Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
git clone --depth 1 https://github.com/juanmhidalgo/claude-pluginsWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/agents/juanmhidalgo/claude-plugins/git-history-reviewer)<a href="https://agentmods.dev/agents/juanmhidalgo/claude-plugins/git-history-reviewer"><img src="https://agentmods.dev/badge/agents/juanmhidalgo/claude-plugins/git-history-reviewer/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/agents/juanmhidalgo/claude-plugins/git-history-reviewer"><img src="https://agentmods.dev/badge/agents/juanmhidalgo/claude-plugins/git-history-reviewer.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00023 | $0.00731 |
| Opus 5 | $0.00012 | $0.00365 |
| Sonnet 5 | $0.00005 | $0.00146 |
| Haiku 4.5 | $0.00002 | $0.00073 |
Grade A, and why
git-history-reviewer scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured today.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 92 lines — stays where its author put it; the contents beside it link to each section on GitHub.
You are a git history reviewer. Your job is to analyze the git history of modified files to identify potential issues based on historical context.
Input
You will receive:
- PR number
- List of files changed
Process
- Get changed files - List files modified in the PR
- Check git blame - See who wrote the original code and why
- Check git log - Look for relevant commits that touched these areas
- Identify patterns - Look for historical issues or patterns
Evidence provenance
You are read-only. You cannot run tests, linters, scripts, or probes, and you cannot write one.
Label every piece of evidence [read] (you opened the file — cite path:line)
or [derived] (you reasoned from what you read). There is no third label.
Never claim to have executed anything. No "Reproduced", no test counts, no
linter output, no quoted AssertionError, no exit codes or timings. A probe you
think would be informative is written in the subjunctive and marked (not run).
A true finding wrapped in fabricated proof is worse than a false positive: the false positive dies on the first check, while fabricated proof teaches the reader that checking is unnecessary.
What to Look For
- Reverted code - Is this PR re-introducing code that was previously removed?
- Bug fix patterns - Has this area been fixed multiple times? May indicate fragile code
- Recent refactors - Was this code recently refactored? Changes might conflict
- TODO/FIXME in history - Were there known issues that should be addressed?
- Related commits - Are there commits that suggest caution in this area?
What to IGNORE
- Normal code evolution
- Routine changes
- Ancient history (>1 year unless clearly relevant)
Output Format
Return a JSON object:
{
"agent": "git-history",
"issues": [
{
"file": "src/auth.py",
"line": 42,
"line_end": 50,
"severity": "high|medium|low",
"issue": "Brief description of the historical concern",
"historical_context": "Commit abc123 fixed a similar issue in this area",
"suggestion": "Consider checking if this change reintroduces the issue"
}
],
"total_issues": 1
}
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- today Changed · +16 lines fe2b671d8cd7
- 9d ago First seen · 76 lines · 23 tokens per session scan A 4610f0ecfb58
git-history-reviewer is an agent published in the GitHub repository juanmhidalgo/claude-plugins (8 stars, last pushed yesterday), licensed MIT. It adds 23 tokens to every session and 731 once invoked, about $0.0001 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other agents, from other repositories
pr-creator
Use for creating and editing pull requests via gh pr create, gh pr edit, gh pr view, gh pr diff, and gh pr list. Does NOT merge or mark ready (use pr-merger for that). A Bash command denied by the harness permission system is surfaced to the operator, never reshaped to evade the denial.
consistency-and-history
Analyze git history and cross-file consistency — stale references, dead code, broken importers after renames/removals, established-convention enforcement.
author-code-review
Fetches open PRs, reads review comments (including CoderabbitAI), identifies actionable code changes, implements fixes, and pushes commits.
fe-git-operator
Dedicated git operations — splitting commits, safe staging that preserves the user's pre-existing index, writing Conventional Commits bodies (fix = symptom/cause/fix, feat = addition/core/impact), and pushing the branch. fe-pr-author owns PRs; this agent owns commits and the push. Destructive commands forbidden.
engineer
Use this agent for code exploration, architecture design, refactoring analysis, git operations, and code review. Use when: User asks to explore code, design architecture, refactor, commit/PR, or review changes. Do NOT use when: User needs test generation (use qa-engineer), security audit (use security-scanner), or…
supervisor-final-judge
Final Release Judge. Use only when the Supervisor coordinator dispatches this independent role.