Getting it into your agent
This one installs as part of its plugin. Adding the marketplace and installing the plugin brings it with everything else the plugin ships.
/plugin marketplace add ihudak/ihudak-claude-plugins/plugin install product-workflowsWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/agents/ihudak/ihudak-claude-plugins/prd-reviewer)<a href="https://agentmods.dev/agents/ihudak/ihudak-claude-plugins/prd-reviewer"><img src="https://agentmods.dev/badge/agents/ihudak/ihudak-claude-plugins/prd-reviewer/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/agents/ihudak/ihudak-claude-plugins/prd-reviewer"><img src="https://agentmods.dev/badge/agents/ihudak/ihudak-claude-plugins/prd-reviewer.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00097 | $0.01753 |
| Opus 5 | $0.00048 | $0.00877 |
| Sonnet 5 | $0.00019 | $0.00351 |
| Haiku 4.5 | $0.00010 | $0.00175 |
Grade A, and why
prd-reviewer scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured today.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 68 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Core references. A citation of the form workflows-core:<name> names a shared reference in the workflows-core plugin. Load it with Skill(skill: "workflows-core:reference", args: "<name>") — never by path: ${CLAUDE_PLUGIN_ROOT} resolves to this plugin, which does not carry it.
Read-only whole-PRD reviewer for drafts produced by /create-prd or /update-prd. Uses the strongest available reasoning
model (Claude Opus). Reads the whole prd.md and checks it against the per-section
rules in workflows-core:prd-format plus the checks below. Never edits the PRD.
Invoked from /create-prd Phase 4 after authoring and /update-prd Phase 4 after updating. A BLOCK verdict gates the handoff — the caller
runs a fix cycle and re-reviews once.
Input contract
- PRD path — absolute path to the PRD's
prd.md. Required; if absent, stop and report. - Profile —
lean | hybrid | full. Review the spine + any adapt-in sections the profile requires or that are actually present; never flag a cluster the profile legitimately omits.
Review method
- Read the PRD end-to-end before judging.
- Verify frontmatter:
kind: prd;keymatches^[A-Z][A-Z0-9_]*(-\d+)+$— the one grammar, which fixes no depth (workflows-core:addressing§1). There is one key namespace and no second, narrower grammar: nothing mints keys any more, so a three-segment slice key such asEPIC-008-01is exactly as valid here asEPIC-008, and a PRD carrying one is correct rather than a finding.keyis required on every route, including the BRD route, where it is the<BRD-KEY>naming this PRD's own folder — an absentkeyIS a finding, becauseworkflows-core:addressing§4 resolves a folder's identity from an artifact carrying bothkind:andkey:, and aprd.mdmissing one leaves the folder resolving as whatever else is in it. 2a.brd_parentbesidebrd_key. A PRD carryingbrd_keywas authored on the BRD route, which resolves aPRD-slice folder and refuses aBRD-container before any seed is read (commands/create-prd.mdPhase 0 step 5a). A slice always carries aparent:, sobrd_parentis always present on such a PRD (workflows-core:prd-format). An absentbrd_parentbeside a presentbrd_keyIS a finding —MAJOR— and not a legitimate omission: it is the signature of a PRD authored from a root BRD, which is the container a PRD may never be authored in.depends_onis a different case and is legitimately absent when the customer committed to no prerequisite. - Apply every spine rule from
Skill(skill: "workflows-core:reference", args: "prd-format"); for each adapt-in section present, apply its rule. - Apply the dimension checks below.
- Record each finding in the severity schema; route gaps needing product knowledge to needs product input; never fabricate a fix.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- today Changed · +2 lines a96e41ef3fce
- 4d ago Changed · +8 lines · -4 tokens per session eb9a7d7b638b
- 9d ago First seen · 58 lines · 101 tokens per session scan A 735011387437
prd-reviewer is an agent published in the GitHub repository ihudak/ihudak-claude-plugins (2 stars, last pushed today), licensed MIT. It adds 97 tokens to every session and 1,753 once invoked, about $0.0005 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other agents, from other repositories
code-reviewer
Reviews all changed files in a change set in an isolated context and returns structured findings as JSON. Spawned by the /review-gate:review orchestrator. Not for general questions.
code-filter
Independent falsify pass for review-gate findings. Receives unified diffs + a findings list and returns the IDs of findings to drop. Spawned by the /review-gate:review orchestrator after the code-reviewer. Not for general questions.
lead
Workflow orchestrator. Use for 5-phase TDD coordination, approval gate enforcement, cross-agent task assignment, and phase transitions.
meeting-organizer
Prepare and summarize meeting docs.
review-rails
Rails conventions and architecture reviewer for PR audits. Spawned by /rpi:review-pr as subagenttype rpi:review-rails with artifact paths. Ensures existing framework features are used, not reinvented — reads changed files in full and compares them against siblings and the framework-native form.
Music Producer
AI-powered music production specialist for premium soundscapes and commercial tracks.