self-review-cold-grader

self-review-cold-grader is an agent for Claude Code from HoussemDjeghri/self-review. It costs 63 tokens per session (1,615 once invoked), scanned A, original, MIT.

A reviewer that examines a recorded, sandboxed run of a program from a user's point of view. The sandbox limits network access and file changes.

In plain words
What is it for?
It is for checking whether command-line invocations, such as dry-run or status commands, behave safely during a contained test.
Why use it?
It can identify unsafe behavior from the actual run without allowing the reviewer to execute commands with real credentials or network access.

Agent for Claude Code

Written for Claude Code: effort in frontmatter. Also seen: model in frontmatter.

Part of the self-review plugin — 2 skills, 5 agents shipped together

Good fit It is for checking whether command-line invocations, such as dry-run or status commands, behave safely during a contained test.

Compare 6 agents from other repositories ↓
Install with agentmods
npx agentmods add agents/houssemdjeghri/self-review/self-review-cold-grader
Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

Clone the repo
git clone --depth 1 https://github.com/HoussemDjeghri/self-review

Made for: Claude Code.

Or install self-review, the plugin that ships this one along with the rest of its 2 skills, 5 agents.

Wrote this? Show the measurements

A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.

agentmods badge for self-review-cold-grader

README.md
[![agentmods](https://agentmods.dev/badge/agents/houssemdjeghri/self-review/self-review-cold-grader/github.svg)](https://agentmods.dev/agents/houssemdjeghri/self-review/self-review-cold-grader)
Your own site
<a href="https://agentmods.dev/agents/houssemdjeghri/self-review/self-review-cold-grader"><img src="https://agentmods.dev/badge/agents/houssemdjeghri/self-review/self-review-cold-grader/github.svg" alt="Measured on agentmods" height="20"></a>

Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.

agentmods 80×15 button for self-review-cold-grader

Your own site · 80×15
<a href="https://agentmods.dev/agents/houssemdjeghri/self-review/self-review-cold-grader"><img src="https://agentmods.dev/badge/agents/houssemdjeghri/self-review/self-review-cold-grader.svg" alt="Reviewed on agentmods" width="80" height="20"></a>
Per session 63 Only the description is in the session, so the agent can decide to use it. The body loads when it is invoked.
When invoked 1,615 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. A grade says what 26 rules found in the file — not that it is safe.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5.1 $0.00063 $0.01615
Opus 5 $0.00032 $0.00807
Sonnet 5 $0.00013 $0.00323
Haiku 4.5 $0.00006 $0.00161

Measured 7d ago against content hash 798c5d4d02e3, method: parsed. Prices are Anthropic first-party input rates as of 2026-09-11, from the pricing page.

Security

Grade A, and why

self-review-cold-grader scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 7d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

agents/self-review-cold-grader.md · 99 lines

How it starts

The opening of the file, as written. The whole thing — 99 lines — stays where its author put it; the contents beside it link to each section on GitHub.

You are one reviewer in a panel, and you have one angle: X, cold run. Every other reviewer reads the change. You read what the change did when it was run the way a user gets it — a transcript your brief names, produced before you were spawned by scripts/coldrun.sh.

Why you have no shell

Angle X used to ask a reviewer to pick, by reading the artifact, which invocation of it was safe to execute. That is circular: the code you would read to judge safety is exactly the code the review exists because it might be broken. A mis-parsed --dry-run, an untested side effect behind a status subcommand — the bug class X hunts — and the judgement is wrong with real credentials and a real network behind it. So the run was moved into a sandbox that denies the network and confines writes, and the choice was taken away from the reviewer entirely.

You are the reviewer. You have no Bash tool, and that is the mechanism, not an oversight. (Write is here only for the state file below; it grants no execution, so the property still holds.) If you believe a further invocation is needed to settle something, that belief is a finding — name the entry point and the argv you would want — not something to go and do.

How to work

  1. Read the brief: the user's intent, the scope file, the transcript path, and the dismissed ledger.
  2. Read the transcript in full. Its header names the containment tier; read that first, because it decides what the rest of the file means.
  3. Read the entry points it names, in the repository, to learn what each one declares it does — the README's usage line, the --help text the code prints, the docs this change edited.
  4. Grade each invocation against that declaration. Report candidates as JSON.

What the transcript means

  • containment: contained — network denied and writes confined. The invocations ran; grade them.
  • containment: network-denied — the network was denied but writes and reads were not confined. You only ever see this tier on a host whose owner set coldRun.uncontained: true, because otherwise it refuses to execute. The invocations did run; say so in evidence if a finding turns on a file the artifact wrote or read.
  • containment: uncontained and a "Nothing was executed" section — nothing ran. Those entry points are UNVERIFIED, not verified-clean, and the correct output is a single minor candidate saying angle X could not be exercised on this host and naming what the transcript says would fix it. Never report a pass, and never report the entry points as defective: you have no evidence either way.

Read the full file on GitHub · 99 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 7d ago Changed · +2 lines 798c5d4d02e3
  2. 11d ago First seen · 97 lines · 63 tokens per session scan A 9a7c6e68ef17

Subscribe to this mod's changes

self-review-cold-grader is an agent published in the GitHub repository HoussemDjeghri/self-review (1 stars, last pushed 3d ago), licensed MIT. It adds 63 tokens to every session and 1,615 once invoked, about $0.0003 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.

Related

Other agents, from other repositories

pr-test-analyzer

Use this agent when you need to review a pull request for test coverage quality and completeness. This agent should be invoked after a PR is created or updated to ensure tests adequately cover new functionality and edge cases. Examples:\n\n \nContext: Daisy has just created a pull request with new…

anthropics/claude-code · 0 tokens

ai-hygiene-auditor

Audit codebases for AI-generation warning signs: vibe coding patterns, agent psychosis indicators, slop artifacts, and Tab-completion bloat. Specialized complement to bloat-auditor.

athola/claude-night-market · 48 tokens

sap-test-plan-reviewer

Adversarial review of a test-case plan produced by design-cases. READS the actual ABAP source snapshot (plus findings.md, flow.md, units.md, and the TC-.md files) to catch branches and MESSAGEs the plan missed, checks total case count against the enumerated minimum, checks every mandatory category has at least one…

marcellourbani/vscode_abap_remote_fs · 161 tokens

edge-case-explorer

Systematically discovers and catalogs edge cases that should be covered by tests for a given piece of code. Traces input sources, call chains, and integration boundaries to find boundary values, type coercion traps, external input messiness, state-dependent failures, and error propagation gaps. Use when exploring how…

testdouble/han · 135 tokens

sdd-init

Initialize project SDD context, testing capabilities, and skill registry.

Gentleman-Programming/gentle-pi · 17 tokens

test-reviewer

Reviews test coverage and test quality for code changes.

ai-sdlc-framework/ai-sdlc · 13 tokens