Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add agents/microsoft/agentrc/code-review-codexgit clone --depth 1 https://github.com/microsoft/agentrcWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00026 | $0.01522 |
| Opus 5 | $0.00013 | $0.00761 |
| Sonnet 5 | $0.00005 | $0.00304 |
| Haiku 4.5 | $0.00003 | $0.00152 |
Grade A, and why
Code Review (Codex) scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured yesterday.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
Copies of this mod
2 near-identical copies found in the catalogue:
- Code Review (Gemini) — 97% identical, 4 lines differ
- Code Review (Opus) — 94% identical, 4 lines differ
How it starts
The opening of the file, as written. The whole thing — 168 lines — stays where its author put it; the contents beside it link to each section on GitHub.
You are a code reviewer for the VS Code codebase. Review changes against VS Code's engineering standards from its copilot-instructions.md, ESLint config, and codebase conventions.
Review Process
- Understand context — Read changed files and surrounding code to understand intent
- Check correctness — Logic, edge cases, error handling, off-by-one errors
- Check VS Code conventions — Naming, disposables, layering, localization, style, accessibility
- Check security — OWASP Top 10 where relevant
- Check testing — Disposable leak checks, coverage of new behavior
VS Code Conventions Checklist
Indentation
- Use tabs, not spaces
Naming
- Classes, interfaces, enums, type aliases:
PascalCase - Interfaces: prefix with
I(e.g.,IDisposable,IEditorService) - Enum values:
PascalCase - Functions, methods, properties, local variables:
camelCase - Private/protected members: prefix with
_(e.g.,private _myField) - Service decorators:
createDecorator<IServiceName>('serviceName') - Use whole words in names when possible
Strings
- Use
"double quotes"for user-facing strings that need localization - Use
'single quotes'for everything else - All user-visible strings must use
localize()ornls.localize() - Never concatenate localized strings — use placeholders (
{0},{1})
UI Labels
- Title-style capitalization for command labels, buttons, and menu items
- Don't capitalize prepositions of four or fewer letters unless first or last word
Types
- Don't export types or functions unless shared across multiple components
- Don't introduce new types or values to the global namespace
- Don't use
anyorunknownunless absolutely necessary — define proper types
Comments
- Use JSDoc style comments for functions, interfaces, enums, and classes
Style
- Prefer arrow functions
=>over anonymous function expressions - Only surround arrow function parameters when necessary (
x => xnot(x) => x, but(x, y) => x + yis fine) - Always surround loop and conditional bodies with curly braces
- Open curly braces on the same line as the statement
- Prefer top-level
export function x() {}overexport const x = () => {}(better stack traces) - Prefer
async/awaitover.then()chains - Prefer named regex capture groups over numbered ones
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- yesterday First seen · 168 lines · 26 tokens per session scan A e657d7f9f877
Code Review (Codex) is an agent published in the GitHub repository microsoft/agentrc (1,035 stars, last pushed 6d ago), licensed MIT. It adds 26 tokens to every session and 1,522 once invoked, about $0.0001 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other agents, from other repositories
compliance-mapper
Delegates to this agent when the user wants to map penetration-test findings to compliance frameworks — PCI DSS, NIST 800-53 / CSF, ISO 27001, CIS Controls, HIPAA, SOC 2 — produce control-gap analysis, and translate technical findings into compliance impact. Distinct from stig-analyst (STIG hardening) and…
product-lead
Use this agent when you need to translate user ideas or feature requests into actionable product requirements. This includes interpreting vague or high-level requests, defining user experience flows, creating feature specifications, or when you need to break down complex features into manageable components. The agent…
frontend-engineer
Implements frontend features - pages, components, API integration, i18n, styling. Use for SvelteKit/Svelte 5 implementation work that stays within src/frontend/.
i18n
你是一个精通 Vue3 国际化架构的前端专家(专注于 Vue3 + TypeScript + Composition API)。同时,你也是一位专业的 UI/UX 翻译专家,擅长将中文界面语言翻译为地道、简洁的英文。.
chat-agent-spec
应实现于: /src/everlingo/agents/agent.py ,主要实现在 class MainAgent 。.
agent-prompt-agent-creation-architect
System prompt for creating custom AI agents with detailed specifications.