react18-commander

react18-commander is an agent for Claude Code from github/awesome-copilot. It costs 101 tokens per session (2,257 once invoked), scanned A, original, MIT.

A coordinator for upgrading applications built with older React versions, especially those using many class components, to React 18.3.1. It organizes dependency changes, code migrations, and test checks into saved phases.

In plain words
What is it for?
Use it to audit a React 16 or 17 project, upgrade its dependencies, migrate class-component patterns, address automatic batching, and verify the test suite.
Why use it?
React upgrades can affect old component APIs, asynchronous state updates, dependencies, and tests at the same time. This agent keeps the work ordered and can resume an interrupted migration.

Agent for Claude Code

Written for Claude Code: argument-hint in frontmatter. Also seen: Copilot chat-mode frontmatter (tools: vscode/*).

About the project

Awesome GitHub Copilot is a community collection of custom agents, instructions, skills, hooks, workflows, plugins, and configuration for GitHub Copilot. It helps Copilot users customize coding and development tasks. Catalogue entries are individual Copilot add-ons from this collection.

github/awesome-copilot · 38,651 stars · on GitHub

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add agents/github/awesome-copilot/react18-commander
Clone the repo
git clone --depth 1 https://github.com/github/awesome-copilot

Made for: Claude Code.

Wrote this? Show the measurements

A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.

agentmods badge for react18-commander

README.md
[![agentmods](https://agentmods.dev/badge/agents/github/awesome-copilot/react18-commander.svg)](https://agentmods.dev/agents/github/awesome-copilot/react18-commander)
Your own site
<a href="https://agentmods.dev/agents/github/awesome-copilot/react18-commander"><img src="https://agentmods.dev/badge/agents/github/awesome-copilot/react18-commander.svg" alt="Measured on agentmods" height="20"></a>
Per session 101 Only the description is in the session, so the agent can decide to use it. The body loads when it is invoked.
When invoked 2,257 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 1 finding. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5.1 $0.00101 $0.02257
Opus 5 $0.00051 $0.01128
Sonnet 5 $0.00020 $0.00451
Haiku 4.5 $0.00010 $0.00226

Measured 2d ago against content hash fa3c84f2bcdc, method: parsed. Prices are Anthropic first-party input rates as of 2026-09-06, from the pricing page.

Security

Grade A, and why

react18-commander scanned grade A with 1 finding against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Strips warnings and disclaimerslowAnti-refusal

Omitting safety caveats hides risk from the user and is a common jailbreak preamble.

- **Legacy lifecycle methods** (`componentWillMount`, `componentWillReceiveProps`, `componentWillUpdate`) were deprecated in 16.3 - but React kept calling them in 16 and 17 WITHOUT warnings unless StrictMode was enabled.

Downgraded: this mod is about security review, or the phrase is quoted, so it is likely naming the pattern rather than instructing it.

Origin

Copies of this mod

2 near-identical copies found in the catalogue:

agents/react18-commander.agent.md · 231 lines

How it starts

The opening of the file, as written. The whole thing — 231 lines — stays where its author put it; the contents beside it link to each section on GitHub.

React 18 Commander - Migration Orchestrator (React 16/17 → 18.3.1)

You are the React 18 Migration Commander. You are orchestrating the upgrade of a class-component-heavy, React 16/17 codebase to React 18.3.1. This is not cosmetic. The team has been patching since React 16 and the codebase carries years of un-migrated patterns. Your job is to drive every specialist agent through a gated pipeline and ensure the output is a properly upgraded, fully tested codebase - with zero deprecation warnings and zero test failures.

Why 18.3.1 specifically? React 18.3.1 was released to surface explicit warnings for every API that React 19 will remove. A clean 18.3.1 run with zero warnings is the direct prerequisite for the React 19 migration orchestra.

Memory Protocol

Read migration state on every boot:

#tool:memory read repository "react18-migration-state"

Write after each gate passes:

#tool:memory write repository "react18-migration-state" "[state JSON]"

State shape:

{
  "phase": "audit|deps|class-surgery|batching|tests|done",
  "reactVersion": null,
  "auditComplete": false,
  "depsComplete": false,
  "classSurgeryComplete": false,
  "batchingComplete": false,
  "testsComplete": false,
  "consoleWarnings": 0,
  "testFailures": 0,
  "lastRun": "ISO timestamp"
}

Boot Sequence

  1. Read memory - report which phases are complete

  2. Check current version:

    node -e "console.log(require('./node_modules/react/package.json').version)" 2>/dev/null || grep '"react"' package.json | head -3
    
  3. If already on 18.3.x - skip dep phase, start from class-surgery

  4. If on 16.x or 17.x - start from audit


Pipeline

PHASE 1 - Audit

#tool:agent react18-auditor
"Scan the entire codebase for React 18 migration issues.
This is a React 16/17 class-component-heavy app.
Focus on: unsafe lifecycle methods, legacy context, string refs,
findDOMNode, ReactDOM.render, event delegation assumptions,
automatic batching vulnerabilities, and all patterns that
React 18.3.1 will warn about.
Save the full report to .github/react18-audit.md.
Return issue counts by category."

Read the full file on GitHub · 231 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 2d ago First seen · 231 lines · 101 tokens per session scan A fa3c84f2bcdc

Subscribe to this mod's changes

react18-commander is an agent published in the GitHub repository github/awesome-copilot (38,651 stars, last pushed yesterday), licensed MIT. It adds 101 tokens to every session and 2,257 once invoked, about $0.0005 per session on Opus 5. A static security scan graded it A with 1 finding (strips warnings and disclaimers). No closer match exists in the catalogue, so it is treated as the original; first seen 2026-09-03.

Related

Other agents, from other repositories

react-expert

Specialized in React.js, Next.js, and modern frontend ecosystems. Uses specialized knowledge of hooks, state management (Zustand/Redux), and server components.

ashrafmusa/agenticana · 37 tokens

frontend-specialist

Senior Frontend Architect who builds maintainable React/Next.js systems with performance-first mindset. Use when working on UI components, styling, state management, responsive design, or frontend architecture. Triggers on keywords like component, react, vue, ui, ux, css, tailwind, responsive.

ashrafmusa/agenticana · 63 tokens

mobile-developer

Expert in React Native and Flutter mobile development. Use for cross-platform mobile apps, native features, and mobile-specific patterns. Triggers on mobile, react native, flutter, ios, android, app store, expo.

ashrafmusa/agenticana · 47 tokens

algorithmic-patterns

Load this reference when the PR diff touches code outside the transport/cache layer -- i.e. when the change introduces or modifies loops, data structures, lookup patterns, or module-level imports.

microsoft/apm · 0 tokens

Frontend Developer

React/TypeScript specialist for CoreAI DIY frontend development with React Flow, Zustand, and Tailwind CSS.

microsoft/skills · 24 tokens

spec-tag-architect

Adversarial web-platform / TAG-style architect persona for reviewing the OpenAPM specification artifact. Activate ONLY from the apm-spec-guardian skill -- this persona's review contract assumes a spec-review fan-out with JSON-only return.

microsoft/apm · 51 tokens