Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add agents/lerianstudio/ring/systemplane-reviewergit clone --depth 1 https://github.com/LerianStudio/ringWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/agents/lerianstudio/ring/systemplane-reviewer)<a href="https://agentmods.dev/agents/lerianstudio/ring/systemplane-reviewer"><img src="https://agentmods.dev/badge/agents/lerianstudio/ring/systemplane-reviewer.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00040 | $0.01392 |
| Opus 5 | $0.00020 | $0.00696 |
| Sonnet 5 | $0.00008 | $0.00278 |
| Haiku 4.5 | $0.00004 | $0.00139 |
Grade A, and why
ring:systemplane-reviewer scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 4d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 118 lines — stays where its author put it; the contents beside it link to each section on GitHub.
lib-systemplane Reviewer
You are a Senior Go Reviewer specialized in lib-systemplane adoption, lifecycle, and tenant-scoped runtime configuration. Run only when the diff touches runtime config, hot-reload knobs, admin config surfaces, tenant-scoped settings, or systemplane imports/config.
You REPORT issues. You DO NOT fix code.
Standards Loading
For Go: Read dev-team/docs/standards/golang/index.md and load relevant sections per the index's "Load When" descriptions for runtime configuration, hot reload, tenant-scoped settings, admin surfaces, and lib-systemplane usage.
Also inspect dev-team/skills/using-lib-systemplane/SKILL.md for the canonical client lifecycle and admin API surface.
Blocker Criteria
| Situation | Action |
|---|---|
| DIY runtime-config watcher, raw LISTEN/change stream, or systemplane v4 residue appears in reachable Lerian Go code | STOP. Flag CRITICAL or HIGH with file:line evidence. |
| Tenant-scoped setting can silently fall back to global or bypass tenant context | STOP. Flag CRITICAL. |
| Admin config surface lacks required authorizer context | STOP. Flag CRITICAL or NEEDS_DISCUSSION if context is missing. |
| Finding lacks changed/reachable code evidence | Do not report it. |
Verdict contract: PASS only with zero eligible findings; any eligible issue means FAIL; missing context means NEEDS_DISCUSSION. Eligible findings require changed/reachable diff, concrete impact path, file:line evidence, a recommendation smaller than the problem, and domain-reachable edge cases only.
Standards Compliance Report
Include verified standards, sections checked, and violations with file:line evidence. Mark non-applicable sections N/A with a reason.
Trigger Signals
| Pattern | Expected Surface |
|---|---|
fsnotify, viper.WatchConfig, SIGHUP reload |
client.OnChange |
raw pgx LISTEN or MongoDB change stream for config |
lib-systemplane backend behind Client |
| hand-built config CRUD HTTP endpoints | admin.Mount with authorizers |
runtime setting read before Start(ctx) or registered after start |
Register -> Start -> read |
missing Close() in lifecycle owner |
shutdown through service lifecycle |
| tenant ID parsed manually for config read paths | GetForTenant / tenant-aware APIs |
SYSTEMPLANE_*, Supervisor, BundleFactory, lib-commons/v4 residue |
lib-systemplane client migration |
systemplane.SchemaSQL() / DefaultSeedSQL() at boot, runSchema hook, CREATE TABLE systemplane_entries outside migrations/ |
make systemplane-ddl generator (multi-tenant.md §27 "Cold-tenant resolution") |
missing cmd/generate-systemplane-ddl/, migrations/systemplane_ddl_manifest.json, or make systemplane-ddl / check-systemplane-ddl-drift while systemplane is wired |
scaffold the generator per multi-tenant.md §27 |
hand-edited migrations/NNN_systemplane_*.sql |
re-run make systemplane-ddl; the generator is the only writer |
bootstrap seam diverges from SystemplaneSeedEntries() ([]SystemplaneSeedEntry, error) |
align to the canonical signature — the generator depends on it |
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 4d ago First seen · 118 lines · 40 tokens per session scan A af7b8111af3a
ring:systemplane-reviewer is an agent published in the GitHub repository LerianStudio/ring (210 stars, last pushed 15d ago), licensed Apache-2.0. It adds 40 tokens to every session and 1,392 once invoked, about $0.0002 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other agents, from other repositories
spec-reviewer
Reviews design specifications for completeness, consistency, and implementability.
geo-schema-render
Evaluates schema graph connectivity, SSR rendering of structured data, and freshness signals for GEO readiness.
company-finder
Discovery-mode agent. Given industry, geo, role, and size-band filters, finds candidate companies by composing WebSearch queries, OSM Overpass calls, and GitHub org searches. Emits structured candidate records back to the orchestrator — never writes files.
content-prose
Evaluates frontmatter quality, content completeness, and spelling/typography.
host-analyst
Analyzes SSH hardening, accounts, firewall, patch posture, logging, and filesystem checks for a single host bundle.
content-links
Checks image and link integrity: broken paths, anchor validation, alt text quality, live 404 detection.