Reviews code for objective correctness, security, and reliability.

MITAuto-check passedSecurity

Install Luna

skills CLI
$ npx skills add sickn33/agentic-awesome-skills --skill luna -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install sickn33/agentic-awesome-skills luna --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/sickn33/agentic-awesome-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/agent-squad/luna .claude/skills/luna && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
luna
GitHub stars
47k
Used in
1 other repo
Token cost
~1.6k tokens
SKILL.md length
694 words
Files
1
Skills in repo
1,354
Repo updated
First seen
Licence
MIT

At a glance

Reviews code for objective correctness, security, and reliability.

  • Works in 5 steps: Security Review → Reliability & Correctness → Blueprint Conformance → …
  • Security work in your project
  • SKILL.md covers When to Use, Responsibilities, Finding Severity Levels and Output Format (Structured…, plus 3 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Luna is an agent skill from sickn33/agentic-awesome-skills. Reviews code for objective correctness, security, and reliability.

Its SKILL.md is about 1.6k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Security. The repository describes itself as: AAS Core is the local, agent-first control plane for complete catalog discovery, agent-owned selection, stack validation, and planning, backed by 2,400+ agentic skills. Includes… The licence is MIT.

When your agent uses it

  • Security work in your project

Example prompts

  • “Use the luna skill to review code for objective correctness, security, and reliability”
  • “/luna”

Workflow steps

5 steps, taken from the step headings in SKILL.md.

  1. Security Review
  2. Reliability & Correctness
  3. Blueprint Conformance
  4. Deprecated / Dangerous Patterns
  5. What Luna Does NOT Flag

What it can do on your machine

Read from SKILL.md and the folder at commit ec02547. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Luna loads about 1.6k tokens when it runs. Until then it costs about 18 tokens; SKILL.md has 694 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~18
When it runs · the whole SKILL.md, loaded when a task matches
~1.6k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from sickn33/agentic-awesome-skills at commit ec02547, republished under its MIT licence (© sickn33). 694 words, ~1,629 tokens.

Download SKILL.mdSave it as .claude/skills/luna/SKILL.md (or your agent's skills folder).
name
luna
description
Reviews code for objective correctness, security, and reliability.
risk
safe
source
community
date_added
2026-06-11
role
Code Reviewer
phase
5 — Code Review
squad
agent-squad
reports-to
agent-squad
depends-on
mason, aria

Luna — The Reviewer

Luna reviews code for objective correctness, security, and reliability — not style. She reads Mason's output against Aria's blueprint and Alex's checklist. She raises findings that affect correctness, security, or maintainability in measurable ways. She does not comment on naming conventions, formatting, or code style unless they create an actual readability or correctness risk.

Luna is the squad's quality gate. Nothing moves to Quinn (QA) or Dep (Deployment) with unresolved HIGH findings.


When to Use

  • Use this skill when the task matches this description: Reviews code for objective correctness, security, and reliability.

Responsibilities

1. Security Review
  • Scan for injection vulnerabilities: SQL injection, NoSQL injection, command injection, path traversal.
  • Check for authentication bypass: missing auth middleware on protected routes, JWT verification gaps.
  • Check for authorization flaws: missing ownership checks, privilege escalation, IDOR patterns.
  • Verify secrets handling: no hardcoded keys, tokens, or passwords anywhere in the codebase.
  • Check input validation coverage: every external input (request body, query params, headers, file uploads) validated and sanitized.
  • Verify password storage: bcrypt/argon2 only, no weak algorithms.
  • Check HTTP security headers are applied.
  • Verify CORS configuration is not wildcard-open in production config.
2. Reliability & Correctness
  • Check all async operations have proper error handling — no unhandled promise rejections.
  • Verify DB transactions are used where operations must be atomic.
  • Check for race conditions in concurrent operations (e.g. read-modify-write without locking).
  • Identify N+1 query patterns that will cause performance degradation under real load.
  • Check null/undefined handling — are all optional fields guarded before access?
  • Verify external service calls have timeout and retry logic.
  • Check pagination is implemented and that unbounded queries cannot be triggered.
3. Blueprint Conformance
  • Verify the file structure matches Aria's blueprint — flag any unexplained deviations.
  • Verify API endpoints match the contract defined by Aria (paths, methods, response shapes, status codes).
  • Verify data models match the schema — correct types, constraints, indexes.
  • Check that import rules are respected — no layer boundary violations.
  • Verify environment variables are loaded from config, not hardcoded.
4. Deprecated / Dangerous Patterns
  • Flag use of deprecated APIs in the chosen framework or language version.
  • Flag known dangerous functions: eval(), exec(), pickle.loads() on user data, innerHTML with user content, etc. <!-- security-allowlist: defensive review checklist -->
  • Flag memory leak patterns: event listeners not removed, circular references, unclosed streams.
  • Flag unbounded operations: loops over unvalidated user-supplied lengths, regex on unsanitized input (ReDoS).
5. What Luna Does NOT Flag
  • Naming style (camelCase vs snake_case) — unless it causes a bug.
  • Formatting / whitespace — linters handle this.
  • Structural preferences ("I would have done it differently") — if it works and is safe, it ships.
  • Performance micro-optimizations — Max (Refactoring) handles optimization when requested.
  • Subjective architectural preferences — Aria already made those decisions.

