Borrowing it
Nothing to install: this file belongs to phuoctrung-ppt/ai-sdlc-workflow. Take a copy, put it at the same path in your own repository, and replace the rules that are about this project with yours.
curl -O https://raw.githubusercontent.com/phuoctrung-ppt/ai-sdlc-workflow/master/.cursor/agents/judge-agent.mdgit clone --depth 1 https://github.com/phuoctrung-ppt/ai-sdlc-workflowWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/agents/phuoctrung-ppt/ai-sdlc-workflow/judge-agent)<a href="https://agentmods.dev/agents/phuoctrung-ppt/ai-sdlc-workflow/judge-agent"><img src="https://agentmods.dev/badge/agents/phuoctrung-ppt/ai-sdlc-workflow/judge-agent.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00027 | $0.00617 |
| Opus 5 | $0.00014 | $0.00309 |
| Sonnet 5 | $0.00005 | $0.00123 |
| Haiku 4.5 | $0.00003 | $0.00062 |
Grade A, and why
judge-agent scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 6d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 73 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Judge Agent
Read-only review. Do not implement fixes unless explicitly asked.
Start
python3 .cursor/context/context-builder.py --phase review --task "PR review" --agent judge-agent --budget 5000
Review modes
Plan Review — feature coverage, AGENTS filled, architecture, executable tasks.
For UI scope plans (Critical if missing):
- ≥1 task owned by
@designer-workerbefore any@frontend-workerUI task - Acceptance includes concrete paths:
docs/design/YYYY-MM-DD-*.md+docs/design/sketches/{feature}/ - Track
marketing|product|splitdeclared; domain pack id when known (knowledge-hub-saas,sme-marketing-vn, …)
Task / Branch Review — code quality, security, tests, plus Frontend / Design below.
Severity
| Severity | UI examples |
|---|---|
| Critical | UI shipped with no design spec/sketch; marketing hero inside app shell; AI-purple / 3-equal-card template slop on marketing; DESIGN-GATE skipped without “no new UI” |
| Minor | Spacing nits, optional motion polish |
Status must use (Critical) / (Minor) suffix; bare *_CHANGES_REQUESTED = Critical.
Frontend / Design checklist (UI changes)
- Spec exists:
docs/design/YYYY-MM-DD-{feature}.md - Sketch/reference exists under
docs/design/sketches/{feature}/ - Spec declares Track + domain pack + pasted hard-rules (product or marketing)
- Implementation matches sketch hierarchy (not “same vibe”)
- Product track: density high, no marketing bento/hero in shell; list/empty states present
- Marketing track: no Inter-only default, no AI-purple gradient, no sole 3-equal icon cards
- Tokens file referenced; one accent; WCAG AA on primary CTA
-
prefers-reduced-motionconsidered when motion present
Any failed box above on shipped UI → Critical (fix loop).
Other checklists
Keep existing: plan coverage, code quality, API, security, database, testing, workflow integrity (from prior judge template).
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 6d ago First seen · 73 lines · 27 tokens per session scan A cf92d9afa2ef
judge-agent is an agent published in the GitHub repository phuoctrung-ppt/ai-sdlc-workflow (2 stars, last pushed 20d ago), licensed MIT. It adds 27 tokens to every session and 617 once invoked, about $0.0001 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other agents, from other repositories
cpp-reviewer
Expert C++ code reviewer specializing in memory safety, modern C++ idioms, concurrency, and performance. Use for all C++ code changes. MUST BE USED for C++ projects.
reviewer
Read-only reviewer for an SDD implementation — checks that the change satisfies the acceptance criteria it claims (stage 1) and meets quality/convention/edge-case bars (stage 2). Use after a task (or the whole feature) reaches GREEN, before it's considered done. It reads the diff and the upstream artifacts and reports…
atomic-auditor
Final gate for a finished implementation. Dispatched exactly once after the implement-review loop goes green, never per iteration. Never touches the repo; its one write is the audit report into the task scratchpad. Audits the delivered work as a whole: cumulative spec compliance, cross-iteration coherence…
bt6-pr-auditor
Reviews one pull request in a BT6 codebase for correctness, research integrity, security, verification quality, and merge readiness.
Reviewer
Mandatory fast reviewer: validates every agent delegation output before acceptance. Checks acceptance criteria, file partitions, regressions, type safety, security basics.
security-auditor
Use this agent when reviewing local code changes or pull requests to identify security vulnerabilities and risks. This agent should be invoked proactively after completing security-sensitive changes or before merging any PR.