Reviews pasted code that announces published articles to social channels (Bluesky, Mastodon, a Facebook page, Pinterest through a feed, Tumblr, DEV) for the ways a channel stays silent or posts twice, which tests with a fake network and a green build do not catch. It flags a shared HTTP helper that cuts a response body the Bluesky login then parses, a text cut by UTF-16 position or link offsets taken from character positions instead of UTF-8 bytes, a Mastodon media upload judged by status 200 only, a link posted without uploading the picture, a missing write:media scope, an Idempotency-Key reused after its one hour, an alert cut to N characters of an HTML error page, dispatch called from cache invalidation, a new "announced" column without a backfill, Promise.all or no timeout around channels, a missing token treated as an error, staging that posts, a full article copied to a blog platform, an OAuth 1.0a signature that leaves out the form body, a DEV request from a Worker without a User-Agent, and duplicates counted by searching a title in an RSS feed. Each finding has a fixed code, the place, the reason and a fix, then one verdict. Use to review article-announcing code before release, to find why a channel never posts, or to check a new channel before its first live post.
Social Dispatch Code Review: Bluesky, Mastodon, DEV is a tested SKILL.md that reviews pasted code that announces published articles to social channels (Bluesky, Mastodon, a Facebook page, Pinterest through a feed, Tumblr, DEV) for the ways a channel stays silent or posts twice, which tests with a fake network and a green build do not catch; an agent buys it once for $0.03 over x402.
Not for
What the networks allow, cost or limit (use social-api-reality-2026), general code review or security, and anything the paste does not show: it reads pasted code, so a function that is called but not pasted is unknown, not a finding. Facts dated 2026-10-08; the networks change often, and the incident-based ones (see the changelog) were not re-checked against public documentation.
Tested, honestly
Tested 2026-10-08 with a strong and a weak model.
With and without the skill
Results with and without the skill, for Sonnet and Haiku |
| with | without | with | without |
|---|
| Snippets reviewed right (24 snippets) |
| Snippets reviewed right (24 snippets) | 24/24 | 21/24 | 24/24 | 19/24 |
|---|
Same request on both sides, a fence removed first. Read by hand, Sonnet without the skill already caught the timeouts, the sequential loop, the token that is not checked, the replay window and the scope change. It missed three: it trusted Mastodon to build a preview card from the article page, it kept the first 400 characters of an HTML error page as the log line, and it did not know that the DEV API refuses a Worker request that carries no User-Agent. Haiku without the skill missed the same three, plus the Mastodon feed that counts one post twice and the missing token that should switch a channel off. Without the skill both models also raised alarms on most sound snippets; that is not counted.
Same cases and the same checks with and without the skill. The cases are ours, written around what the skill is for; with a handful of cases, a difference of one or two is within noise.
- SonnetStrong model, claude-sonnet-5-5
- Right on all 24 snippets in substance, read by hand: it asked for a media upload instead of hoping for a preview card, for the page title instead of the first characters of an HTML error page, for an honest User-Agent toward the DEV API, for counting items rather than strings in a Mastodon feed, for a quiet switch-off when a token is missing, and caught the scope change that replaces the token, the replay key window, the timeouts and the sequential loop. On two snippets the form slipped: once it put No findings. and the verdict on one line, once it listed a code with the words "does not apply".
- HaikuWeak model, claude-haiku-5-5
- Right on all 24 snippets in substance, read by hand, with the same findings as Sonnet, and No findings. on the eight sound snippets. On two snippets it also reported true problems our key had not listed: a post made of title and address only, and a loop that one thrown request stops.
Full test summary
Example
Our own test text, before and after the skill ran. Excerpts only.
