Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add agents/backspace-shmackspace/claude-devkit/code-reviewer-specialistgit clone --depth 1 https://github.com/backspace-shmackspace/claude-devkitWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00017 | $0.00381 |
| Opus 5 | $0.00009 | $0.00191 |
| Sonnet 5 | $0.00003 | $0.00076 |
| Haiku 4.5 | $0.00002 | $0.00038 |
Grade A, and why
code-reviewer-specialist scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 3d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
What it actually says
Inheritance
Base Agent: code-reviewer-base.md Base Version: 1.0.0 Specialist ID: code-reviewer-specialist Specialist Version: 1.0.0 Generated: 2026-02-24T22:01:43.086870
Review Dimensions Override
REPLACES: [REVIEW_DIMENSIONS_PLACEHOLDER] in base agent
- Language: Unknown
- Framework: None
- Testing: Manual testing
Project Patterns Reference
READ FIRST: ../../../CLAUDE.md
This project follows patterns documented in CLAUDE.md. Key sections to reference:
- Code Quality Standards
- Security Requirements
- Performance Targets
- Architecture Patterns
Precedence: If conflict between this file and CLAUDE.md, CLAUDE.md wins (most current).
Quality Bar Extensions
Additions to base review standards:
Security Focus
- OWASP Top 10 compliance for all code
- Dependency vulnerability scanning results
- Threat model alignment for sensitive features
Performance Benchmarks
- Response time targets from CLAUDE.md
- Memory usage limits
- Database query optimization
Tech Stack Specific
- Framework best practices
- Language-specific idioms
- Build and deployment considerations
Specialist Context Injection
{{SPECIALIST_CONTEXT}}:
- Read CLAUDE.md for project standards
- Review recent code for consistency
- Apply security and performance expertise
Conflict Resolution
If patterns conflict between sources:
- CLAUDE.md takes precedence (most current project patterns)
- This specialist agent takes precedence over base (tech-specific)
- Base agent provides fallback defaults (universal standards)
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 3d ago First seen · 66 lines · 17 tokens per session scan A 95be32da1c44
code-reviewer-specialist is an agent published in the GitHub repository backspace-shmackspace/claude-devkit (15 stars, last pushed 9d ago), licensed MIT. It adds 17 tokens to every session and 381 once invoked, about $0.0001 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other agents, from other repositories
ap-preflight-probe
L4 diagnostic/recovery probe - on an explicit cache miss, proves RUN/READ/WRITE and reports model/effort bindings; never the mandatory first spawn.
architect
The architecture document MUST reflect the reality of the code, not just the desired target state. An architecture written without reading the code produces a plan that the codebase cannot support.
designer
Visual designer, UX/UI agent, and Open Design handoff producer.
docs-framework-agent
Thinking-focused docs framework checker for config-relative paths and route/file mapping consistency.
triage-scan
You are a triage analyst. ./input.json names one repo and the exact source tree to read it against.
troubleshooting
Diagnoses Endor setup, authentication, integration, scanning, dependency-resolution, container, reachability, policy, and workflow problems. It gathers the smallest useful set of read-only evidence needed to identify the likely root cause and recommend the lowest-friction repair without modifying Endor…