review-skill skillA
review-skill is agent-read markdown (skill) from runxhq/runx: Inspect, safely test, and assess one Runx skill package for capability, trust, and operator readiness. Use when deciding whether to adopt, improve, reject, install, or publish a skill; its evidence-only assess runner is available when native test evidence already exists..
Indexed from public GitHub and served as immutable, content-addressed versions. Install it pinned to an exact SHA-256 with the mdr CLI, and every file is verified against the hash recorded here before it reaches your agent. The deterministic audit below grades the latest version, and the same file always earns the same grade.
What the file says
# Review Skill Evaluate one skill from bounded evidence. The default runner passes a local package to native `runx.skill.validate`, which parses and inspects the exact package, runs read-only or planning harnesses with isolated receipts and no operator credentials, and forwards that evidence to the focused assessment runner. Execute-capable targets are inspected but never run automatically. This skill does not mutate the package, publish a report, install a package, or manufacture missing evidence. Use `assess` directly when a caller already has a bounded evidence pack. ## Procedure 1. Resolve a workspace- or owning-skill-relative package path and capture its native capability and readiness envelope. Registry or marketplace material must first be installed or supplied as a bounded evidence pack; this skill does not fetch it implicitly. 2. Run the native harness only when catalog execution is `read` or `plan`. 3. Compare the documented capability with the inspected runner and catalog metadata in the evidence pack. 4. Separate native harness results, provider readback, supplied assertions, and unverified claims. …
Read the whole file at its exact version.
How to install
mdr add runxhq/runx/review-skill@git:20260803.0993e04mdr add runxhq/runx/review-skill@sha256:0bb55d42aad95cdfPin to a label to follow the author's releases, or to a sha256 to freeze the exact bytes forever. Either way the resolved hash is written to mdr.lock, and mdr install reproduces it on any machine.
[](https://markdownregistry.com/a/art_y5c5liwxjfva7km2)
1 badge views in 30 days
Versions
| version | committed | commit | size | audit | |
|---|---|---|---|---|---|
| git:20260803.0993e04 latest | 2026-08-03 | 0993e04 | 3,862 B | A | view · diff |
| git:20260723.6e5370b | 2026-07-23 | 6e5370b | 3,883 B | A | view · diff |
| git:20260716.fa2dea2 | 2026-07-16 | fa2dea2 | 2,914 B | A | view · diff |
| git:20260715.f00df98 | 2026-07-15 | f00df98 | 2,444 B | A | view · diff |
| git:20260620.d28892f | 2026-06-20 | d28892f | 3,488 B | A | view |
Audit of the latest version
- pass: Frontmatter block present
- pass: Frontmatter declares a name
- pass: Frontmatter declares a description
- pass: Size between 200 bytes and 200 KB (3862 bytes)
- pass: No zero-width or bidi control characters
- pass: No instruction hidden inside an HTML comment
- pass: No link to an exfiltration or paste host
- pass: No credential-shaped string
- pass: No instruction to send local credentials anywhere
- pass: No text hidden with inline styles
- pass: No prompt-injection phrasing
- pass: No curl or wget piped into a shell
- pass: No recursive delete of root, home or parent
- pass: No instruction to read or print local credentials
- pass: No base64 blob over 200 characters
- pass: No link to a raw IP address
- pass: No script tag
Source
runxhq/runx · 93 stars · license Apache-2.0 · pushed 2026-09-24 · branch main
API
GET https://markdownregistry.com/api/v1/artifacts/art_y5c5liwxjfva7km2 GET https://markdownregistry.com/api/v1/resolve?ref=runxhq/runx/review-skill GET https://markdownregistry.com/api/v1/blob/0bb55d42aad95cdf5c2d5bd765a1dd79a2adc691b8cb6eba902b673216dfc50c
Your agent does the legwork. You hear about the deals worth your word. Hand yours the standing instructions at modelranch.com and it joins the network that reads files like this one.