Code & Engineering

Social Dispatch Code Review: Bluesky, Mastodon, DEV

Reviews pasted code that announces published articles to social channels (Bluesky, Mastodon, a Facebook page, Pinterest through a feed, Tumblr, DEV) for the ways a channel stays silent or posts twice, which tests with a fake network and a green build do not catch. It flags a shared HTTP helper that cuts a response body the Bluesky login then parses, a text cut by UTF-16 position or link offsets taken from character positions instead of UTF-8 bytes, a Mastodon media upload judged by status 200 only, a link posted without uploading the picture, a missing write:media scope, an Idempotency-Key reused after its one hour, an alert cut to N characters of an HTML error page, dispatch called from cache invalidation, a new "announced" column without a backfill, Promise.all or no timeout around channels, a missing token treated as an error, staging that posts, a full article copied to a blog platform, an OAuth 1.0a signature that leaves out the form body, a DEV request from a Worker without a User-Agent, and duplicates counted by searching a title in an RSS feed. Each finding has a fixed code, the place, the reason and a fix, then one verdict. Use to review article-announcing code before release, to find why a channel never posts, or to check a new channel before its first live post.

Social Dispatch Code Review: Bluesky, Mastodon, DEV is a tested SKILL.md that reviews pasted code that announces published articles to social channels (Bluesky, Mastodon, a Facebook page, Pinterest through a feed, Tumblr, DEV) for the ways a channel stays silent or posts twice, which tests with a fake network and a green build do not catch; an agent buys it once for $0.03 over x402.

Tested 2026-10-08No code, no hidden instructionsv1.0.0 · 13.7 KB · perpetual license

Not for

What the networks allow, cost or limit (use social-api-reality-2026), general code review or security, and anything the paste does not show: it reads pasted code, so a function that is called but not pasted is unknown, not a finding. Facts dated 2026-10-08; the networks change often, and the incident-based ones (see the changelog) were not re-checked against public documentation.

Tested, honestly

Tested 2026-10-08 with a strong and a weak model.

With and without the skill

Results with and without the skill, for Sonnet and Haiku
SonnetHaiku
withwithoutwithwithout
Snippets reviewed right (24 snippets)24/2421/2424/2419/24

Same request on both sides, a fence removed first. Read by hand, Sonnet without the skill already caught the timeouts, the sequential loop, the token that is not checked, the replay window and the scope change. It missed three: it trusted Mastodon to build a preview card from the article page, it kept the first 400 characters of an HTML error page as the log line, and it did not know that the DEV API refuses a Worker request that carries no User-Agent. Haiku without the skill missed the same three, plus the Mastodon feed that counts one post twice and the missing token that should switch a channel off. Without the skill both models also raised alarms on most sound snippets; that is not counted.

Same cases and the same checks with and without the skill. The cases are ours, written around what the skill is for; with a handful of cases, a difference of one or two is within noise.

SonnetStrong model, claude-sonnet-5-5
Right on all 24 snippets in substance, read by hand: it asked for a media upload instead of hoping for a preview card, for the page title instead of the first characters of an HTML error page, for an honest User-Agent toward the DEV API, for counting items rather than strings in a Mastodon feed, for a quiet switch-off when a token is missing, and caught the scope change that replaces the token, the replay key window, the timeouts and the sequential loop. On two snippets the form slipped: once it put No findings. and the verdict on one line, once it listed a code with the words "does not apply".
HaikuWeak model, claude-haiku-5-5
Right on all 24 snippets in substance, read by hand, with the same findings as Sonnet, and No findings. on the eight sound snippets. On two snippets it also reported true problems our key had not listed: a post made of title and address only, and a loop that one thrown request stops.

Full test summary

Example

Our own test text, before and after the skill ran. Excerpts only.

English · claude-sonnet-5-5

Before

// src/social/http.ts — one helper for every channel export async function call(url: string, init: RequestInit) { const res = await fetch(url, { ...init, signal: AbortSignal.timeout(8000) }); const text = (await res.text()).slice(0, 400); // keep the logs short return { ok: res.ok, status: res.status, text }; }…

After

[BODY-SLICED] src/social/http.ts:call (used by src/social/bluesky.ts:login): the shared helper cuts every response body to 400 characters and returns the cut text, and the Bluesky login runs `JSON.parse` on it; the session answer holds two long tokens and a did, so it can pass 400 characters and the cut text is not valid JSON, and the login fails with an error that looks like the network's…

What is in the file

  • The answer
  • Rules that keep the review honest
  • Group 1: the channel stays silent, or posts wrong, in normal use (verdict will misbehave)
  • Group 2: works today, fails or misleads later (verdict fix before release)
  • Work in this order
  • Short example
  • When this was checked

Languages

Any language. Tried in: English.

License

Perpetual, non-exclusive; use and modify for yourself incl. paid work; no resale or republishing. Holder: Georgi Kalchev, aiskills402.com. Full terms.

Versions

Current version 1.0.0, updated 2026-10-08. Whoever bought an earlier version gets new ones free through the same re-download token.

  1. v1.0.0 · 2026-10-08

    First release: reviews pasted code that announces published articles to social channels and lists each mistake with a fixed code, the place, the reason and a fix, then a verdict (will misbehave, fix before release, no known pitfalls). The skill carries from the start the rule that only what the paste shows is reported and unseen code is unknown.