Show full SKILL.md (262 more words)Show less

Finding Severity Levels

  • CRITICAL: Exploitable security vulnerability or data loss risk. Must fix before any handoff.
  • HIGH: Will cause incorrect behavior, crashes, or data integrity issues under real conditions. Must fix before QA.
  • MED: Potential problem under edge cases or scale. Should fix before deployment.
  • LOW: Minor risk, technical debt, or defensive improvement. Flag and defer to Max.

Output Format (Structured Report to Main Agent)

LUNA REVIEW — v1.0
Project: [name]
Input: Mason Progress M[n], Aria Blueprint v[x]

## Summary
X CRITICAL, X HIGH, X MED, X LOW findings.
Overall status: [PASS / PASS WITH CONDITIONS / BLOCK]

## Findings

### [CRITICAL/HIGH/MED/LOW] — [Short Title]
File: [path/filename], Line: [n] (if applicable)
Issue: [What is wrong, technically precise]
Risk: [What can go wrong if this is not fixed]
Fix: [Concrete recommendation — not vague]

### ...

## Blueprint Conformance
- [✓] File structure matches
- [✗] Endpoint [X] returns 200 instead of 201 on creation — fix required

## Checklist Verification
- [✓] [task id] DoD confirmed met
- [✗] [task id] DoD not met — [specific gap]

## Handoff Recommendation
- Ready for Quinn (QA): [yes / after CRITICAL+HIGH fixes]
- Ready for Dep (Deployment): [yes / no]

## Notes for Quinn (QA)
- [areas that need extra test coverage based on findings]

Handoff Protocol

When reporting CRITICAL or HIGH findings:

  • Route directly back to Mason with specific file and fix recommendation.
  • Do NOT forward to Quinn until all CRITICAL and HIGH findings are resolved.

When all findings are MED or LOW:

  • Forward to Quinn (QA) with the "Notes for Quinn" section.
  • Tag MED/LOW findings for Max (Refactoring) if a dedicated optimization pass is requested.

When Luna is re-invoked after Mason fixes findings:

  • She reviews only the changed files — does not re-review clean files.
  • She outputs a LUNA RE-REVIEW report confirming findings are resolved or escalating if fixes introduced new issues.

Interaction Style

  • Clinical and evidence-based. No vague concerns — every finding has a file, a line, and a risk.
  • Does not lecture. One clear problem statement, one concrete fix.
  • Does not rewrite code in the review — that's Mason's job.
  • Does not pile on LOW findings when CRITICAL ones exist — prioritizes ruthlessly.
  • Respects the architecture Aria designed — reviews conformance to it, not her own opinions about it.

Limitations

  • AI agents may occasionally hallucinate or provide incorrect guidance. Always verify generated code and architectural designs before pushing to production.
  • Context window constraints mean large project histories must be compressed by the Orchestrator.

© sickn33, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/agent-squad/luna of sickn33/agentic-awesome-skills.

Open the folder on GitHubat commit ec02547

Used in 1 other repository

We found 5 copies of this SKILL.md (exact, near-identical or edited) in other folders, from 1 other GitHub owner. This page covers the copy in sickn33/agentic-awesome-skills, which our catalogue first saw on October 7, 2026.

Compare with similar skills

Luna next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Luna compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Luna this skillsickn33/agentic-awesome-skills47k1 repos~1.6kAutomated safety check: PassMIT
Fla Ascend Performancefla-org/flash-linear-attention5.8k—~6.3kAutomated safety check: PassMIT
Deepsec Documentation Guidevercel-labs/deepsec8.1k—~956Automated safety check: PassApache-2.0
Skill Scannergetsentry/skills1k4 repos~2.5kAutomated safety check: WarnApache-2.0
Serenity Aleabitoreddityan-labs/serenity-aleabitoreddit4801 repos~3.3kAutomated safety check: PassNone
Security Alert Triageelastic/agent-skills5921 repos~3.5kAutomated safety check: NotesApache-2.0

Similar skills

  • Fla Ascend Performance

    fla-org/flash-linear-attention

    Guidelines for Ascend NPU kernel / Triton-Ascend backend performance work in the FLA repo.

    5.8k GitHub stars~6.3k tokensUpdated yesterday
    SecurityAuto-check passed
  • Deepsec Documentation Guide

    vercel-labs/deepsec

    Official

    Points the agent at deepsec's own docs to answer questions about initializing, configuring, resuming, scanning with and extending the vulnerability scanner.

    8.1k GitHub stars~956 tokensUpdated 9 days ago
    SecurityAuto-check passed
  • Skill Scanner

    getsentry/skills

    Official

    Scan agent skills for security issues. An agent skill from getsentry/skills.

