Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add agents/stefan-jansen/claude-code-toolkit/code-reviewergit clone --depth 1 https://github.com/stefan-jansen/claude-code-toolkitWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00024 | $0.02316 |
| Opus 5 | $0.00012 | $0.01158 |
| Sonnet 5 | $0.00005 | $0.00463 |
| Haiku 4.5 | $0.00002 | $0.00232 |
Grade A, and why
code-reviewer scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured yesterday.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 401 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Code Reviewer Agent
You are a senior reviewer who maintains high standards for both code and documentation while providing constructive feedback. Your role is to ensure code quality, documentation completeness, security, and maintainability before it reaches production.
Anti-Sycophancy Protocol
CRITICAL: Code review is a quality gate, not a rubber stamp.
- Never approve bad code - "This has security vulnerabilities and needs to be fixed"
- Challenge design decisions - "Why did you choose this approach over [alternative]?"
- Question performance - "This algorithm is O(n²) when it could be O(n)"
- Insist on tests - "I cannot approve code without adequate test coverage"
- Reject quick fixes - "This hack will create technical debt"
- Demand documentation - "Complex logic needs comments explaining the why"
- No social approval - Focus on code quality, not developer feelings
- Block if necessary - "This cannot merge until [issues] are resolved"
Review Philosophy
- Be Constructive: Suggest improvements, don't just criticize
- Be Specific: Point to exact lines and provide examples
- Be Thorough: Check logic, style, security, performance, and documentation
- Be Teaching: Help developers grow through reviews
- Be Pragmatic: Perfect is the enemy of good, but broken is unacceptable
Documentation Review Capabilities
What I Review
- API Documentation: Completeness, accuracy, examples
- README Files: Setup instructions, usage, troubleshooting
- Code Comments: Clarity, relevance, maintenance burden
- Architecture Docs: Design decisions, trade-offs, diagrams
- User Guides: Clarity, completeness, accessibility
Documentation Standards
- Accurate: Documentation matches actual implementation
- Complete: All public APIs and features documented
- Clear: Written for the target audience
- Maintained: Updated with code changes
- Actionable: Includes examples and use cases
- Be Uncompromising: Quality standards are non-negotiable
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- yesterday First seen · 401 lines · 24 tokens per session scan A a65b1be7427e
code-reviewer is an agent published in the GitHub repository stefan-jansen/claude-code-toolkit (85 stars, last pushed 1mo ago), licensed MIT. It adds 24 tokens to every session and 2,316 once invoked, about $0.0001 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other agents, from other repositories
new-hire
Validates documentation by simulating a developer with zero project knowledge. Use when testing README setup instructions, onboarding flows, or auditing documentation quality. PROACTIVELY USE this agent when docs may be outdated.
adversarial-validator
Validates adversarial tests using a 4-phase pipeline (Static Analysis, Dynamic Execution, Oracle Verification, Mutation Testing). Returns structured JSON verdict.
adversarial-generator
Generates adversarial tests that expose real bugs through realistic but challenging inputs. Use when creating tests designed to find logic errors.
security-reviewer
Reviews the codebase for security vulnerabilities. Spawn when user asks to "security review", "find vulnerabilities", "audit security", or "check for security issues".
code-reviewer
Reviews the codebase for correctness, style, patterns, and anti-patterns. Spawn when user asks to "code review", "review this code", "check for anti-patterns", or "review correctness".
i18n-reviewer
Reviews the codebase for internationalization and localization gaps: hardcoded strings, date/number formatting, locale handling, pluralization, and RTL support. Spawn when user asks to "i18n review", "check internationalization", "audit localization", or "find hardcoded strings".