English · claude-sonnet-5-5
Before
// src/social/http.ts — one helper for every channel
export async function call(url: string, init: RequestInit) {
const res = await fetch(url, { ...init, signal: AbortSignal.timeout(8000) });
const text = (await res.text()).slice(0, 400); // keep the logs short
return { ok: res.ok, status: res.status, text };
}…
After
[BODY-SLICED] src/social/http.ts:call (used by src/social/bluesky.ts:login): the shared helper cuts every response body to 400 characters and returns the cut text, and the Bluesky login runs `JSON.parse` on it; the session answer holds two long tokens and a did, so it can pass 400 characters and the cut text is not valid JSON, and the login fails with an error that looks like the network's…
What is in the file
- The answer
- Rules that keep the review honest
- Group 1: the channel stays silent, or posts wrong, in normal use (verdict will misbehave)
- Group 2: works today, fails or misleads later (verdict fix before release)
- Work in this order
- Short example
- When this was checked
Languages
Any language. Tried in: English.
License
Perpetual, non-exclusive; use and modify for yourself incl. paid work; no resale or republishing. Holder: Georgi Kalchev, aiskills402.com. Full terms.
Versions
Current version 1.0.0, updated 2026-10-08. Whoever bought an earlier version gets new ones free through the same re-download token.
v1.0.0 · 2026-10-08
First release: reviews pasted code that announces published articles to social channels and lists each mistake with a fixed code, the place, the reason and a fix, then a verdict (will misbehave, fix before release, no known pitfalls). The skill carries from the start the rule that only what the paste shows is reported and unseen code is unknown.
Facts re-checked on 2026-10-08 by read-only fetch of the vendors' own pages: the Bluesky link-facet schema (byteStart and byteEnd are bytes of the UTF-8 text, the end excluded) and the post schema (text limit 300 graphemes, and 3000 as a plain length); the Mastodon media method (answers 200 when processed at once and 202 while processing; since version 4.0 smaller images get 200 and larger video and audio get 202; scope write:media; optional description) and the status method (Idempotency-Key kept at most one hour); the Meta page on app modes (content made in development mode is visible only to people with a role on the app, and becomes visible after the switch to Live).
Not re-checked (owner-measured from incidents, September to October 2026): the body cut that breaks only the Bluesky login (dom-bg, 22 September), no preview card fetched by Mastodon, the Mastodon scope change replacing the token, the HTML error page, dispatch from cache invalidation, the missing backfill (573 articles), the DEV refusal of a request without a User-Agent (4 October; DEV's API documentation does not mention it), the Tumblr signature rules, the title counted twice in the profile feed. The Pinterest feed rules are not a code check here and stay in social-api-reality-2026.
Price starts at $0.04; the measured Sonnet result with and without the skill decides it.
FAQ
Eighteen mistakes: what are they?
Eighteen mistakes in two groups. Seven make a channel silent or wrong in normal use: a shared helper that cuts the body the Bluesky login parses, announcing from cache invalidation, a new announced column with no backfill, a missing write:media scope, staging that posts, an OAuth 1.0a signature without the form body, a DEV request from a Worker with no User-Agent. Eleven fail later: UTF-16 cuts, link offsets in characters, a media upload judged by 200 only, a key replayed after an hour, Promise.all around channels.
Does it also say what the networks cost or allow?
No, it reads code only. Prices, plans and limits of the networks are in the separate skill social-api-reality-2026, and the two are written so that they do not repeat each other.
Does it complain about sound code?
It is written not to. Its first rule is to name only what is visible in the paste, and eight of the twenty-four test snippets are sound code that must come back as exactly No findings: a dispatcher with allSettled and timeouts, a Bluesky card, link offsets counted in bytes, a Mastodon upload that polls, an error text that reads the HTML title, a correct OAuth 1.0a signature, a DEV request with an honest User-Agent and a backfilled column.
Does it help Claude Sonnet?
Three facts it could not know made the difference. We gave twenty-four dispatch snippets to Sonnet and Haiku, once loaded and once not. On its own Sonnet found the timeouts, loops and token mistakes, but trusted Mastodon to build a preview card, logged the first characters of an HTML error page, and missed that the DEV API refuses a Worker request with no User-Agent. That is 21 of 24 bare and 24 with the file. Haiku rose from 19 to 24. Bare, both models also flagged most of the sound snippets.