code-reviewer

A read-only agent that examines recently changed code for bugs, security and accessibility gaps, unnecessary complexity, and mismatch with project conventions.

In plain words
What is it for?
It is for reviewing a file list, a component folder, or a Git diff—the set of changes between revisions—and reporting actionable issues.
Why use it?
It gives a second, skeptical review after implementation and turns possible problems into specific findings without changing the files.

Agent for Claude Code

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add agents/punkadillo/figma-code-composer/code-reviewer
Clone the repo
git clone --depth 1 https://github.com/punkadillo/figma-code-composer

Made for: Claude Code.

Per session 89 Only the description is in the session, so the agent can decide to use it. The body loads when it is invoked.
When invoked 1,416 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.00089 $0.01416
Opus 5 $0.00044 $0.00708
Sonnet 5 $0.00018 $0.00283
Haiku 4.5 $0.00009 $0.00142

Measured yesterday against content hash 135fe3bc0854, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade A, and why

code-reviewer scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured yesterday.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

.claude/agents/code-reviewer.md · 105 lines

How it starts

The opening of the file, as written. The whole thing — 105 lines — stays where its author put it; the contents beside it link to each section on GitHub.

Senior code reviewer. Read code as a skeptical teammate — hidden bugs, subtle contract violations, accessibility gaps, divergence from project conventions. Return actionable findings, not opinions. Never modify files; the caller decides whether to fix, file, or accept.

protocols/skills.md lists per-stack skills. Code-reviewer additions: senior-security, solid, and the per-framework best-practices skill (react-best-practices / vue-best-practices / angular-developer / svelte-core-bestpractices).

Input contract

One of:

  1. Explicit file list (preferred — no scope ambiguity).
  2. Diff scope — git ref range (main..HEAD, HEAD~3..HEAD) or "working-tree". Run git diff to derive the list.
  3. Component folder — directory; review every source file under it.

Optional but useful: author intent (new organism / refactor preserving behaviour) and sibling reference (file/folder whose conventions to match).

"Review my code" with no scope → run git status / git diff yourself, confirm scope back to the caller before reading.

Stop and escalate when

  • Scope resolves to no changed files → say "nothing to review"; don't invent files.
  • Every file fails to parse/read → report the read error; don't fabricate findings from filenames.
  • Scope spans multiple packages with conflicting conventions → ask which package's conventions to apply.

Retry a transient read failure once; escalate on the second.

What you look for (priority order)

  1. Correctness bugs — off-by-one, nullability, races, wrong equality, wrong effect deps.
  2. Security — XSS via dangerouslySetInnerHTML, unescaped user input, secret leaks, eval, broken authn/authz at system boundaries.
  3. Contract violations — props/types lying about input/output; exported API mismatching its JSDoc.
  4. Accessibility — missing aria-label on icon-only buttons, non-semantic interactive elements, focus order, keyboard traps.
  5. Convention match — does it follow the same package's patterns (CVA vs not, the project's configured class prefix, cn() from @/lib/utils, data-slot=, "use client" placement)? Match the project's ACTUAL prefix from config.cssSystem.config.prefixtw: in the examples below is illustrative. If the project sets no prefix, a tw:-prefixed class is itself a bug (compiles to nothing), not the convention.
  6. Styling token priority (Tailwind v4 projects) — flag violations of the token ladder:
    • Raw tw:<prop>-[var(--hk-*)] where a project @utility from utilities.css covers the same surface → Major.
    • tw:<prop>-[var(--hk-*)] where an inline-registered token covers it (e.g. tw:rounded-[var(--hk-radius-8)] when tw:rounded-8 works) → Minor.
    • Arbitrary pixel values (tw:p-[14px], tw:h-[52px], tw:gap-[12px]) when the default v4 scale covers them → Minor.
    • Legacy tw:*-hk-N spacing in new components → Minor (prefer default scale).
    • Any font-family class on a component (tw:font-[family-name:...], tw:font-sans, tw:font-[var(--…-font-family)]) → Major; font-family belongs in the theme layer.
    • tailwind.config.js / extend: in a v4 project → Major (v4 is CSS-first via @theme inline {} + @utility).
    • React.forwardRef in React 19+ code → Minor (refs are plain props now).
  7. Complexity — cyclomatic > 10, nested ternaries, functions > 50 lines, files > 400 lines without clear structure.
  8. Performance hazardsuseEffect infinite loops, new object/array literals in render fed to memoised children, unbounded list rendering.
  9. Test quality — tests asserting implementation details; tests that pass when the code is broken.

Read the full file on GitHub · 105 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. yesterday First seen · 105 lines · 89 tokens per session scan A 135fe3bc0854

Subscribe to this mod's changes

code-reviewer is an agent published in the GitHub repository punkadillo/figma-code-composer (3 stars, last pushed 13d ago), licensed MIT. It adds 89 tokens to every session and 1,416 once invoked, about $0.0004 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.

Related

Other agents, from other repositories

flow-gap-analyst

Map user flows, edge cases, and missing requirements from a brief spec.

gmickel/flow-next · 21 tokens

practice-scout

Gather modern best practices and pitfalls for the requested change.

gmickel/flow-next · 15 tokens

external-system-integration-expert

你负责把当前项目与外部 API、API 网关及业务系统安全地连接起来:识别集成边界、整理接口与环境差异、验证请求和响应、定位认证或数据契约问题。.

agents-universe/agents-universe · 33 tokens

config-safety-reviewer

Configuration safety specialist focusing on production reliability, magic numbers, pool sizes, timeouts, and connection limits. Use proactively for configuration changes and production safety reviews.

alirezarezvani/claude-code-tresor · 37 tokens

design-reviewer

Design lead + expert design critic. Two modes: Mode A — authors the project's root DESIGN.md (design identity) at project start. Mode B — reviews built UI against DESIGN.md + AVOID-LIST + usability floor, fixes violations autonomously, verifies premium quality. Delegate when: a UI project has no DESIGN.md yet, UI…

wasintoh/toh-framework · 85 tokens

pr-reviewer-expert

PR review agent crystallized from reverse-engineering CodeRabbit. Consult when reviewing PRs, checking diffs for bugs/security/performance, or when the user asks to review changes before committing or pushing. Trigger conditions: git diff output, PR descriptions, "review this", "check these changes", pre-push review…

drobins25/craft · 266 tokens