devops-reviewer

devops-reviewer is an agent for Claude Code from niels-emmer/myace. It costs 18 tokens per session (253 once invoked), scanned A, original, MIT.

A read-only DevOps reviewer examines the automation that builds, tests, and deploys software, along with its artifacts, secrets, and monitoring. DevOps is the work of delivering and operating software through repeatable automation.

In plain words
What is it for?
Use it to review CI/CD pipelines, Dockerfiles, deployment settings, and monitoring configuration. It checks staged releases, immutable versioned artifacts, runtime secret injection, logging, metrics, alerts, and rollback readiness.
Why use it?
It exposes secret leaks, unsafe release steps, replaceable build outputs, weak health checks, and deployments that could affect too much at once. It also highlights missing or slow rollback options.

Agent for Claude Code

Written for Claude Code: a Claude Code subagent (agents/*.md). Also seen: mentions subagents; mentions Codex; built for aider.

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add agents/niels-emmer/myace/devops-reviewer
Clone the repo
git clone --depth 1 https://github.com/niels-emmer/myace

Made for: Claude Code.

Wrote this? Show the measurements

A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.

agentmods badge for devops-reviewer

README.md
[![agentmods](https://agentmods.dev/badge/agents/niels-emmer/myace/devops-reviewer.svg)](https://agentmods.dev/agents/niels-emmer/myace/devops-reviewer)
Your own site
<a href="https://agentmods.dev/agents/niels-emmer/myace/devops-reviewer"><img src="https://agentmods.dev/badge/agents/niels-emmer/myace/devops-reviewer.svg" alt="Measured on agentmods" height="20"></a>
Per session 18 Only the description is in the session, so the agent can decide to use it. The body loads when it is invoked.
When invoked 253 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5.1 $0.00018 $0.00253
Opus 5 $0.00009 $0.00127
Sonnet 5 $0.00004 $0.00051
Haiku 4.5 $0.00002 $0.00025

Measured 2d ago against content hash 1eadc4d2c37a, method: parsed. Prices are Anthropic first-party input rates as of 2026-09-06, from the pricing page.

Security

Grade A, and why

devops-reviewer scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

collections/additional/devops/agents/devops-reviewer.md · 26 lines

What it actually says

Read-only DevOps reviewer. Check pipeline safety, artifact integrity, and deployment blast radius.

Responsibilities

  • Review pipeline definitions for secret exposure, stage isolation, and proper gate sequencing.
  • Confirm artifacts are immutable and versioned — no rebuild-from-source for promotions.
  • Check that secrets are injected at deploy time, not baked into images or config.
  • Assess deployment blast radius: canary/staged rollouts, rollback speed, health check coverage.
  • Verify observability coverage: structured logging, RED/USE metrics, alerting on symptoms.

Permission posture

Strictly read-only. Read pipeline definitions, Dockerfiles, deployment configs, monitoring configs. Never edit files or run deployment commands.

Handoff

Return findings to devops-builder or the user. Flag any secret exposure or missing rollback capability as blocking.

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 2d ago Changed · +1 lines 1eadc4d2c37a
  2. 5d ago First seen · 25 lines · 18 tokens per session scan A f48ee2ae8b2d

Subscribe to this mod's changes

devops-reviewer is an agent published in the GitHub repository niels-emmer/myace (1 stars, last pushed 4d ago), licensed MIT. It adds 18 tokens to every session and 253 once invoked, about $0.0001 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.

Related

Other agents, from other repositories

code-reviewer

当一个主要项目步骤完成并需要根据原始计划和编码标准进行审查时使用此智能体。示例: Context: 用户正在创建一个代码审查智能体,应在逻辑代码块编写完成后调用。user: "我已经按照计划第 3 步完成了用户认证系统的实现" assistant: "干得好!让我使用 code-reviewer 智能体来根据我们的计划和编码标准审查实现" 由于一个主要项目步骤已完成,使用 code-reviewer 智能体来验证工作是否符合计划并识别任何问题。 Context: 用户完成了一个重要功能的实现。user: "任务管理系统的 API 端点现在完成了——这涵盖了我们架构文档中的第 2 步" assistant: "很好!让我用…

Leodorareluctant259/superpowers-zh · 247 tokens

design-archeologist

Long-running codebase scan. Extracts de-facto design tokens from existing UI code, clusters them by frequency, names them, returns a draft DESIGN.md body conforming to the Google Labs spec. Dispatched by /mddesign:harvest.

OthmanAdi/MDDesign · 56 tokens

planner

Drafts a PhaseSpec v1 from a phase in taskplan.md. Read-only on planning files; returns the spec as text.

OthmanAdi/MDDesign · 29 tokens

executor

Consumes one PhaseSpec v1 and runs it end to end. Reads referenced files itself. Returns a structured result. Default subagent for /mddesign:team dispatch.

OthmanAdi/MDDesign · 37 tokens

orchestrator

Agent "orchestrator" from extracurricular-ai/codex-rewind, covering user updates spec, reviews and general guidelines.

extracurricular-ai/codex-rewind · 0 tokens

architect

Generate or refresh the Architecture doc, shards, Mermaid diagrams, and ADRs, ensuring alignment with PRD, UX spec, and backlog.

im-shashanks/CoaCoA · 0 tokens