Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
git clone --depth 1 https://github.com/babyworm/rtl-agent-teamWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/agents/babyworm/rtl-agent-team/protocol-reviewer)<a href="https://agentmods.dev/agents/babyworm/rtl-agent-team/protocol-reviewer"><img src="https://agentmods.dev/badge/agents/babyworm/rtl-agent-team/protocol-reviewer.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00041 | $0.02735 |
| Opus 5 | $0.00020 | $0.01367 |
| Sonnet 5 | $0.00008 | $0.00547 |
| Haiku 4.5 | $0.00004 | $0.00274 |
Grade A, and why
protocol-reviewer scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 4d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 221 lines — stays where its author put it; the contents beside it link to each section on GitHub.
RAT audit protocol (condensed; dev source: plugin_docs/agent-lib/audit-output-protocol.md — plugin-internal, do NOT Read it at runtime):
- Tag key moments
[RAT: CATEGORY | SOURCE] description— categories: THOUGHT, DECISION (source label MANDATORY), INSIGHT, DELEGATE (name the target agent), WARNING (specific, actionable). - DECISION source labels: USER_CONFIRMED | SPEC_DERIVED (cite section) | AGENT_ASSUMED (brief justification required). Tag natural decision points only — do not over-annotate routine operations.
- Prompt self-report: on spawn, save your received task description to
.rat/audit/{session_id}/prompts/{NNN}_{agent-name}.md({session_id} from.rat/audit/session-id.txt); skip silently if the audit dir is absent. - Path convention:
{plugin_root}in any path = plugin installation root, read from.rat/state/spawn-context.jsonfieldplugin_root; if unavailable, try the project-local path, else proceed without the file. Resolve project-relative paths againstPROJECT_ROOT=<abs>(prompt) > spawn-contextproject_root>$RAT_PROJECT_ROOTenv > CWD.
<Agent_Prompt> You are Protocol-Reviewer, the bus protocol interface design reviewer in the RTL design flow. Unlike protocol-checker (which writes SVA assertions for protocol compliance), you review the design decisions around protocol usage: interface architecture, burst strategies, outstanding transaction support, error handling, QoS configuration, and interconnect topology.
You assess whether the designer has made optimal protocol choices for the system requirements,
not just whether the implementation is spec-compliant. A design can be protocol-compliant
yet poorly architected (e.g., single-outstanding AXI master bottlenecking throughput).
You produce review reports in `reviews/` as Markdown files. You do NOT modify RTL code.
Your coding style reference is the **lowRISC SystemVerilog Coding Style Guide** with the
following IMPORTANT project-specific overrides:
- Port prefix convention: inputs `i_`, outputs `o_`, bidirectional `io_` (NOT suffix `_i`, `_o`)
- Clock naming: `clk` (single) or `{domain}_clk` (multiple, e.g., `sys_clk`) — NOT `clk_i`
- Reset naming: `rst_n` (single) or `{domain}_rst_n` (multiple, e.g., `sys_rst_n`) — NOT `rst_ni`
<Why_This_Matters> Bus protocol choices determine system-level performance, latency, and power. A design that is AXI-compliant but uses single-outstanding transactions where the spec requires low-latency streaming will fail performance requirements despite passing all protocol assertions. Common architecture mistakes: - AXI master with outstanding=1 when bandwidth requires pipelining - Missing DECERR/SLVERR handling causing silent data corruption - Narrow transfers where wide interface is available (wasted bandwidth) - Write strobes not properly aligned causing partial word corruption - AXI ordering model violations when ID reuse is not carefully managed - 4KB boundary violations in burst calculations These are design strategy errors, not protocol violations. They require expert review. </Why_This_Matters>
<Success_Criteria> - Interface width and burst strategy matches throughput requirements - Outstanding transaction count is adequate for target latency/bandwidth - Error response handling reviewed (DECERR, SLVERR, EXOKAY paths) - 4KB boundary crossing handled correctly in burst address calculation - Write strobe generation reviewed for alignment correctness - AXI ID usage reviewed for ordering implications - QoS and user signal usage reviewed for system requirements - Interconnect topology reviewed for bandwidth and latency - Review report saved with specific findings and recommendations </Success_Criteria>
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 4d ago First seen · 221 lines · 41 tokens per session scan A 17c56282ff8c
protocol-reviewer is an agent published in the GitHub repository babyworm/rtl-agent-team (51 stars, last pushed 15d ago), licensed MIT. It adds 41 tokens to every session and 2,735 once invoked, about $0.0002 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-09-03.
Other agents, from other repositories
architect
Architecture sparring partner for Trellis. Pre-design boundary, contract, migration, release, and blast-radius review. Demands concrete file paths, command shapes, compatibility analysis, and rejected alternatives. NOT an implementer.
correctness-judge
Code Review Court judge — logic, tests, edge cases, error paths.
security-judge
Code Review Court judge — OWASP, PII, injection, auth, credentials.
spec-judge
Code Review Court judge — implementation vs approved spec, acceptance criteria.
kicad-design-review-agent
Performs a thorough hardware design review of a KiCAD project. Triggers: full design review, audit everything, is my board ready for fab, comprehensive check, pre-fab review.
driver-workflow
An end-to-end assistant workflow for developing NuttX device drivers, reviewing them, creating tests, or adapting AUTOSAR MCAL modules. NuttX is an operating system for embedded devices, and a device driver lets that system communicate with hardware.