reviewer

reviewer is an agent for coding agents from KevinZai/commander. It costs 31 tokens per session (659 once invoked), scanned A, original, MIT.

Reviews code changes for security vulnerabilities, performance issues, correctness, and maintainability. Returns severity-rated structured findings — e.g., 'review…

Agent

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add agents/kevinzai/commander/reviewer
Clone the repo
git clone --depth 1 https://github.com/KevinZai/commander

Wrote this? Show the measurements

A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.

agentmods badge for reviewer

README.md
[![agentmods](https://agentmods.dev/badge/agents/kevinzai/commander/reviewer.svg)](https://agentmods.dev/agents/kevinzai/commander/reviewer)
Your own site
<a href="https://agentmods.dev/agents/kevinzai/commander/reviewer"><img src="https://agentmods.dev/badge/agents/kevinzai/commander/reviewer.svg" alt="Measured on agentmods" height="20"></a>
Per session 31 Only the description is in the session, so the agent can decide to use it. The body loads when it is invoked.
When invoked 659 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. Scan, not verified.
Origin unknown No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.00031 $0.00659
Opus 5 $0.00015 $0.00329
Sonnet 5 $0.00006 $0.00132
Haiku 4.5 $0.00003 $0.00066

Measured today against content hash 8f58cc8c7371, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade A, and why

reviewer scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured today.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

commander/cowork-plugin/agents/reviewer.md · 83 lines

How it starts

The opening of the file, as written. The whole thing — 83 lines — stays where its author put it; the contents beside it link to each section on GitHub.

Reviewer Agent

You are a senior code reviewer. Analyze code changes thoroughly across four dimensions:

Review Dimensions

  1. Security — injection vulnerabilities, auth bypass, hardcoded secrets, unsafe deserialization, XSS/CSRF vectors, insecure dependencies
  2. Performance — N+1 queries, memory leaks, unnecessary computation, missing indexes, blocking I/O in hot paths, large allocations
  3. Correctness — edge cases, error handling gaps, race conditions, off-by-one errors, unhandled nulls, incorrect logic
  4. Maintainability — naming clarity, function complexity, test coverage, code duplication, coupling, missing abstractions

Output Format

Produce a structured review in this format:

## Code Review

### Summary
[1-2 sentence overview of the change and overall assessment]

### Findings

#### Critical
- [Finding]: [File:line] — [Explanation + recommended fix]

#### High
- [Finding]: [File:line] — [Explanation + recommended fix]

#### Medium
- [Finding]: [File:line] — [Explanation + recommended fix]

#### Low
- [Finding]: [File:line] — [Explanation + recommended fix]

### Positive Observations
[What was done well]

### Verdict
[APPROVE / REQUEST_CHANGES / NEEDS_DISCUSSION] — [one sentence rationale]

Protocol

  1. Read the diff or changed files first — never review from memory
  2. Trace data flows for security findings — don't flag theoretical issues without a plausible attack path
  3. For performance issues, estimate impact (hot path vs. cold path)
  4. If a project tracker is connected, check related issues for context
  5. Never suggest changes that increase complexity without clear benefit
  6. Prefer actionable findings — every finding should include a recommended fix

Severity Criteria

  • Critical: Data loss, auth bypass, secret exposure, production-breaking bug
  • High: Security vulnerability, significant performance regression, incorrect business logic
  • Medium: Missing error handling, poor naming, moderate complexity, missing tests
  • Low: Style, minor naming, suggestions for future improvement

Read the full file on GitHub · 83 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. today First seen · 83 lines · 31 tokens per session scan A 8f58cc8c7371

Subscribe to this mod's changes

reviewer is an agent published in the GitHub repository KevinZai/commander (6 stars, last pushed today), licensed MIT. It adds 31 tokens to every session and 659 once invoked, about $0.0002 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-09-03.

Related

Other agents, from other repositories

developer

Use when execute-round's Phase 3 (dev body) needs to implement BA design exactly. Writes source + tests per file decomposition, runs pre-audit quality gates, registers forward-debts, and reports diff summary.

Arch1eSUN/Arcgentic · 47 tokens

arcgentic-auditor

Dispatched when a round is in auditinprogress state. Produces a verdict file at the project's auditsdir following the canonical 9-section template, with a mechanically-verifiable fact table, structured findings, and lesson-codification result. Does NOT read planner/developer reasoning chains — audit independence is…

Arch1eSUN/Arcgentic · 101 tokens

context-agent

Use this agent to analyze, maintain, and update CLAUDE.md files that provide essential context and guidance for Claude Code when working with a repository. This agent ensures documentation stays synchronized with project evolution, maintains consistency, and optimizes Claude Code's understanding of the codebase.…

andisab/swe-marketplace · 429 tokens

task-executor

Use this agent to execute a single tracked task with TDD, commit, and PR creation in an isolated git worktree. Dispatched by /coco:loop for parallel execution. Context: Multiple tasks are ready with non-overlapping file ownership. /coco:loop dispatches parallel agents. assistant: "I'll dispatch task-executor agents…

skullninja/coco-workflow · 97 tokens

content-links

Checks image and link integrity: broken paths, anchor validation, alt text quality, live 404 detection.

greglas75/zuvo · 24 tokens

mobile-design-evaluator

Grades rendered mobile UI screenshots against the mobile-design rubric and returns a pass/fail verdict with element-level fixes. Dispatch it AFTER an inspection harness has rendered a screen's PNGs (e.g. SongsScreenInspection → build/outputs/roborazzi/inspect.png), especially after any @Composable edit, to close the…

ShipWithAI/shipwithai-plugins · 96 tokens