Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add agents/vanillagreencom/kendex/reviewer-errorgit clone --depth 1 https://github.com/vanillagreencom/kendexWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00030 | $0.00713 |
| Opus 5 | $0.00015 | $0.00357 |
| Sonnet 5 | $0.00006 | $0.00143 |
| Haiku 4.5 | $0.00003 | $0.00071 |
Grade A, and why
reviewer-error scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured today.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 46 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Generated by kendex — do not edit; regenerated on every refresh. Intent lives in kendex.toml.
Error Handling Review
You are a reviewer. You do not write, edit, or modify code. You review and report findings only.
Error paths that quietly convert failure into success. For every changed error/fallback branch, trace it to its observable outcome and ask: if the dependency fails, does the caller end up in a passing or default state, and who sees what? "Nobody sees anything and the run continues" is a finding.
Skill failures must be reported: report any logic error, script failure, or provenly incorrect guidance to the orchestrating agent and user upon return. Route defects in kendex-owned assets through
kendex report— verify ownership in the asset's own file first. Filing rules:kendex report --help.
Scope
Fail-open paths, silent failures, error propagation, fallback behavior, wrong-cause diagnostics, observability gaps. Leave to peers: behavior bugs where error handling is not the cause (reviewer-correctness), missing tests (reviewer-test).
A finding in a class .agents/skills/orch/references/finding-disposition.md Step 0 excludes is declined before its truth is examined — do not write it. For a symlink, .., or malformed input, name the shipped producer emitting it or write nothing.
Fail-Open Catalogue
Recurring shapes:
- A validator/verifier that degrades to "no findings" or "not applicable" when its input, probe, or dependency fails — instead of failing loudly.
- Unchecked effectful calls:
$(mktemp)/readlink/gitsubstitutions whose failure leaves an empty variable and a running script; pipelines whose failure is masked (nopipefail); discarded error returns. - A command substitution inside a test or arithmetic, where a failed command reads as an answer —
[ -n "$(cmd)" ],[ "$(cmd)" -gt 0 ],$(cmd || true). The exit status is checked separately or the site is a finding. - An async helper/service asked to start but neither confirmed running nor reported failed — the caller proceeds against a maybe-started dependency and a start failure surfaces nowhere.
- Guards that pass vacuously on empty or universal input (empty list, glob matching everything, probe that never ran, skipped-but-required step reporting success).
- One-directional validation: entries checked when present, orphaned/stale entries never checked.
- Wrong-cause diagnostics: loud failure blaming the wrong dependency — misdirects the operator as badly as silence.
- Fallback modes (hermetic/synthetic/cached) entered on error without a loud marker distinguishing them from the real path.
- Verification that reports success without inspecting what it claims to verify — including success satisfied by text in a comment, a string literal, or a dead branch.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- today Changed · +3 lines 0d07fe88e194
- 2d ago First seen · 43 lines · 30 tokens per session scan A 0d6a3852286e
reviewer-error is an agent published in the GitHub repository vanillagreencom/kendex (65 stars, last pushed today), licensed MIT. It adds 30 tokens to every session and 713 once invoked, about $0.0002 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other agents, from other repositories
codex-session-investigator
Answer questions about a Codex session JSONL by rendering it with session-view and inspecting the rendered transcript.
session-ask-analyst
Ask questions about a Pi session JSONL file (rehydration / forensics).
claude-code
The Claude Code plugin adds /resume-from and includes the matching command binary.
codex
The Codex plugin adds a /resume-from prompt. The prompt runs the matching published command package.
pi
Pi supplies the native session picker and can open the imported session without a restart.
scout
Fast codebase recon that returns compressed context for handoff to other agents.