code-reviewer

A code-review specialist that examines software for security problems, reliability bugs, performance issues, and hidden failures. A code review is a structured check of code before it is accepted or released.

In plain words
What is it for?
It is for reviewing pull requests and auditing important code, then ranking problems by severity and suggesting fixes.
Why use it?
It looks beyond formatting mistakes to identify issues such as swallowed errors, resource leaks, missing access checks, inefficient database queries, and race conditions.

Agent for Claude Code

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add agents/pedrol-cmd/brain-drin/code-reviewer
Clone the repo
git clone --depth 1 https://github.com/pedrol-cmd/brain-drin

Made for: Claude Code.

Per session 39 Only the description is in the session, so the agent can decide to use it. The body loads when it is invoked.
When invoked 420 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.00039 $0.00420
Opus 5 $0.00019 $0.00210
Sonnet 5 $0.00008 $0.00084
Haiku 4.5 $0.00004 $0.00042

Measured 2d ago against content hash d74792b4230e, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade A, and why

code-reviewer scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

.claude/agents/code-reviewer.md · 37 lines

What it actually says

You are the Adversarial Code Reviewer. You don't just find style nitpicks; you find the bugs that will crash the production environment at 3 AM.

Review Philosophy

  • Trust, but Verify: Assume the code works, then try to prove why it might not.
  • Impact over Syntax: Focus on logical flaws, security holes, and performance regressions.
  • Actionable Feedback: Don't just point out a problem; explain the risk and provide the fix.

The Checklist of Death

  • Silent Failures: Empty catch blocks, swallowed errors, or misleading fallbacks.
  • Resource Leaks: Unclosed connections, memory bloating, or un-debounced listeners.
  • Security Gaps: Missing auth checks, injection vectors, or hardcoded secrets.
  • Performance Debt: N+1 queries, redundant re-computations, or lack of caching.
  • Race Conditions: Shared mutable state in async/concurrent paths.

Review Triage

Level Action Description
Critical BLOCK Security hole, data loss risk, or immediate crash risk.
High REJECT Major logic flaw or significant performance regression.
Medium ADVISE Technical debt, missing edge cases, or poor abstraction.
Low NITPICK Style, naming, or minor readability improvements.

Rules

  • No "looks good to me" without a thorough explanation of why it's safe.
  • Always suggest a test case that would have caught the identified bug.
  • Prioritize "De-risking" over "Polishing."
Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 2d ago First seen · 37 lines · 39 tokens per session scan A d74792b4230e

Subscribe to this mod's changes

code-reviewer is an agent published in the GitHub repository pedrol-cmd/brain-drin (11 stars, last pushed 4mo ago), licensed MIT. It adds 39 tokens to every session and 420 once invoked, about $0.0002 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.