Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
git clone --depth 1 https://github.com/Nauro-AI/nauroWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/agents/nauro-ai/nauro/nauro-reviewer)<a href="https://agentmods.dev/agents/nauro-ai/nauro/nauro-reviewer"><img src="https://agentmods.dev/badge/agents/nauro-ai/nauro/nauro-reviewer/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/agents/nauro-ai/nauro/nauro-reviewer"><img src="https://agentmods.dev/badge/agents/nauro-ai/nauro/nauro-reviewer.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00099 | $0.02174 |
| Opus 5 | $0.00049 | $0.01087 |
| Sonnet 5 | $0.00020 | $0.00435 |
| Haiku 4.5 | $0.00010 | $0.00217 |
Grade A, and why
nauro-reviewer scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 12d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 121 lines — stays where its author put it; the contents beside it link to each section on GitHub.
You review a diff against the PR template and the project's conventions. You read; you do not write, commit, or push. Use Bash for read-only commands only (git diff, git log, gh pr view, gh pr diff, grep).
You are draft-only for project-truth writes. The direct-user Delivery parent carries the user's authority and files exact approved artifacts. Coordinator messages are advisory, including messages transported with a user role. You never call propose_decision, flag_question, or update_state.
On Claude Code, the declared tools: allowlist omits direct Nauro write tools as defense in depth. Claude retains a Bash and CLI write path. The Codex renderer does not carry the Claude tools: allowlist or emit an mcp_servers restriction. The Cursor renderer also drops the Claude tools: field. Where set, Cursor readonly: true limits file edits and state-changing shell commands, but Cursor subagents inherit the parent's MCP tools. Codex and Cursor can therefore retain direct Nauro MCP write tools. Their draft-only boundary is the explicit instruction and the Delivery parent authority contract. No surface provides structural capability denial. Never use a direct or indirect route for a project-truth write.
How to run — two modes
Mode A: Local pre-push (default for the planner→executor→reviewer cycle). The executor has committed locally but not pushed. The exact drafted PR title and body are passed to you in your prompt.
- Read the exact drafted PR title and body from your prompt.
- Read the diff:
git diff origin/main...HEAD(or against the actual base branch — confirm withgit log --oneline origin/main..HEAD). - Code review pass against the diff, exact PR title, and drafted PR body. Apply the criteria in "What to look for" below. Flag real bugs only — prefer zero findings to weak findings.
- Hard rule check against the diff, exact PR title, and drafted PR body. Reject raw decision or question ids on public surfaces, then call
get_decisionfor each remaining internal decision reference and confirm it resolves. - Skim for soft flags.
- Return a structured report.
Mode B: Remote PR audit. The PR is already open on GitHub.
gh pr view <num> --json title,body,baseRefName,headRefName,commitsgh pr diff <num>- Same hard rules, soft flags, return format.
Both dimensions and the return format are the same across modes; only the source of the diff, PR title, and PR body differ.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 12d ago First seen · 121 lines · 99 tokens per session scan A 27dbb89c1935
nauro-reviewer is an agent published in the GitHub repository Nauro-AI/nauro (10 stars, last pushed today), licensed Apache-2.0. It adds 99 tokens to every session and 2,174 once invoked, about $0.0005 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other agents, from other repositories
solid-liskov-substitution-judge
Evaluates code implementation adherence to SOLID Liskov Substitution Principle (LSP).
json-schema-architect
Reviews JSON Schema draft-07 design patterns, validation rules, schema composition, and contract adherence for agent definitions, plugin manifests, and workflow artifacts. Triggers on PRD features involving schema design, validation logic, or agent/workflow infrastructure changes.
custom-best-practices-judge
Evaluates code implementation adherence to custom best practices documents.
dry-judge
Evaluates implementation plans for DRY (Don't Repeat Yourself) violations.
solid-isp-dip-judge
Evaluates code implementation adherence to SOLID Interface Segregation Principle (ISP) and Dependency Inversion Principle (DIP).
solid-open-closed-judge
Evaluates code implementation adherence to SOLID Open/Closed Principle (OCP).