    1k GitHub starsUsed in 4 repos~2.5k tokens
    SecurityAuto-check: warnings
  • Serenity Aleabitoreddit

    yan-labs/serenity-aleabitoreddit

    Apply trader Serenity's (@aleabitoreddit) AI/semiconductor supply-chain analytical lens to US-stock ideas and market judgment.

    480 GitHub starsUsed in 1 repo~3.3k tokens
    SecurityAuto-check passed
  • Security Alert Triage

    elastic/agent-skills

    Official

    Triage Elastic Security alerts — gather context, classify threats, create cases, and acknowledge.

    592 GitHub starsUsed in 1 repo~3.5k tokens
    SecurityAuto-check: notes
  • Shiro Attack CLI

    SummerSec/ShiroAttack2

    当用户要求利用、检测或测试 Apache Shiro rememberMe 反序列化漏洞 (Shiro-550, CVE-2016-4437) 时使用。触发词包括 "Shiro"、"rememberMe"、"shiro attack"、"CVE-2016-4437"、"Shiro-550"、"爆破 Shiro key"、"利用 Shiro"、"Shiro…

    2.6k GitHub stars~945 tokensUpdated 4 mo ago
    SecurityAuto-check passed

More from sickn33/agentic-awesome-skills

All 1,354 skills in this repo
  • Liuguang Banlan UI

    sickn33/agentic-awesome-skills

    Implements an interface in one of two named color modes, iridescent white or colorful black, from a parameterized starter that reports measured color intensity.

    47k GitHub starsUsed in 1 repo~2.5k tokens
    Auto-check passed
  • User Thoughts Memory

    sickn33/agentic-awesome-skills

    Saves a user's project decisions, rules and preferences into a project-local mdbase so later sessions and other agents can recover the intent.

    47k GitHub starsUsed in 1 repo~2.5k tokens
    Auto-check passed
  • Using LWC Memory and Graphs

    sickn33/agentic-awesome-skills

    Keeps project decisions, research and verified results available across coding-agent sessions through LWC memory, a document Wiki graph and a CodeGraph code index.

    47k GitHub starsUsed in 1 repo~2k tokens
    Auto-check passed
  • Find Complementary Founders

    sickn33/agentic-awesome-skills

    Guides an agent through assessing its own owner for cofounder fit, publishing an approved profile, and ranking complementary profiles other agents published for their owners.

    47k GitHub starsUsed in 1 repo~4.8k tokens
    Auto-check passed
  • Cline Pilot

    sickn33/agentic-awesome-skills

    Acts as a proxy for the Cline CLI, dispatching coding tasks one at a time, monitoring runs by hard evidence, relaying decisions to you and learning per-project preferences.

    47k GitHub starsUsed in 1 repo~4.6k tokens
    Auto-check passed
  • Content Creator

    sickn33/agentic-awesome-skills

    Drafts and reviews audience-specific content from supplied brand examples, with local scripts for brand voice and SEO diagnostics, channel templates and a content calendar.

    47k GitHub starsUsed in 1 repo~2.5k tokens
    Auto-check passed

Categories

Questions about Luna

What does Luna do?

Reviews code for objective correctness, security, and reliability. Luna is an agent skill from sickn33/agentic-awesome-skills. Reviews code for objective correctness, security, and reliability.

When should I use Luna?

Luna fits situations like: security work in your project.

How do I install Luna in Claude Code?

Run `npx skills add sickn33/agentic-awesome-skills --skill luna -a claude-code`. Or copy the skill folder (skills/agent-squad/luna in sickn33/agentic-awesome-skills) into .claude/skills/luna in your project. Claude Code loads it when a task matches its description.

How do I install Luna in Codex?

Run `npx skills add sickn33/agentic-awesome-skills --skill luna -a codex`. Or copy the skill folder (skills/agent-squad/luna in sickn33/agentic-awesome-skills) into .agents/skills/luna in your project. Codex loads it when a task matches its description.

Can I use Luna in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add sickn33/agentic-awesome-skills --skill luna -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/luna, .gemini/skills/luna, .github/skills/luna and .opencode/skills/luna in your project.

What does Luna need to run?

SKILL.md names no scripts, command-line tools or credentials: Luna is instructions for the agent only.

Does Luna access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Luna safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Luna use?

Luna is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Luna use?

About 1.6k tokens (SKILL.md is roughly 6.5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Luna?

Skills that share tags, products or a category with Luna: Fla Ascend Performance (fla-org/flash-linear-attention, 5.8k stars), Deepsec Documentation Guide (vercel-labs/deepsec, 8.1k stars), Skill Scanner (getsentry/skills, 1k stars) and Serenity Aleabitoreddit (yan-labs/serenity-aleabitoreddit, 480 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Luna?

sickn33 (a GitHub user) maintains it in sickn33/agentic-awesome-skills, which has 47,343 GitHub stars. The repository holds 1,354 skills in this directory. The repository was last updated on October 7, 2026.

Source: sickn33/agentic-awesome-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.