strategic-reviewer

strategic-reviewer is an agent for Claude Code from ondrej-svec/heart-of-gold-toolkit. It costs 43 tokens per session (1,376 once invoked), scanned A, original, MIT.

A focused code-review agent that examines a complete pull-request or branch diff and judges it against its intended purpose, correctness, and project conventions.

In plain words
What is it for?
Use it to review pull requests, branch changes, or selected files for correctness, quality, and adherence to existing coding practices.
Why use it?
It reduces shallow checklist reviews and puts the most important evidence-based problems first. It also distinguishes confirmed issues from uncertainty.

Agent for Claude Code

Written for Claude Code: shipped in a Claude Code plugin. Also seen: model in frontmatter; mentions CLAUDE.md.

Part of the deep-thought plugin — 11 skills, 9 agents shipped together

Good fit Use it to review pull requests, branch changes, or selected files for correctness, quality, and adherence to existing coding practices.

Compare 6 agents from other repositories ↓
Install with agentmods
npx agentmods add agents/ondrej-svec/heart-of-gold-toolkit/strategic-reviewer
Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

Clone the repo
git clone --depth 1 https://github.com/ondrej-svec/heart-of-gold-toolkit

Made for: Claude Code.

Or install deep-thought, the plugin that ships this one along with the rest of its 11 skills, 9 agents.

Wrote this? Show the measurements

A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.

agentmods badge for strategic-reviewer

README.md
[![agentmods](https://agentmods.dev/badge/agents/ondrej-svec/heart-of-gold-toolkit/strategic-reviewer/github.svg)](https://agentmods.dev/agents/ondrej-svec/heart-of-gold-toolkit/strategic-reviewer)
Your own site
<a href="https://agentmods.dev/agents/ondrej-svec/heart-of-gold-toolkit/strategic-reviewer"><img src="https://agentmods.dev/badge/agents/ondrej-svec/heart-of-gold-toolkit/strategic-reviewer/github.svg" alt="Measured on agentmods" height="20"></a>

Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.

agentmods 80×15 button for strategic-reviewer

Your own site · 80×15
<a href="https://agentmods.dev/agents/ondrej-svec/heart-of-gold-toolkit/strategic-reviewer"><img src="https://agentmods.dev/badge/agents/ondrej-svec/heart-of-gold-toolkit/strategic-reviewer.svg" alt="Reviewed on agentmods" width="80" height="20"></a>
Per session 43 Only the description is in the session, so the agent can decide to use it. The body loads when it is invoked.
When invoked 1,376 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. A grade says what 26 rules found in the file — not that it is safe.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5.1 $0.00043 $0.01376
Opus 5 $0.00022 $0.00688
Sonnet 5 $0.00009 $0.00275
Haiku 4.5 $0.00004 $0.00138

Measured 12d ago against content hash 954b8ab73cdb, method: parsed. Prices are Anthropic first-party input rates as of 2026-09-12, from the pricing page.

Security

Grade A, and why

strategic-reviewer scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 12d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

plugins/deep-thought/agents/strategic-reviewer.md · 97 lines

How it starts

The opening of the file, as written. The whole thing — 97 lines — stays where its author put it; the contents beside it link to each section on GitHub.

You are a code reviewer who reads deeply, evaluates with evidence, and flags uncertainty honestly. You do one focused review — not a checklist pass, not a surface scan. You read the code, understand the intent, and give your honest assessment.

How You Work

  1. Read the full diff before forming opinions. Don't react to individual lines in isolation. Understand the whole change before commenting on any part.
  2. Evaluate with evidence. "This is wrong because [specific reason]" — not "this looks off" or "I'm not sure about this." If you can't articulate why something is wrong, it might not be.
  3. Flag uncertainty. If you're not sure about something, say so clearly. "I'm not confident about X — verify with [resource/person]" is more useful than guessing.
  4. Prioritize ruthlessly. Critical issues first. Don't bury a security bug under 10 style nits. If there's only one thing the author reads, make it the most important finding.
  5. Understand intent. Read the plan or brainstorm if referenced. Judge the code against its PURPOSE, not abstract ideals. Code that solves the actual problem is better than code that satisfies a checklist.
  6. One pass, done. Give your best assessment in one focused review. No iterating, no "let me look again." Commit to your findings.

What You Check (Priority Order)

1. Correctness

Does the code do what it's supposed to? Logic errors, edge cases, off-by-ones, incorrect assumptions about data or APIs. This is the most important category — clever code that's wrong is worse than ugly code that works.

2. Security

Auth checks, input validation, SQL injection, XSS, secrets in code, insecure defaults. Quick OWASP scan — not a full security audit, but catch the obvious. If the change touches auth, data access, or external inputs, spend extra time here.

3. Convention Adherence

Does the code match the project's patterns? Read the project's CLAUDE.md for conventions. Naming, structure, style, error handling — match what exists. Inconsistency creates maintenance burden.

Read the full file on GitHub · 97 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 12d ago First seen · 97 lines · 43 tokens per session scan A 954b8ab73cdb

Subscribe to this mod's changes

strategic-reviewer is an agent published in the GitHub repository ondrej-svec/heart-of-gold-toolkit (19 stars, last pushed 23d ago), licensed MIT. It adds 43 tokens to every session and 1,376 once invoked, about $0.0002 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.

Related

Other agents, from other repositories

cpp-reviewer

Expert C++ code reviewer specializing in memory safety, modern C++ idioms, concurrency, and performance. Use for all C++ code changes. MUST BE USED for C++ projects.

affaan-m/ECC · 41 tokens

reviewer

Read-only reviewer for an SDD implementation — checks that the change satisfies the acceptance criteria it claims (stage 1) and meets quality/convention/edge-case bars (stage 2). Use after a task (or the whole feature) reaches GREEN, before it's considered done. It reads the diff and the upstream artifacts and reports…

genkovich/sdd · 81 tokens

atomic-auditor

Final gate for a finished implementation. Dispatched exactly once after the implement-review loop goes green, never per iteration. Never touches the repo; its one write is the audit report into the task scratchpad. Audits the delivered work as a whole: cumulative spec compliance, cross-iteration coherence…

damusix/atomic-claude · 169 tokens

bt6-pr-auditor

Reviews one pull request in a BT6 codebase for correctness, research integrity, security, verification quality, and merge readiness.

elder-plinius/T3MP3ST · 32 tokens

Reviewer

Mandatory fast reviewer: validates every agent delegation output before acceptance. Checks acceptance criteria, file partitions, regressions, type safety, security basics.

monkilabs/opencastle · 30 tokens

security-auditor

Use this agent when reviewing local code changes or pull requests to identify security vulnerabilities and risks. This agent should be invoked proactively after completing security-sensitive changes or before merging any PR.

NeoLabHQ/context-engineering-kit · 40 tokens