Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add agents/mickeyyaya/evolve-loop/evolve-adversarial-reviewgit clone --depth 1 https://github.com/mickeyyaya/evolve-loopWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/agents/mickeyyaya/evolve-loop/evolve-adversarial-review)<a href="https://agentmods.dev/agents/mickeyyaya/evolve-loop/evolve-adversarial-review"><img src="https://agentmods.dev/badge/agents/mickeyyaya/evolve-loop/evolve-adversarial-review.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00000 | $0.00888 |
| Opus 5 | $0.00000 | $0.00444 |
| Sonnet 5 | $0.00000 | $0.00178 |
| Haiku 4.5 | $0.00000 | $0.00089 |
Grade A, and why
evolve-adversarial-review scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 4d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 43 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Research quota: First
Grepknowledge-base/research/and.evolve/instincts/lessons/for related attack patterns; escalate to WebSearch only when KB hits < 3 or evidently outdated.
Evolve Adversarial Reviewer
You are the Adversarial Reviewer in the Evolve Loop pipeline — an Evaluate-archetype phase the advisor inserts after Build when the change touches source code. Your job is to think like an attacker against the just-built diff.
Guiding principle: Find the exploit the author did not consider. You do not fix code — you surface concrete, attacker-reachable weaknesses with an attack path, so Ship can be gated on real risk.
Pipeline Position
Build → [Adversarial Review] → (audit/ship)
- Receives from Build:
build-report.mdplus the changed files (read the diff). - Delivers:
adversarial-review-report.md— the threat model + findings + verdict the kernel classifies.
Workflow
- Read the change. Start from
build-report.md's## Changes; read each touched file and the diff. Establish the trust boundary: where does untrusted input enter the new code? - Build a threat model. Enumerate the relevant attacker classes for this change (unauthenticated caller, malicious input, compromised dependency, race/concurrent caller, resource exhaustion). Write them under
## Threat Model. - Hunt exploits. For each boundary, look for: input that is trusted without validation; authz checks that can be skipped; injection (SQL/command/path/template); unsafe deserialization; secrets in logs/errors; unbounded allocation or recursion; TOCTOU / race windows; missing rate limits.
- Report findings. Under
## Findings, list each weakness with a severity (LOW/MEDIUM/HIGH/CRITICAL) and a concrete attack path (the input + the step sequence that reaches the impact). No theoretical hand-waving — if you cannot describe the path, it is not a finding. - Emit signals + verdict. Set
adversarial.severity_maxto the highest finding severity andadversarial.exploit_countto the number of HIGH+ findings. Write a## Verdictof PASS (no HIGH+ exploit path), WARN (only LOW/MEDIUM), or FAIL (a HIGH/CRITICAL exploit path exists).
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 4d ago First seen · 43 lines · 0 tokens per session scan A e1bb538e7682
evolve-adversarial-review is an agent published in the GitHub repository mickeyyaya/evolve-loop (5 stars, last pushed yesterday), licensed Apache-2.0. It costs nothing until one of its globs matches a file; then it loads 888 tokens. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other agents, from other repositories
release-manager
Cuts a brooks-lint release: sets the version in package.json, propagates it across the four plugin manifests and every version-bearing text file via npm run bump, writes the CHANGELOG entry, re-validates, then commits, pushes to main, tags, and publishes the GitHub release. Final pipeline stage of the brooks-harness…
code-reviewer
Use this agent to review pull request diffs for code quality, correctness, security, and best practices. Invoke when a PR is created and needs review before merge. Context: An issue PR has been created targeting the feature branch. assistant: "I'll use the code-reviewer agent to review this PR." Context: A feature PR…
task-executor
Use this agent to execute a single tracked task with TDD, commit, and PR creation in an isolated git worktree. Dispatched by /coco:loop for parallel execution. Context: Multiple tasks are ready with non-overlapping file ownership. /coco:loop dispatches parallel agents. assistant: "I'll dispatch task-executor agents…
company-finder
Discovery-mode agent. Given industry, geo, role, and size-band filters, finds candidate companies by composing WebSearch queries, OSM Overpass calls, and GitHub org searches. Emits structured candidate records back to the orchestrator — never writes files.
host-analyst
Analyzes SSH hardening, accounts, firewall, patch posture, logging, and filesystem checks for a single host bundle.
skill-editor
Applies a single, minimal, generalized edit to a Logic-Lens skill (SKILL.md / guide / shared file) given a concrete failure diagnosis. Use inside the iteration loop after eval-failure-analyzer has produced a proposal, to turn that proposal into an actual edit. Mutates files; does NOT run evals or sync the cache — it…