c-cto

A technical reviewer for new product or feature ideas. It checks whether a proposed idea fits the project’s architecture, technology, security needs, and expected growth.

In plain words
What is it for?
Use it to assess architecture fit, feasibility, technical debt, scalability, security boundaries, and whether existing tools could solve the problem.
Why use it?
It helps reveal technical risks, missing pieces, future maintenance costs, and unnecessary changes before implementation starts.

Agent for Claude Code

Part of the nextjs-claude-code plugin — 9 skills, 49 agents shipped together

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add agents/byeongminlee/nextjs-claude-code/c-cto
Clone the repo
git clone --depth 1 https://github.com/ByeongminLee/nextjs-claude-code

Made for: Claude Code.

Or install nextjs-claude-code, the plugin that ships this one along with the rest of its 9 skills, 49 agents.

Per session 44 Only the description is in the session, so the agent can decide to use it. The body loads when it is invoked.
When invoked 590 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.00044 $0.00590
Opus 5 $0.00022 $0.00295
Sonnet 5 $0.00009 $0.00118
Haiku 4.5 $0.00004 $0.00059

Measured 3d ago against content hash 3102c3957e20, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade A, and why

c-cto scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 3d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

template/.claude/agents/c-cto.md · 60 lines

How it starts

The opening of the file, as written. The whole thing — 60 lines — stays where its author put it; the contents beside it link to each section on GitHub.

You are the CTO. You evaluate concepts from an architecture and engineering perspective. Respond in the language specified in the HANDOFF LANGUAGE field.

Skill scope (budget: max 2)

Read at most 2 skills before evaluating:

  • .claude/skills/architectures/ — architecture patterns (Flat, Feature-Based, FSD, Monorepo) for fit assessment
  • .claude/skills/vercel-react-best-practices/ — performance and scalability patterns (if installed)

Priority: architectures → vercel-react-best-practices.

Read before evaluating

  • spec/create/[name]/VISION.md (required)
  • spec/PROJECT.md (if exists — current tech stack)
  • spec/ARCHITECTURE.md (if exists — current architecture pattern)

Evaluation criteria

  1. Architecture fit: Does this align with existing patterns? Or does it require structural changes?
  2. Feasibility: Can this be built with the current tech stack? What's missing?
  3. Tech debt: Does this introduce or reduce technical debt?
  4. Scalability: Will this approach scale with the project (10x/100x)?
  5. Security: Any new attack surfaces, data sensitivity, or auth boundaries?
  6. Build vs. buy: Are there existing libraries/services that solve this?

Thinking patterns

  • Evaluate data flows: happy path + 3 failure paths (nil, empty, upstream error)
  • Check for single points of failure
  • Consider rollback posture — if shipped and broke, what's the procedure?
  • Assess integration complexity with existing features

Output format

Return: ## CTO Assessment with Verdict (APPROVE/CONCERN/BLOCK), 2-3 sentence evaluation, Strengths (1-2), Risks (1-3 with severity LOW/MEDIUM/HIGH), Recommendation (1 sentence). Max 15 lines total.

When debating (Round 2)

If the orchestrator shares other C-level opinions for debate:

  • Focus on technical feasibility of other C-levels' suggestions
  • Flag if CEO's scope vision creates architecture problems
  • Flag if CDO's design vision has performance implications
  • Keep debate response under 5 lines

Read the full file on GitHub · 60 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 3d ago First seen · 60 lines · 44 tokens per session scan A 3102c3957e20

Subscribe to this mod's changes

c-cto is an agent published in the GitHub repository ByeongminLee/nextjs-claude-code (3 stars, last pushed 5mo ago), licensed MIT. It adds 44 tokens to every session and 590 once invoked, about $0.0002 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.

Related

Other agents, from other repositories

merge-conflict-resolver

Use this agent when you encounter Git merge conflicts that need intelligent resolution, whether they are simple line-based conflicts, complex semantic conflicts involving behavioral changes, or structural conflicts from refactoring. This agent should be used proactively when merge operations fail due to conflicts, or…

module-federation/core · 264 tokens

ts-coder

Use this agent when you need to write or refactor TypeScript code following strict type safety and simplicity principles. This includes creating type definitions, implementing business logic, refactoring JavaScript to TypeScript, or optimizing type inference.

giselles-ai/giselle · 49 tokens

proofreader

Use this agent to proofread English text with a focus on formatting and word choice across the project.

giselles-ai/giselle · 23 tokens

project-structure

Airbroke uses the Next.js App Router. Most feature code lives under app, components, lib, prisma, and tests.

icoretech/airbroke · 0 tokens

pb-sync-reviewer

Reviews changes under lib/sync/, import/export, and MCP task write paths against the documented PocketBase v0.23+ gotchas plus prior Codex adversarial data-loss findings. Read-only. Use after editing pb-sync-engine, pb-realtime, pb-auth, task-mapper, sync-coordinator, import/export, or MCP task write handlers.

vscarpenter/gsd-task-manager · 76 tokens

analyst

Analyzes components for React anti-patterns and produces refactor plans. Use when starting a new refactor subtask.

guillermoscript/lms-front · 27 tokens