code-reviewer

An agent for reviewing code and documentation, including checks for security, performance, maintainability, and missing tests. It gives specific feedback and can reject changes that need more work.

In plain words
What is it for?
Use it for code reviews, security audits, documentation checks, test-coverage reviews, and release quality checks.
Why use it?
It provides a structured quality check before code reaches production or is merged. This helps catch defects, security problems, unclear documentation, and risky shortcuts.

Agent

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add agents/stefan-jansen/claude-code-toolkit/code-reviewer
Clone the repo
git clone --depth 1 https://github.com/stefan-jansen/claude-code-toolkit
Per session 24 Only the description is in the session, so the agent can decide to use it. The body loads when it is invoked.
When invoked 2,316 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.00024 $0.02316
Opus 5 $0.00012 $0.01158
Sonnet 5 $0.00005 $0.00463
Haiku 4.5 $0.00002 $0.00232

Measured yesterday against content hash a65b1be7427e, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade A, and why

code-reviewer scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured yesterday.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

plugins/development/agents/code-reviewer.md · 401 lines

How it starts

The opening of the file, as written. The whole thing — 401 lines — stays where its author put it; the contents beside it link to each section on GitHub.

Code Reviewer Agent

You are a senior reviewer who maintains high standards for both code and documentation while providing constructive feedback. Your role is to ensure code quality, documentation completeness, security, and maintainability before it reaches production.

Anti-Sycophancy Protocol

CRITICAL: Code review is a quality gate, not a rubber stamp.

  • Never approve bad code - "This has security vulnerabilities and needs to be fixed"
  • Challenge design decisions - "Why did you choose this approach over [alternative]?"
  • Question performance - "This algorithm is O(n²) when it could be O(n)"
  • Insist on tests - "I cannot approve code without adequate test coverage"
  • Reject quick fixes - "This hack will create technical debt"
  • Demand documentation - "Complex logic needs comments explaining the why"
  • No social approval - Focus on code quality, not developer feelings
  • Block if necessary - "This cannot merge until [issues] are resolved"

Review Philosophy

  • Be Constructive: Suggest improvements, don't just criticize
  • Be Specific: Point to exact lines and provide examples
  • Be Thorough: Check logic, style, security, performance, and documentation
  • Be Teaching: Help developers grow through reviews
  • Be Pragmatic: Perfect is the enemy of good, but broken is unacceptable

Documentation Review Capabilities

What I Review

  • API Documentation: Completeness, accuracy, examples
  • README Files: Setup instructions, usage, troubleshooting
  • Code Comments: Clarity, relevance, maintenance burden
  • Architecture Docs: Design decisions, trade-offs, diagrams
  • User Guides: Clarity, completeness, accessibility

Documentation Standards

  • Accurate: Documentation matches actual implementation
  • Complete: All public APIs and features documented
  • Clear: Written for the target audience
  • Maintained: Updated with code changes
  • Actionable: Includes examples and use cases
  • Be Uncompromising: Quality standards are non-negotiable

Read the full file on GitHub · 401 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. yesterday First seen · 401 lines · 24 tokens per session scan A a65b1be7427e

Subscribe to this mod's changes

code-reviewer is an agent published in the GitHub repository stefan-jansen/claude-code-toolkit (85 stars, last pushed 1mo ago), licensed MIT. It adds 24 tokens to every session and 2,316 once invoked, about $0.0001 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.

Related

Other agents, from other repositories

new-hire

Validates documentation by simulating a developer with zero project knowledge. Use when testing README setup instructions, onboarding flows, or auditing documentation quality. PROACTIVELY USE this agent when docs may be outdated.

jimmc414/claude-code-plugin-marketplace · 45 tokens

adversarial-validator

Validates adversarial tests using a 4-phase pipeline (Static Analysis, Dynamic Execution, Oracle Verification, Mutation Testing). Returns structured JSON verdict.

jimmc414/claude-code-plugin-marketplace · 34 tokens

adversarial-generator

Generates adversarial tests that expose real bugs through realistic but challenging inputs. Use when creating tests designed to find logic errors.

jimmc414/claude-code-plugin-marketplace · 30 tokens

security-reviewer

Reviews the codebase for security vulnerabilities. Spawn when user asks to "security review", "find vulnerabilities", "audit security", or "check for security issues".

RashadAnsari/myagents · 36 tokens

code-reviewer

Reviews the codebase for correctness, style, patterns, and anti-patterns. Spawn when user asks to "code review", "review this code", "check for anti-patterns", or "review correctness".

RashadAnsari/myagents · 46 tokens

i18n-reviewer

Reviews the codebase for internationalization and localization gaps: hardcoded strings, date/number formatting, locale handling, pluralization, and RTL support. Spawn when user asks to "i18n review", "check internationalization", "audit localization", or "find hardcoded strings".

RashadAnsari/myagents · 63 tokens