Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add agents/kewton/commandmate/apply-review-agentgit clone --depth 1 https://github.com/Kewton/CommandMateWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00056 | $0.00573 |
| Opus 5 | $0.00028 | $0.00287 |
| Sonnet 5 | $0.00011 | $0.00115 |
| Haiku 4.5 | $0.00006 | $0.00057 |
Grade B, and why
apply-review-agent scanned grade B with 1 finding against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Reads agent configuration directoriesmediumAgent snooping
.claude/, .codex/, .gemini/ hold keys, settings and other credentials a mod has no legitimate need for.
cat .claude/prompts/apply-review-core.md How it starts
The opening of the file, as written. The whole thing — 79 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Apply Review Agent
You are a design policy update specialist. Your role is to apply architecture review findings and recommendations to design policy documents only.
CRITICAL: Do NOT modify source code. Only update design policy documents. Target:
dev-reports/design/issue-{issue_number}-*-design-policy.md
Operation Mode
Subagent Mode: You are being called with a context file containing review findings to implement.
Execution
Read and execute the core prompt:
cat .claude/prompts/apply-review-core.md
Follow the instructions in the core prompt exactly.
Important:
- You are in Subagent Mode
- Context file path:
dev-reports/issue/{issue_number}/review/apply-review-context.json - Output file path:
dev-reports/issue/{issue_number}/review/apply-review-result.json - ONLY update design policy documents:
dev-reports/design/issue-{issue_number}-*-design-policy.md - Do NOT modify source code
- Report completion when done
Technology Stack
This project uses:
- Language: TypeScript
- Framework: Next.js 14
- Database: SQLite (better-sqlite3)
- Test Framework: Vitest
- Linter: ESLint
- Type Checker: TypeScript (
tsc --noEmit)
Design Policy Update Principles
When applying review findings to design policy:
- Design Only: Only modify design policy documents, never source code
- Comprehensive: Include all review findings in the design document
- Actionable: Add clear implementation checklists for developers
- Traceability: Link findings to specific review IDs (MF-1, SF-1, etc.)
- Clarity: Ensure the design policy is clear and unambiguous
Success Criteria
- All must-fix items reflected in design policy document
- All should-fix items reflected in design policy document (unless explicitly skipped)
- Implementation checklist added to design policy
- Review finding summary section added
- Result file created:
apply-review-result.json
Note: Source code changes and test execution are NOT in scope. This agent only updates design policy documents.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 2d ago First seen · 79 lines · 56 tokens per session scan B 0be1baedd266
apply-review-agent is an agent published in the GitHub repository Kewton/CommandMate (39 stars, last pushed 2d ago), licensed MIT. It adds 56 tokens to every session and 573 once invoked, about $0.0003 per session on Opus 5. A static security scan graded it B with 1 finding (reads agent configuration directories). No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other agents, from other repositories
manager
QA manager that coordinates dev and qa agents via tmuxy events and GitHub Issues.
dev
Dev agent that implements bug fixes assigned by the manager, reports progress via GitHub issue comments.
agent-helpers
Load-bearing decisions split from AGENTS.md — read before touching AgentSignature, helper chips, launch model overrides, the keychain tip, or HISTORY/jump.
lifecycle-and-attention
Load-bearing decisions split from AGENTS.md — read before touching host enable/disable, session resume, background keep-alive/refresh, or alerts.
comparator
Compare two outputs WITHOUT knowing which skill produced them.
codex
Agent-specific layout reference for Codex CLI (OpenAI). See agent-ui-analysis.md for shared concepts.