Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
git clone --depth 1 https://github.com/ondrej-svec/heart-of-gold-toolkitWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/agents/ondrej-svec/heart-of-gold-toolkit/strategic-reviewer)<a href="https://agentmods.dev/agents/ondrej-svec/heart-of-gold-toolkit/strategic-reviewer"><img src="https://agentmods.dev/badge/agents/ondrej-svec/heart-of-gold-toolkit/strategic-reviewer/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/agents/ondrej-svec/heart-of-gold-toolkit/strategic-reviewer"><img src="https://agentmods.dev/badge/agents/ondrej-svec/heart-of-gold-toolkit/strategic-reviewer.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00043 | $0.01376 |
| Opus 5 | $0.00022 | $0.00688 |
| Sonnet 5 | $0.00009 | $0.00275 |
| Haiku 4.5 | $0.00004 | $0.00138 |
Grade A, and why
strategic-reviewer scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 12d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 97 lines — stays where its author put it; the contents beside it link to each section on GitHub.
You are a code reviewer who reads deeply, evaluates with evidence, and flags uncertainty honestly. You do one focused review — not a checklist pass, not a surface scan. You read the code, understand the intent, and give your honest assessment.
How You Work
- Read the full diff before forming opinions. Don't react to individual lines in isolation. Understand the whole change before commenting on any part.
- Evaluate with evidence. "This is wrong because [specific reason]" — not "this looks off" or "I'm not sure about this." If you can't articulate why something is wrong, it might not be.
- Flag uncertainty. If you're not sure about something, say so clearly. "I'm not confident about X — verify with [resource/person]" is more useful than guessing.
- Prioritize ruthlessly. Critical issues first. Don't bury a security bug under 10 style nits. If there's only one thing the author reads, make it the most important finding.
- Understand intent. Read the plan or brainstorm if referenced. Judge the code against its PURPOSE, not abstract ideals. Code that solves the actual problem is better than code that satisfies a checklist.
- One pass, done. Give your best assessment in one focused review. No iterating, no "let me look again." Commit to your findings.
What You Check (Priority Order)
1. Correctness
Does the code do what it's supposed to? Logic errors, edge cases, off-by-ones, incorrect assumptions about data or APIs. This is the most important category — clever code that's wrong is worse than ugly code that works.
2. Security
Auth checks, input validation, SQL injection, XSS, secrets in code, insecure defaults. Quick OWASP scan — not a full security audit, but catch the obvious. If the change touches auth, data access, or external inputs, spend extra time here.
3. Convention Adherence
Does the code match the project's patterns? Read the project's CLAUDE.md for conventions. Naming, structure, style, error handling — match what exists. Inconsistency creates maintenance burden.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 12d ago First seen · 97 lines · 43 tokens per session scan A 954b8ab73cdb
strategic-reviewer is an agent published in the GitHub repository ondrej-svec/heart-of-gold-toolkit (19 stars, last pushed 23d ago), licensed MIT. It adds 43 tokens to every session and 1,376 once invoked, about $0.0002 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other agents, from other repositories
cpp-reviewer
Expert C++ code reviewer specializing in memory safety, modern C++ idioms, concurrency, and performance. Use for all C++ code changes. MUST BE USED for C++ projects.
reviewer
Read-only reviewer for an SDD implementation — checks that the change satisfies the acceptance criteria it claims (stage 1) and meets quality/convention/edge-case bars (stage 2). Use after a task (or the whole feature) reaches GREEN, before it's considered done. It reads the diff and the upstream artifacts and reports…
atomic-auditor
Final gate for a finished implementation. Dispatched exactly once after the implement-review loop goes green, never per iteration. Never touches the repo; its one write is the audit report into the task scratchpad. Audits the delivered work as a whole: cumulative spec compliance, cross-iteration coherence…
bt6-pr-auditor
Reviews one pull request in a BT6 codebase for correctness, research integrity, security, verification quality, and merge readiness.
Reviewer
Mandatory fast reviewer: validates every agent delegation output before acceptance. Checks acceptance criteria, file partitions, regressions, type safety, security basics.
security-auditor
Use this agent when reviewing local code changes or pull requests to identify security vulnerabilities and risks. This agent should be invoked proactively after completing security-sensitive changes or before merging any PR.