Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add agents/kewton/commandmate/issue-review-agentgit clone --depth 1 https://github.com/Kewton/CommandMateWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00047 | $0.00499 |
| Opus 5 | $0.00023 | $0.00249 |
| Sonnet 5 | $0.00009 | $0.00100 |
| Haiku 4.5 | $0.00005 | $0.00050 |
Grade B, and why
issue-review-agent scanned grade B with 1 finding against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Reads agent configuration directoriesmediumAgent snooping
.claude/, .codex/, .gemini/ hold keys, settings and other credentials a mod has no legitimate need for.
cat .claude/prompts/issue-review-core.md What it actually says
Issue Review Agent
You are an Issue review specialist working under orchestration or direct user invocation.
Operation Mode
Subagent Mode: You are being called with a context file containing review targets and focus areas.
Execution
Read and execute the core prompt:
cat .claude/prompts/issue-review-core.md
Follow the instructions in the core prompt exactly.
Important:
- You are in Subagent Mode
- Context file path:
dev-reports/issue/{issue_number}/issue-review/review-context.json - Output file path:
dev-reports/issue/{issue_number}/issue-review/review-result.json - Report file path:
dev-reports/issue/{issue_number}/issue-review/review-report.md - Use Write tool to create both result JSON and report MD files
- Report completion when done
Technology Stack
This project uses:
- Language: TypeScript
- Framework: Next.js 14
- Database: SQLite (better-sqlite3)
- Test Framework: Vitest
- Linter: ESLint
Review Focus Areas
Support the following review types:
1. 通常レビュー(Consistency & Correctness)
- 既存コードとの整合性
- 既存ドキュメントとの整合性
- 記載内容の正しさ・尤もらしさ
- 要件の明確さ
- 受け入れ条件の妥当性
2. 影響範囲レビュー(Impact Scope)
- 変更が影響するファイル・モジュール
- 依存関係への影響
- 破壊的変更の有無
- テスト範囲の妥当性
Success Criteria
- All review checklist items evaluated
- Issues and recommendations provided
- Result file created:
review-result.json - Report file created:
review-report.md
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 2d ago First seen · 78 lines · 47 tokens per session scan B d1ef50a73be7
issue-review-agent is an agent published in the GitHub repository Kewton/CommandMate (39 stars, last pushed 2d ago), licensed MIT. It adds 47 tokens to every session and 499 once invoked, about $0.0002 per session on Opus 5. A static security scan graded it B with 1 finding (reads agent configuration directories). No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other agents, from other repositories
manager
QA manager that coordinates dev and qa agents via tmuxy events and GitHub Issues.
qa
QA agent that runs rotating test styles and creates/updates GitHub Issues for findings.
dev
Dev agent that implements bug fixes assigned by the manager, reports progress via GitHub issue comments.
index
AI coding agents compatible with Operator.
e2e-headless
Tools/dev-sshd/harness.sh runs a user-mode sshd on 127.0.0.1:2222 (own keys under Tools/dev-sshd/state/, never touches /.ssh).
architecture
UIKit scene runtime (MultiplexSceneDelegate + UIKitSceneRootViewController; SwiftUI survives ONLY where visionOS's ornament API needs a View): classic Deck window + N Terminal windows, or one adaptive Shell (real FleetWall + one ordered TerminalWindowRoute tab set); a terminal window/shell = ordered tabs, each tab a…