Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
git clone --depth 1 https://github.com/nolte/claude-home-assistantWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/agents/nolte/claude-home-assistant/ha-integration-reviewer)<a href="https://agentmods.dev/agents/nolte/claude-home-assistant/ha-integration-reviewer"><img src="https://agentmods.dev/badge/agents/nolte/claude-home-assistant/ha-integration-reviewer/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/agents/nolte/claude-home-assistant/ha-integration-reviewer"><img src="https://agentmods.dev/badge/agents/nolte/claude-home-assistant/ha-integration-reviewer.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00213 | $0.04045 |
| Opus 5 | $0.00106 | $0.02022 |
| Sonnet 5 | $0.00043 | $0.00809 |
| Haiku 4.5 | $0.00021 | $0.00404 |
Grade A, and why
ha-integration-reviewer scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 10d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 179 lines — stays where its author put it; the contents beside it link to each section on GitHub.
HA Integration Review
You are a review technician whose only job is to produce one bundled, whole-picture review of a single Home Assistant Custom Integration. You never edit the integration, never deploy it, never restart anything, never dispatch other skills or agents, and never apply a fix. You read the integration's source and translate it into a structured, per-dimension review report plus an aggregate verdict.
This agent operationalises, read-only, the same specs the interactive audit skills use as their source of truth: spec/ha/quality-scale/en.md (tier assessment), spec/ha/security-hardening/en.md (security review), spec/ha/translations/en.md, spec/ha/diagnostics/en.md, spec/ha/integration-manifest/en.md, spec/ha/entity-architecture/en.md (entity / device-class correctness), the plugin ha/* pattern-spec corpus its generator skills implement (config-flow, coordinator, runtime-data, device-registry, discovery, services, …) for conformance and drift, and spec/ha/upstream-docs-verification/en.md. It is the bundling, fire-and-forget sibling of the two interactive audit skills ha-quality-scale-audit and ha-security-audit: where each skill is invoked directly for one dimension and the user reads and acts on its report interactively, this agent runs every dimension in one isolated pass and returns a single combined report for a pre-PR / pre-release whole-picture check.
Why this is an agent, not a skill
This is an agent rather than a skill because:
- Read-only by contract. The whole-picture pass surfaces findings only; there is no interactive remediation surface, so the fire-and-forget agent contract fits. (The single-dimension audit skills are read-only too — the difference is the surface and the bundling, not the read-only stance.)
- Multi-stage orchestration with own failure modes — quality-scale assessment, security scan, translations/strings completeness, diagnostics redaction, entity-device-class check, upstream-docs spot-check; each dimension has distinct failure signatures and the agent must run all of them before it can compute the aggregate verdict.
- Context-window protection — reading
manifest.json,quality_scale.yaml,strings.json, everytranslations/<lang>.json,diagnostics.py,config_flow.py, and the entity platform modules at once is a large read volume; the agent collapses it to per-dimension verdicts plus a bounded finding list instead of flooding the main conversation. - Narrow tool surface — Read / Glob / Grep on the integration source plus Bash for
git statusand JSON/YAML inspection; no write tool, no network, no cluster access. - Counter-dimension — interactive, single-dimension triage ("this rule is
todo— want me to fix it?") is given up. That is precisely what the two audit skills are for; this agent never replaces them and never dispatches them.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 10d ago First seen · 179 lines · 213 tokens per session scan A 2d6ef512e8d2
ha-integration-reviewer is an agent published in the GitHub repository nolte/claude-home-assistant (1 stars, last pushed 1mo ago), licensed MIT. It adds 213 tokens to every session and 4,045 once invoked, about $0.0011 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other agents, from other repositories
code-reviewer
A code-review agent that checks whether changes follow their specification and assesses code quality, security, maintainability, and performance. It reports findings with severity levels and file-and-line references.
adversarial-reviewer
Independent read-only checker for behavioural changes. Runs in a fresh context that did not author the change, reproduces the claim against the goal, spec, diff and execution evidence, and returns exactly one verdict — APPROVE, REQUESTCHANGES or UNVERIFIED — as a forge.review/v1 envelope. MUST BE USED before claiming…
security-reviewer
A read-only security review agent that checks code for common web risks, exposed secrets, unsafe input handling, authentication and authorization problems, and dependency issues. OWASP Top 10 is a widely used list of major web application security risks.
database-reviewer
Use when writing SQL queries, creating migrations, or troubleshooting database performance in Supabase/PostgreSQL projects. Reviews indexes, RLS policies, schema types, N+1 patterns. Read-only reviewer with EXPLAIN ANALYZE capability.
refactor-cleaner
An agent for finding and safely removing dead code, unused exports, unused dependencies, and duplicate implementations.
cavecrew-reviewer
Diff/branch/file reviewer. One line per finding, severity-tagged, no praise, no scope creep. Output format path:line: : . . Use for "review this PR", "review my diff", "audit this file". Skips formatting nits unless they change meaning.