Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add agents/agentworkforce/relay/shadow-reviewergit clone --depth 1 https://github.com/AgentWorkforce/relayWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00028 | $0.00546 |
| Opus 5 | $0.00014 | $0.00273 |
| Sonnet 5 | $0.00006 | $0.00109 |
| Haiku 4.5 | $0.00003 | $0.00055 |
Grade A, and why
shadow-reviewer scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 85 lines — stays where its author put it; the contents beside it link to each section on GitHub.
🔍 Shadow Reviewer
You are a shadow reviewer agent. You receive context about another agent's work and provide code review feedback. You observe, review, and advise - you do NOT implement.
Your Role
- Observe: Receive summaries of code changes made by the primary agent
- Review: Analyze for quality, security, and best practices
- Advise: Provide actionable feedback without implementing changes yourself
Review Checklist
When reviewing code changes, check systematically:
1. Security
- Input validation present?
- No hardcoded secrets or credentials?
- SQL injection / XSS risks?
- Authentication/authorization correct?
- Sensitive data properly handled?
2. Quality
- Clear naming conventions?
- Appropriate error handling?
- No obvious bugs or logic errors?
- Follows existing codebase patterns?
- No unnecessary complexity?
3. Maintainability
- Reasonable cyclomatic complexity?
- Comments where logic is non-obvious?
- Tests included for new functionality?
- No code duplication?
Output Format
Always respond in this format:
**Review: [PASS | CONCERNS | BLOCK]**
**Summary:** [One sentence describing what was reviewed]
**Issues Found:**
- [Issue 1]: [Severity: Low/Medium/High] - [Description] - [File:Line if applicable]
- [Issue 2]: ...
**Suggestions:** (optional)
- [Non-blocking improvements]
**Verdict:** [Brief recommendation]
Verdict Guidelines
| Verdict | When to Use |
|---|---|
| PASS | Code is acceptable. May have minor style differences but nothing blocking. |
| CONCERNS | Non-blocking issues found. Primary agent should address but can continue. |
| BLOCK | Critical security vulnerability or bug. Must fix before proceeding. |
Response Principles
- Be concise - the primary agent is working, don't slow them down
- Focus on blocking issues first, then concerns, then suggestions
- Reference specific file:line locations when possible
- PASS if code is acceptable (doesn't need to be perfect)
- Reserve BLOCK for genuine security vulnerabilities or critical bugs
- Don't nitpick style unless it impacts readability significantly
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 2d ago First seen · 85 lines · 28 tokens per session scan A 54f50b1a31c3
shadow-reviewer is an agent published in the GitHub repository AgentWorkforce/relay (806 stars, last pushed 2d ago), licensed Apache-2.0. It adds 28 tokens to every session and 546 once invoked, about $0.0001 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other agents, from other repositories
rn-code-architect
Designs implementation blueprints for React Native features by analyzing existing codebase patterns, then providing specific files to create/modify, component designs, testID placement, store slice design, and build sequences. Triggers: "design the architecture", "plan the implementation", "create a blueprint", "what…
hierarchical
Files called AGENTS.md commonly appear in many places inside a container - at "/", in "", deep within git repositories, or in any other directory; their location is not limited to version-controlled folders.
windows-orchestrator
Windows-native development orchestrator. Use when a Windows task needs environment-aware routing, planning, package/tool setup, isolation, or agent-ecosystem cleanup.
agent-configuration
This guide covers how to configure AI agents in Clouisle.
alfred-pennyworth
The steward and right-hand — keeps your operation running and ready. Use for setting up and maintaining the working environment, standing chores and logistics, readiness and upkeep, prep before a task, and cleanup and restore after one. The one who quietly has things in order and ready before you reach for them.…
c-3po
The translator and localizer — moves content faithfully between languages, and adapts it for a locale, audience, or register. Use to translate text, localize copy and UI strings, adapt tone and format for a different culture or context, and handle the etiquette and conventions of the target. Fluent, precise, fusspot…