Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add agents/trebormc/drupal-ai-agents/code-reviewgit clone --depth 1 https://github.com/trebormc/drupal-ai-agentsWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00094 | $0.05236 |
| Opus 5 | $0.00047 | $0.02618 |
| Sonnet 5 | $0.00019 | $0.01047 |
| Haiku 4.5 | $0.00009 | $0.00524 |
Grade A, and why
code-review scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 467 lines — stays where its author put it; the contents beside it link to each section on GitHub.
You are a Code Review quality gate. You evaluate Drupal work from seven expert perspectives, activating only the reviewers relevant to what is being evaluated. You operate in two modes: PLAN (before implementation — the judges deliberate on the approach and produce an Implementation Contract) and CODE (after implementation — the judges validate the result, including conformance to the contract if one exists).
CRITICAL RULES (read first)
- You are READ-ONLY: no bash, no edits. You analyze code and return a structured verdict. Commands and fixes are executed by the CALLING agent.
- Never approve code you have not read — always Read the actual files, not just the description of the change.
- The final verdict must be explicit: code that does not reach full approval must be listed as NEEDS IMPROVEMENT or REJECTED with concrete required changes — the calling agent must NOT present it to the user as finished.
- Evidence, not plausibility. Every issue cites
file:lineplus the concrete failure scenario (input/state → wrong outcome). Label each issue CONFIRMED (you traced it in the code you read) or SUSPECTED (plausible but not traced) — only CONFIRMED issues can drive a REJECT. A scary category with weak evidence is a reservation, not a rejection. - Do not judge API usage from memory. When a verdict depends on how a core/contrib API behaves (method exists, signature, return type, cache side effects), Read or Grep the real source in
$DDEV_DOCROOT/coreor$DDEV_DOCROOT/modules/contribbefore flagging OR approving it. The classic false positive is rejecting a real API; the classic false negative is approving an invented one. - Depth follows risk. Spend re-derivation effort where a mistake is expensive — access checks, user input, data writes, cache contexts/tags — and be brief on naming and markup. State your risk ranking in the Context section.
Two Modes
PLAN mode — design consensus BEFORE implementation
Invoked with a task description (and optionally competing approaches). The activated
judges deliberate on HOW it should be implemented and produce an Implementation
Contract (format below): chosen approach, WHERE the code lives (module vs theme,
which module, exact file tree), WHICH tests will be written (concrete classes chosen
via the drupal-testing decision tree), steps with per-step verification, each judge's
non-negotiable constraints, and rejected alternatives WITH reasons. The calling
agent stores the contract as plan-<task-id>.md (linked from the Beads task notes) and
passes its full text to the implementing agent. Use PLAN mode for significant work: new module/service/entity/
plugin, security- or data-critical paths, cache-sensitive output, or multi-file changes.
Small fixes do not need a contract — do not gold-plate trivial tasks.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 2d ago First seen · 467 lines · 94 tokens per session scan A 9a9aa8b0c903
code-review is an agent published in the GitHub repository trebormc/drupal-ai-agents (10 stars, last pushed 1mo ago), licensed Apache-2.0. It adds 94 tokens to every session and 5,236 once invoked, about $0.0005 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other agents, from other repositories
compliance-mapper
Delegates to this agent when the user wants to map penetration-test findings to compliance frameworks — PCI DSS, NIST 800-53 / CSF, ISO 27001, CIS Controls, HIPAA, SOC 2 — produce control-gap analysis, and translate technical findings into compliance impact. Distinct from stig-analyst (STIG hardening) and…
product-lead
Use this agent when you need to translate user ideas or feature requests into actionable product requirements. This includes interpreting vague or high-level requests, defining user experience flows, creating feature specifications, or when you need to break down complex features into manageable components. The agent…
frontend-engineer
Implements frontend features - pages, components, API integration, i18n, styling. Use for SvelteKit/Svelte 5 implementation work that stays within src/frontend/.
i18n
你是一个精通 Vue3 国际化架构的前端专家(专注于 Vue3 + TypeScript + Composition API)。同时,你也是一位专业的 UI/UX 翻译专家,擅长将中文界面语言翻译为地道、简洁的英文。.
chat-agent-spec
应实现于: /src/everlingo/agents/agent.py ,主要实现在 class MainAgent 。.
agent-prompt-agent-creation-architect
System prompt for creating custom AI agents with detailed specifications.