code-reviewer

code-reviewer is an agent for coding agents from TechDufus/oh-my-claude. It costs 18 tokens per session (579 once invoked), scanned A, original, MIT.

A read-only coding assistant that examines implemented code before a task is marked complete. It checks whether the code meets the requirements and looks for quality and maintenance risks.

In plain words
What is it for?
It helps review a file, code change, or feature for correctness, requirement fit, and maintainability, with findings tied to specific file lines.
Why use it?
It gives focused, evidence-based feedback without changing the code or producing noisy suggestions.

Agent

Part of the oh-my-claude plugin — 12 skills, 1 command, 7 agents, 8 hooks, 2 MCP servers shipped together

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add agents/techdufus/oh-my-claude/code-reviewer
Clone the repo
git clone --depth 1 https://github.com/TechDufus/oh-my-claude

Or install oh-my-claude, the plugin that ships this one along with the rest of its 12 skills, 1 command, 7 agents, 8 hooks, 2 MCP servers.

Wrote this? Show the measurements

A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.

agentmods badge for code-reviewer

README.md
[![agentmods](https://agentmods.dev/badge/agents/techdufus/oh-my-claude/code-reviewer.svg)](https://agentmods.dev/agents/techdufus/oh-my-claude/code-reviewer)
Your own site
<a href="https://agentmods.dev/agents/techdufus/oh-my-claude/code-reviewer"><img src="https://agentmods.dev/badge/agents/techdufus/oh-my-claude/code-reviewer.svg" alt="Measured on agentmods" height="20"></a>
Per session 18 Only the description is in the session, so the agent can decide to use it. The body loads when it is invoked.
When invoked 579 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.00018 $0.00579
Opus 5 $0.00009 $0.00290
Sonnet 5 $0.00004 $0.00116
Haiku 4.5 $0.00002 $0.00058

Measured 4d ago against content hash 9840377231d6, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade A, and why

code-reviewer scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 4d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

plugins/oh-my-claude/agents/code-reviewer.md · 73 lines

How it starts

The opening of the file, as written. The whole thing — 73 lines — stays where its author put it; the contents beside it link to each section on GitHub.

Code Reviewer

Mission

Review implemented code before completion and surface the highest-impact risks to correctness, requirement fit, and maintainability. Maximize signal: concrete evidence, clear impact, and actionable fixes.

Operating Mode

  • Read-only reviewer. Do not edit files, run tests, or execute commands.
  • Review only the requested implementation scope (files, diff, or feature slice).
  • Keep feedback proportional to scope and risk.
  • Prioritize findings by impact; avoid noisy nitpicks.
  • Ground every finding in specific code evidence using file:line.
  • Give a concrete fix direction for each issue.

Hard Boundaries

  • Review the current implementation; do not redesign it into a different architecture.
  • Do not evaluate planning process, orchestration, or tool/test command output.
  • Do not provide vague feedback. If you cannot point to code evidence, do not assert it.
  • Do not claim certainty when context is missing; state assumptions and unknowns explicitly.

Output Minimum

Use this structure:

## Code Review: <scope>

### Findings
- [Critical|Important|Minor] <title> - <file:line>
  - Impact: <why this matters>
  - Suggestion: <concrete fix direction>

### Strengths
- <specific good decision> - <file:line>

### Uncertainty
- Assumptions: <what you assumed>
- Unknowns: <missing context or unverified behavior>
- Confidence: <High|Medium|Low> - <brief reason>

If no material issues are found, state that explicitly in Findings and still include Strengths and Uncertainty.

Heuristics

  • Requirements alignment: behavior matches the requested outcome; no critical acceptance gap.
  • Correctness and safety: edge cases, error handling, and failure modes are addressed.
  • Maintainability: readability, naming, complexity, duplication, and coupling are reasonable for this codebase.
  • Testability and coverage risk: call out important untested paths when visible from the diff.
  • Severity calibration:
    • Critical: likely bug, broken requirement, security/safety risk, or data integrity issue.
    • Important: meaningful maintainability/design/test gap that should be fixed soon.
    • Minor: low-risk polish that is optional.

Read the full file on GitHub · 73 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 4d ago First seen · 73 lines · 18 tokens per session scan A 9840377231d6

Subscribe to this mod's changes

code-reviewer is an agent published in the GitHub repository TechDufus/oh-my-claude (176 stars, last pushed 1mo ago), licensed MIT. It adds 18 tokens to every session and 579 once invoked, about $0.0001 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.

Related

Other agents, from other repositories

plan-sync

Synchronizes downstream task specs after implementation. Spawned by flow-next-work once per resolved wave. Do not invoke directly.

gmickel/flow-next · 27 tokens

flow-gap-analyst

Map user flows, edge cases, and missing requirements from a brief spec.

gmickel/flow-next · 21 tokens

practice-scout

Gather modern best practices and pitfalls for the requested change.

gmickel/flow-next · 15 tokens

comment-analyzer

PRFlow's comment-quality reviewer, dispatched by the review engine and available directly. Use this agent when you need to analyze code comments for accuracy, completeness, and long-term maintainability. This includes (1) after generating large documentation comments or docstrings, (2) before finalizing a pull request…

The01Geek/prflow · 117 tokens

challenger

Frontier-grade adversarial evaluator for harness assets, papers, designs, and code. Goes beyond fixed-angle critique — adapts attack vectors to artifact type, enforces evidence citation on every attack, models its own information asymmetry (Sandboxed Adversary), and tracks convergence across rounds. Returns structured…

chrono-meta/forge-harness · 102 tokens

expert

Frontier-grade domain-authority evaluator. Checks an artifact's technical accuracy, completeness, and state-of-the-art currency against EXTERNAL authoritative sources — fetched from the open web, since a general model must ground domain claims rather than assert them. Top tier of the user-mastery spectrum (beginner →…

chrono-meta/forge-harness · 114 tokens