and MCP APIs for X data workflows: search public posts, inspect users, export datasets, download media, monitor accounts or keywords, and send webhook events.

    462 GitHub stars~1k tokensUpdated 3 mo ago
    Backend & APIsAuto-check passed
  • Yolfi Payments

    yolfinance/yolfi-agent

    Add Yolfi crypto checkout, payment links, and webhook handling to an app through @yolfi/agent or the Yolfi MCP server.

    178 GitHub stars~1.2k tokensUpdated 2 mo ago
    Backend & APIsAuto-check passed
  • Frontmcp Channels

    agentfront/frontmcp

    A skill your agent uses when pushing real-time notifications or events into Claude Code (or another MCP client) sessions, or building two-way chat bridges.

    146 GitHub stars~3.7k tokensUpdated today
    Backend & APIsAuto-check passed
  • Klaviyo Developer

    thatrebeccarae/claude-marketing

    Klaviyo API and developer integration expertise. An agent skill from thatrebeccarae/claude-marketing.

    161 GitHub stars~4.9k tokensUpdated 4 mo ago
    Backend & APIsAuto-check: notes

More from myICOR/myPKA

All 9 skills in this repo
  • Answers the six everyday life questions (my goals, what to focus on, the weekly priorities, the highlight of today, my key elements, what has my attention)…

    308 GitHub stars~489 tokensUpdated 5 days ago
    Auto-check: notes
  • Session Checkpoint

    myICOR/myPKA

    Ends a session on purpose: reads the checkpoint report, closes or carries every task the session touched, rules on each WiP folder with the user, links the…

    308 GitHub stars~445 tokensUpdated 5 days ago
    Auto-check: notes
  • Build or fix one web UI component in the user's code project, on the design system, typed, accessible and reviewed.

    308 GitHub stars~271 tokensUpdated 5 days ago
    Auto-check passed
  • Skill Importer

    myICOR/myPKA

    Converts an external skill (a SKILL.md package, a prompt recipe, an agent toolkit found online or on disk) into the scaffold's own shapes: procedures become…

    308 GitHub stars~372 tokensUpdated 5 days ago
    Auto-check passed
  • Make a still image in the user's own style from a brief and references, with three variants and a receipt, or write an image brief when no generator is…

    308 GitHub stars~284 tokensUpdated 5 days ago
    Auto-check passed
  • Red Tests

    myICOR/myPKA

    Feeds every guard in Scripts/ something it must reject and confirms it says no, then reports the count exactly as printed with the skips named; before a release the same suite runs against the…

    308 GitHub stars~495 tokensUpdated 5 days ago
    Auto-check: notes

Categories

Questions about Vex Review Before It Runs

What does Vex Review Before It Runs do?

Review a plugin, MCP server, script, expansion pack, OAuth flow, webhook or dependency before it runs, and return a pinned verdict. Vex Review Before It Runs is an agent skill from myICOR/myPKA. Review a plugin, MCP server, script, expansion pack, OAuth flow, webhook or dependency before it runs, and return a pinned verdict.

When should I use Vex Review Before It Runs?

Vex Review Before It Runs fits situations like: the user says: is this safe to install; check this before I run it; is this plugin safe; review this MCP server.

How do I install Vex Review Before It Runs in Claude Code?

Run `npx skills add myICOR/myPKA --skill vex-review-before-it-runs -a claude-code`. Or copy the skill folder (.claude/skills/vex-review-before-it-runs in myICOR/myPKA) into .claude/skills/vex-review-before-it-runs in your project. Claude Code loads it when a task matches its description.

How do I install Vex Review Before It Runs in Codex?

Run `npx skills add myICOR/myPKA --skill vex-review-before-it-runs -a codex`. Or copy the skill folder (.claude/skills/vex-review-before-it-runs in myICOR/myPKA) into .agents/skills/vex-review-before-it-runs in your project. Codex loads it when a task matches its description.

Can I use Vex Review Before It Runs in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add myICOR/myPKA --skill vex-review-before-it-runs -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/vex-review-before-it-runs, .gemini/skills/vex-review-before-it-runs, .github/skills/vex-review-before-it-runs and .opencode/skills/vex-review-before-it-runs in your project.

What does Vex Review Before It Runs need to run?

SKILL.md names no scripts, command-line tools or credentials: Vex Review Before It Runs is instructions for the agent only.

Does Vex Review Before It Runs access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Vex Review Before It Runs safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Vex Review Before It Runs use?

Vex Review Before It Runs is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Vex Review Before It Runs use?

About 289 tokens (SKILL.md is roughly 1.2k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Vex Review Before It Runs?

Skills that share tags, products or a category with Vex Review Before It Runs: X Twitter Scraper (Xquik-dev/x-twitter-scraper, 211 stars), Zalo Agent (PhucMPham/zalo-agent-cli, 166 stars), Xquik (understudy-ai/understudy, 462 stars) and Yolfi Payments (yolfinance/yolfi-agent, 178 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Vex Review Before It Runs?

myICOR (a GitHub organization) maintains it in myICOR/myPKA, which has 308 GitHub stars. The repository holds 9 skills in this directory. The repository was last updated on October 5, 2026.

Source: myICOR/myPKA on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.