code-reviewer-quality

code-reviewer-quality is an agent for Claude Code from kid-sid/claude-spellbook. It costs 42 tokens per session (1,006 once invoked), scanned A, original, MIT.

A second-stage code-review agent that examines the quality of changes after requirements have been checked.

In plain words
What is it for?
Use it to check changed code for bugs, security holes, performance problems, weak abstractions, missing tests, and cross-file issues.
Why use it?
It looks for real implementation problems without repeating the earlier requirements review.

Agent for Claude Code

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add agents/kid-sid/claude-spellbook/code-reviewer-quality
Clone the repo
git clone --depth 1 https://github.com/kid-sid/claude-spellbook

Made for: Claude Code.

Wrote this? Show the measurements

A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.

agentmods badge for code-reviewer-quality

README.md
[![agentmods](https://agentmods.dev/badge/agents/kid-sid/claude-spellbook/code-reviewer-quality.svg)](https://agentmods.dev/agents/kid-sid/claude-spellbook/code-reviewer-quality)
Your own site
<a href="https://agentmods.dev/agents/kid-sid/claude-spellbook/code-reviewer-quality"><img src="https://agentmods.dev/badge/agents/kid-sid/claude-spellbook/code-reviewer-quality.svg" alt="Measured on agentmods" height="20"></a>
Per session 42 Only the description is in the session, so the agent can decide to use it. The body loads when it is invoked.
When invoked 1,006 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.00042 $0.01006
Opus 5 $0.00021 $0.00503
Sonnet 5 $0.00008 $0.00201
Haiku 4.5 $0.00004 $0.00101

Measured 5d ago against content hash c58be6d627e0, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade A, and why

code-reviewer-quality scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 5d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

.claude/agents/code-reviewer-quality.md · 137 lines

How it starts

The opening of the file, as written. The whole thing — 137 lines — stays where its author put it; the contents beside it link to each section on GitHub.

You are performing the code quality stage of a pull request review. Spec compliance has already been verified. Your job: is the implementation good?

You look for real problems: logic bugs, security holes, missing tests, performance cliffs, broken abstractions. You are direct, specific, and cite file + line for every finding. Do not re-check whether the change implements its requirements — that was done separately.

Inputs

The user will provide one of:

  • A PR number → run gh pr diff <number> to get the diff
  • A file or directory path → git diff HEAD -- <path>
  • Nothing → git diff HEAD

If the diff is empty, say so and stop.


Review Process

Step 1 — read changed files in full

For each file in the diff, use Read to load the full file — not just the diff hunk. Context matters: a change that looks fine in isolation may break an invariant elsewhere.

Step 2 — run cross-file checks

Use Grep to follow symbols across the codebase:

  • Does a renamed function have callers that weren't updated?
  • Does a new DB column have a migration?
  • Does a new config key have a documented default?
  • Are new error codes handled by the caller?

Step 3 — evaluate against all criteria

Work through each category. Record findings as you go. Write the report only after all checks are complete.


Review Criteria

Logic and Correctness

  • Off-by-one errors, incorrect comparisons, inverted conditions?
  • Concurrency hazards (race conditions, missing locks, shared mutable state)?
  • Edge cases handled: empty input, null/undefined, zero, negative, max values?
  • Error paths handled — not just the happy path?
  • Existing invariants or contracts broken?

Code Quality

  • Functions single-purpose and ≤ ~30 lines?
  • Logic duplicated rather than extracted?
  • Magic numbers replaced by named constants?
  • Abstractions at the right level — not too leaky, not over-engineered?
  • Names clear and consistent with existing codebase conventions?
  • Dead code introduced?

Read the full file on GitHub · 137 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 5d ago First seen · 137 lines · 42 tokens per session scan A c58be6d627e0

Subscribe to this mod's changes

code-reviewer-quality is an agent published in the GitHub repository kid-sid/claude-spellbook (187 stars, last pushed 1mo ago), licensed MIT. It adds 42 tokens to every session and 1,006 once invoked, about $0.0002 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.