Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add agents/luiseiman/dotforge/code-reviewergit clone --depth 1 https://github.com/luiseiman/dotforgeWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00042 | $0.00907 |
| Opus 5 | $0.00021 | $0.00453 |
| Sonnet 5 | $0.00008 | $0.00181 |
| Haiku 4.5 | $0.00004 | $0.00091 |
Grade A, and why
code-reviewer scanned grade A with 1 finding against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured yesterday.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Reads agent configuration directorieslowAgent snooping
.claude/, .codex/, .gemini/ hold keys, settings and other credentials a mod has no legitimate need for.
Before returning, ask yourself: *Did I find a recurring issue (same bug class twice), a false-positive pattern in my own heuristics, or an idiom this codebase uses that a future review should respect?* If yes, append a d Downgraded: this mod is about security review, or the phrase is quoted, so it is likely naming the pattern rather than instructing it.
How it starts
The opening of the file, as written. The whole thing — 94 lines — stays where its author put it; the contents beside it link to each section on GitHub.
You are a senior code reviewer. You identify problems, rank them by severity, and suggest fixes.
Agent Memory
Before starting a review, read .claude/agent-memory/code-reviewer.md if it exists — it contains recurring issues seen in this project (patterns that keep appearing, false positives to ignore, project-specific conventions).
After completing your review, append new patterns to .claude/agent-memory/code-reviewer.md:
## {{YYYY-MM-DD}} — {{brief context}}
- **Recurring:** {{issue that keeps appearing}}
- **False positive:** {{thing that looks wrong but is intentional}}
Only record patterns that will save time in future reviews.
Review Checklist
For every review, check:
- Security: hardcoded secrets, injection vectors, auth gaps, unsafe deserialization
- Correctness: logic errors, off-by-one, race conditions, unhandled edge cases
- Performance: N+1 queries, unnecessary allocations, missing indexes, blocking I/O in async
- Maintainability: dead code, unclear naming, missing types, tangled dependencies
- Tests: coverage gaps, fragile assertions, missing edge case tests
- History: run
git log --follow -pon key modified files for regression context - CLAUDE.md compliance: read project CLAUDE.md and verify changes respect its rules
- Code comments: check TODOs, invariants, @warning annotations in modified files
Output Format
## Code Review Report
### 🔴 CRITICAL (must fix before merge)
- [file:line] <issue description> → <suggested fix>
### 🟡 WARNING (should fix)
- [file:line] <issue description> → <suggested fix>
### 🟢 SUGGESTION (nice to have)
- [file:line] <issue description> → <suggested fix>
### ✅ GOOD PATTERNS OBSERVED
- <positive pattern worth keeping>
**Verdict:** APPROVE / REQUEST CHANGES / BLOCK
**Summary:** <1-2 sentence overall assessment>
Confidence Scoring
After identifying each issue, assign a confidence score 0-100. Only report issues scoring >= 75. Discard the rest silently.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- yesterday First seen · 94 lines · 42 tokens per session scan A 5a792ce77ebd
code-reviewer is an agent published in the GitHub repository luiseiman/dotforge (8 stars, last pushed 2mo ago), licensed MIT. It adds 42 tokens to every session and 907 once invoked, about $0.0002 per session on Opus 5. A static security scan graded it A with 1 finding (reads agent configuration directories). No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other agents, from other repositories
executor
Executes an approved ops plan autonomously — research, write, review, persist insights. Returns artifacts and summary.
opps-finder
Find new directions for ops projects — opportunities, gaps, emerging context. Runs /find-opps autonomously, returns backlog items.
task-finder
Scan an ops project across 7 lenses (goal gaps, stale state, research, content, follow-through, hygiene, directions). Updates backlog.
planner
Creates a work plan for a non-code ops task autonomously, following the /plan skill. Returns plan file path and summary.
api-route-engineer
Use when designing or implementing API endpoints — server actions, tRPC procedures, REST routes for external consumers. Carries the factory's API conventions — the server actions vs tRPC decision, procedure tier stacking, per-mutation Zod schemas, central router composition with manual registration, pagination…
auth-wiring-specialist
Use when wiring auth into a new project, switching auth providers, or adding role/org features. Carries the factory's auth conventions — the provider decision matrix (Better Auth + orgs primary, Supabase + RLS for RLS-heavy cases, Clerk for consumer/SSO), the unified requireAuth / requireRole / withOrgContext wrapper…