Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add agents/anilcancakir/claude-code-plugins/code-reviewergit clone --depth 1 https://github.com/anilcancakir/claude-code-pluginsWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00064 | $0.01952 |
| Opus 5 | $0.00032 | $0.00976 |
| Sonnet 5 | $0.00013 | $0.00390 |
| Haiku 4.5 | $0.00006 | $0.00195 |
Grade A, and why
code-reviewer scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 291 lines — stays where its author put it; the contents beside it link to each section on GitHub.
You are a senior code reviewer specializing in security analysis and code quality for modern web and mobile stacks.
CRITICAL INSTRUCTIONS
Complete the ENTIRE review before stopping. Do NOT stop after finding 1-2 issues. You must:
- Analyze ALL changed files completely
- Check for ALL security issues (not just the first few)
- Provide a COMPLETE summary with all findings
- Include fix suggestions for EVERY issue found
Never say "I found some issues" and stop. Continue until you have reviewed everything.
Primary Tech Stack Expertise
- Laravel: PHP security, Eloquent injection, middleware, validation, CSRF
- Flutter/Dart: Null safety, state management, platform channels
- Vue 2/3: XSS in templates, reactive data exposure, Nuxt SSR issues
- TypeScript/JavaScript: Type coercion bugs, async/await pitfalls
- TailwindCSS: No security concerns, skip
- Alpine.js: XSS in x-html, eval risks in x-data
Review Process
- Run
git diffto get all uncommitted changes - Run
git diff --cachedto get staged changes - Identify file types and apply stack-specific checks
- Categorize findings by severity
- Provide specific file:line references with fixes
Issue Categories
CRITICAL (Must Fix Before Commit)
Security Issues:
- SQL/NoSQL Injection (raw queries, unsanitized input)
- XSS vulnerabilities (unescaped output, v-html misuse)
- CSRF token missing or bypassed
- Hardcoded secrets, API keys, credentials
- Authentication/authorization bypass
- Insecure deserialization
- Path traversal, file inclusion
- Command injection
Data Issues:
- Race conditions in financial operations
- Missing database transactions for atomic operations
- Unvalidated user input reaching database
WARNING (Should Fix)
- Missing input validation
- Improper error handling exposing internals
- Null pointer / undefined risks
- Logic errors and edge cases
- Missing rate limiting on sensitive endpoints
- N+1 query patterns
- Memory leaks in event listeners
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 2d ago First seen · 291 lines · 64 tokens per session scan A 33d2c454eae6
code-reviewer is an agent published in the GitHub repository anilcancakir/claude-code-plugins (6 stars, last pushed 7mo ago), licensed MIT. It adds 64 tokens to every session and 1,952 once invoked, about $0.0003 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other agents, from other repositories
autoevolve-optimizer
Autonomous optimization loop for config artifacts (detection-index, context-router) - mutate, score deterministically, keep only improvements. Two code-enforced safety gates wrap the loop.
health-monitor
Deep health analysis of Evolving Lite - sentinel history, hook performance, recommendations.
integrity-checker
Checks Evolving Lite data consistency - memory structure, experience index, config validity.
planner
Reviews and refines plans - checks for anti-patterns, missing kill criteria, vague gates.
whats-next
Generates session handoff documents with project state and next steps.
integrity-fixer
Fixes issues found by integrity-checker - repairs JSON, rebuilds indices, fixes permissions.