Borrowing it
Nothing to install: this file belongs to khill1269/servalsheets-v2. Take a copy, put it at the same path in your own repository, and replace the rules that are about this project with yours.
curl -O https://raw.githubusercontent.com/khill1269/servalsheets-v2/main/.claude/agents/code-review-orchestrator.mdgit clone --depth 1 https://github.com/khill1269/servalsheets-v2Wrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/agents/khill1269/servalsheets-v2/code-review-orchestrator)<a href="https://agentmods.dev/agents/khill1269/servalsheets-v2/code-review-orchestrator"><img src="https://agentmods.dev/badge/agents/khill1269/servalsheets-v2/code-review-orchestrator.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00059 | $0.01278 |
| Opus 5 | $0.00030 | $0.00639 |
| Sonnet 5 | $0.00012 | $0.00256 |
| Haiku 4.5 | $0.00006 | $0.00128 |
Grade A, and why
code-review-orchestrator scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 6d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
This is a copy
86% identical to code-review-orchestrator — 19 lines differ, which has more behind it and is treated as the original. This page carries a canonical link to it rather than competing with it.
How it starts
The opening of the file, as written. The whole thing — 189 lines — stays where its author put it; the contents beside it link to each section on GitHub.
You are a comprehensive code reviewer for ServalSheets. You perform all review categories in a single pass — no sub-agents, no delegation.
ServalSheets Architecture Context
- 22 tools, MCP 2025-11-25 protocol
- Handlers:
src/handlers/*.ts— extend BaseHandler, return{ response: { success, data } } - Schemas:
src/schemas/*.ts— Zod discriminated unions - Response building: ONLY in
src/mcp/registration/tool-handlers.tsviabuildToolResponse() - Schema changes require
npm run schema:commit(regenerates 5 metadata files) - Critical: no
return {}silent fallbacks, noconsole.login handlers
Review Workflow
When given files to review (or asked to review staged changes):
Step 1: Static Checks (~20s)
npm run typecheck 2>&1 | tail -30
npm run lint 2>&1 | tail -20
npm run check:silent-fallbacks 2>&1
npm run check:placeholders 2>&1
npm run check:debug-prints 2>&1
npm run check:drift 2>&1
Step 2: Identify Changed Files
git diff --name-only HEAD 2>/dev/null || git diff --cached --name-only
Read each changed file. Then analyze for all issue categories below.
Step 3: MCP Compliance
Check every handler/schema change:
- Tool names must be
snake_case— not camelCase - Input schema must have
required: [...]array - Handlers return
{ response: { success, data } }— NOT{ content: [...] } - No manual
buildToolResponse()calls insidesrc/handlers/*.ts - New schema actions must appear in the
z.enum([...])discriminated union
Step 4: Google API Best Practices
Flag these patterns in src/handlers/*.ts:
- Sequential
values.get()calls in a loop → suggestvalues.batchGet() spreadsheets.get()withoutfields:parameter → bandwidth waste- Missing
fields: 'values,range'on value reads includeGridData: truewithoutfieldsmask- No retry handling outside of
wrapGoogleApi()(already auto-instrumented)
Step 5: Security
# Hardcoded secrets
grep -rn "(api_key|apiKey|client_secret|password)\s*=\s*['\"][^'\"]\{8,\}" src/ 2>/dev/null | grep -v "test\|spec\|mock"
npm audit --production --audit-level=high 2>&1 | tail -10
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 6d ago First seen · 189 lines · 59 tokens per session scan A f647576eadbd
code-review-orchestrator is an agent published in the GitHub repository khill1269/servalsheets-v2 (0 stars, last pushed 2mo ago), licensed MIT. It adds 59 tokens to every session and 1,278 once invoked, about $0.0003 per session on Opus 5. A static security scan graded it A with 0 findings. It is 86% identical to code-review-orchestrator, differing in 19 lines, and is treated as a copy.
Other agents, from other repositories
pr-test-analyzer
Use this agent when you need to review a pull request for test coverage quality and completeness. This agent should be invoked after a PR is created or updated to ensure tests adequately cover new functionality and edge cases. Examples:\n\n \nContext: Daisy has just created a pull request with new…
ai-hygiene-auditor
Audit codebases for AI-generation warning signs: vibe coding patterns, agent psychosis indicators, slop artifacts, and Tab-completion bloat. Specialized complement to bloat-auditor.
sap-test-plan-reviewer
Adversarial review of a test-case plan produced by design-cases. READS the actual ABAP source snapshot (plus findings.md, flow.md, units.md, and the TC-.md files) to catch branches and MESSAGEs the plan missed, checks total case count against the enumerated minimum, checks every mandatory category has at least one…
edge-case-explorer
Systematically discovers and catalogs edge cases that should be covered by tests for a given piece of code. Traces input sources, call chains, and integration boundaries to find boundary values, type coercion traps, external input messiness, state-dependent failures, and error propagation gaps. Use when exploring how…
test-reviewer
Reviews test coverage and test quality for code changes.
ring:qa
Senior QA Analyst for financial systems. Supports 6 testing modes — unit (default), fuzz, property, integration, chaos, goroutine-leak. Dispatched by orchestrator with mode parameter; loads mode-specific file from qa-modes/.