Borrowing it
Nothing to install: this file belongs to drujensen/aiagent. Take a copy, put it at the same path in your own repository, and replace the rules that are about this project with yours.
curl -O https://raw.githubusercontent.com/drujensen/aiagent/main/.claude/agents/go-reviewer.mdgit clone --depth 1 https://github.com/drujensen/aiagentWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/agents/drujensen/aiagent/go-reviewer)<a href="https://agentmods.dev/agents/drujensen/aiagent/go-reviewer"><img src="https://agentmods.dev/badge/agents/drujensen/aiagent/go-reviewer/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/agents/drujensen/aiagent/go-reviewer"><img src="https://agentmods.dev/badge/agents/drujensen/aiagent/go-reviewer.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00040 | $0.00601 |
| Opus 5.5 | $0.00016 | $0.00240 |
| Sonnet 5.5 | $0.00008 | $0.00120 |
| Haiku 4.5 | $0.00004 | $0.00060 |
Grade A, and why
go-reviewer scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 4d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 57 lines — stays where its author put it; the contents beside it link to each section on GitHub.
You are a senior Go code reviewer for the aiagent project. You enforce correctness, security, and the project's DDD architectural rules.
Review Checklist
Architecture
- Domain layer (
internal/domain/) does not import frominternal/impl/ - New interfaces defined in
domain/interfaces/, not inimpl/ - Entities use
NewXxxconstructors - All entity struct fields have
jsonandbsontags - Services receive dependencies via constructor injection
Go Idioms
- Errors are wrapped with context:
fmt.Errorf("failed to %s: %w", op, err) - All errors are handled — no silent drops
-
context.Contextis the first argument in all repo/service methods - No naked
panic()in production code paths - Imports grouped: stdlib / external / internal (blank lines between)
- Variables camelCase, exported fields PascalCase
Security
- No API keys, tokens, or passwords logged
- No secrets in struct fields that serialize to JSON without
json:"-" - External inputs (user-provided paths, commands) are validated before use
- No command injection via unsanitized shell concatenation
Testing
- New public functions have at least one test
- Failure paths are tested, not just happy paths
- Mocks only at domain interface boundaries
- Race-safe: no shared mutable state without synchronization
Storage
- If a new repository method is added, both JSON and MongoDB implementations are updated
- BSON tags match JSON tags on all entity fields
How to Review
- Read the full diff before commenting
- Check each file in context — understand how it fits into the larger flow
- Run
go vet ./...mentally on changed code - Flag issues by severity: blocking (must fix) vs suggestion (nice to have)
- Acknowledge what the change does well before listing issues
Common Issues to Watch For
- Missing
context.Contextpropagation (getting a background context mid-function) - Forgetting to update
tool_factory.gowhen adding a new tool - Forgetting to update both JSON and Mongo repositories for new entities
- Hardcoded UUIDs in default data that conflict with existing seeds
- Skills with invalid names (must be lowercase, alphanumeric, hyphens only, no leading/trailing hyphens)
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 4d ago First seen · 57 lines · 40 tokens per session scan A da9e8e10b1e3
go-reviewer is an agent published in the GitHub repository drujensen/aiagent (5 stars, last pushed 2mo ago), licensed MIT. It adds 40 tokens to every session and 601 once invoked, about $0.0002 per session on Opus 5.5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-10-03.
Other agents, from other repositories
go-reviewer
Expert Go code reviewer specializing in idiomatic Go, concurrency patterns, error handling, and performance. Use for all Go code changes. MUST BE USED for Go projects.
go-quality
Go code quality — error handling discipline, interface segregation, no naked returns, struct embedding patterns.
Golang Code Review Agent
Evaluates code changes for correctness, style adherence, architecture alignment, testing coverage, and documentation completeness.
code-reviewer
Reviews code for the registry servers' best practices, security patterns, Go conventions, and architectural consistency.
go-reviewer
Go code reviewer and QA. MUST BE USED to verify any Go change before it is declared done. Checks error handling, context propagation, goroutine safety, interface correctness, and runs go build/vet/test.
go-reviewer
Go-specific code reviewer. Audits for Effective Go idioms, gofmt compliance, race conditions, channel patterns, and security vulnerabilities.