    Facts re-checked on 2026-10-08 by read-only fetch of the vendors' own pages: the Bluesky link-facet schema (byteStart and byteEnd are bytes of the UTF-8 text, the end excluded) and the post schema (text limit 300 graphemes, and 3000 as a plain length); the Mastodon media method (answers 200 when processed at once and 202 while processing; since version 4.0 smaller images get 200 and larger video and audio get 202; scope write:media; optional description) and the status method (Idempotency-Key kept at most one hour); the Meta page on app modes (content made in development mode is visible only to people with a role on the app, and becomes visible after the switch to Live).

    Not re-checked (owner-measured from incidents, September to October 2026): the body cut that breaks only the Bluesky login (dom-bg, 22 September), no preview card fetched by Mastodon, the Mastodon scope change replacing the token, the HTML error page, dispatch from cache invalidation, the missing backfill (573 articles), the DEV refusal of a request without a User-Agent (4 October; DEV's API documentation does not mention it), the Tumblr signature rules, the title counted twice in the profile feed. The Pinterest feed rules are not a code check here and stay in social-api-reality-2026.

    Price starts at $0.04; the measured Sonnet result with and without the skill decides it.

FAQ

Eighteen mistakes: what are they?

Eighteen mistakes in two groups. Seven make a channel silent or wrong in normal use: a shared helper that cuts the body the Bluesky login parses, announcing from cache invalidation, a new announced column with no backfill, a missing write:media scope, staging that posts, an OAuth 1.0a signature without the form body, a DEV request from a Worker with no User-Agent. Eleven fail later: UTF-16 cuts, link offsets in characters, a media upload judged by 200 only, a key replayed after an hour, Promise.all around channels.

Does it also say what the networks cost or allow?

No, it reads code only. Prices, plans and limits of the networks are in the separate skill social-api-reality-2026, and the two are written so that they do not repeat each other.

Does it complain about sound code?

It is written not to. Its first rule is to name only what is visible in the paste, and eight of the twenty-four test snippets are sound code that must come back as exactly No findings: a dispatcher with allSettled and timeouts, a Bluesky card, link offsets counted in bytes, a Mastodon upload that polls, an error text that reads the HTML title, a correct OAuth 1.0a signature, a DEV request with an honest User-Agent and a backfilled column.

Does it help Claude Sonnet?

Three facts it could not know made the difference. We gave twenty-four dispatch snippets to Sonnet and Haiku, once loaded and once not. On its own Sonnet found the timeouts, loops and token mistakes, but trusted Mastodon to build a preview card, logged the first characters of an HTML error page, and missed that the DEV API refuses a Worker request with no User-Agent. That is 21 of 24 bare and 24 with the file. Haiku rose from 19 to 24. Bare, both models also flagged most of the sound snippets.

Share

Read this page as Markdown: /skills/social-dispatch-code-review.md.

  • Social API Reality 2026

    Marketing & Copy

    SKILL.md · v1.0.0 · 8.6 KB

    Tells a publishing agent what the social networks allow, cost and return in autumn 2026, checked on 8 October 2026, before it plans or writes the posting code. Covers X (no free tier, pay per request, a post with a link costs more), Hashnode (public API now needs a paid plan), Pinterest feed auto-publish (domain claim, first board by alphabet, image tag, first pins within the hour), Mastodon (media 202, scopes, token replacement, one-hour Idempotency-Key, no card fetched), Bluesky (three length units, byte offsets, card thumbnail upload, write budget) and Meta (Development mode versus Live). Answers as JSON when asked and says which facts to re-check. Use when asked to plan, write, fix or review automatic posting of articles to social networks, or why posts do not appear.

    $0.05once

    • x402
    • USDC
    • Base
    Get skill

    Tested with Sonnet and Haiku, 8 Oct 2026

  • Workers Pitfalls Review: D1, OpenNext, Fetch

    Code & Engineering

    SKILL.md · v1.2.0 · 9.8 KB

    Reviews pasted Cloudflare Workers code and configuration (a Worker, a Next.js app on OpenNext, D1 queries, wrangler config) for platform pitfalls that pass every local test and then fail in production or quietly cost money. It flags the edge runtime under OpenNext, a fetch to your own Worker's workers.dev address (error 1042), D1 queries that bind more than 100 parameters as data grows, LIKE patterns over D1's 50-byte limit, reading rowsAffected where D1 returns meta.changes, interactive transactions D1 does not have, secrets kept in plain vars, outbound fetch code that treats only a thrown error as failure, a browser User-Agent that bot protection challenges, client hop-by-hop headers forwarded to fetch, cron triggers whose day of the week is written as numbers, and unbounded queries on the request path. Each finding has a fixed code, the place, the reason and a fix, then one verdict. Use to review a Cloudflare Worker before deploy, check D1 or wrangler code, or audit a Next.js app running on Cloudflare.

    $0.05once

    • x402
    • USDC
    • Base
    Get skill

    Tested with Sonnet and Haiku, 8 Oct 2026

  • RSS Feed Builder

    SEO & Content

    SKILL.md · v1.0.0 · 11.6 KB

    Writes an RSS 2.0 file, or an Atom one when asked, from a list of posts, answered as the XML only with no fence and no sentence around it. Dates are RFC 822 with a correct weekday, never ISO; a post with no date gets no date, a post with no image gets no image and a post with no summary gets no description, so nothing is invented. Ampersands are escaped, HTML summaries go in CDATA, every link is absolute, the guid never changes, and the Atom namespace with a self link is declared. For Pinterest auto-publish it adds the image, title, description and link the importer needs. Use when asked to build, fix or check an RSS feed or an Atom feed for readers or for Pinterest.

    $0.02once

    • x402
    • USDC
    • Base
    Get skill

    Tested with Sonnet and Haiku, 8 Oct 2026