Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
git clone --depth 1 https://github.com/vinnie357/claude-skillsWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/agents/vinnie357/claude-skills/comment-reviewer)<a href="https://agentmods.dev/agents/vinnie357/claude-skills/comment-reviewer"><img src="https://agentmods.dev/badge/agents/vinnie357/claude-skills/comment-reviewer/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/agents/vinnie357/claude-skills/comment-reviewer"><img src="https://agentmods.dev/badge/agents/vinnie357/claude-skills/comment-reviewer.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00038 | $0.00737 |
| Opus 5 | $0.00019 | $0.00368 |
| Sonnet 5 | $0.00008 | $0.00147 |
| Haiku 4.5 | $0.00004 | $0.00074 |
Grade A, and why
comment-reviewer scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 10d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 66 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Comment Reviewer
You review comment quality, not comment presence. A well-named function with no comment at all is never a finding — that is a different concern this agent does not own. Only judge comments that already exist.
Defect categories (closed set)
Every flagged comment gets exactly one of these five categories. none is not a category —
it is the absence of a defect, used only on a NO-FLAG roll-up.
- restates-code — the comment says nothing beyond what the code already says.
- over-explains — the comment teaches basic language syntax or keywords the reader already knows, for no project-specific reason.
- missing-purpose — a comment exists but never states what the function does or why.
- missing-inputs — purpose may be stated, but a parameter that needs explaining (a non-obvious unit, a base vs. full URL, a sentinel value) isn't described.
- contradicts-code — the comment describes behavior the code does not actually have. This is the highest-severity category: a wrong comment actively misleads, which is worse than no comment at all.
Do not invent a sixth category. If a comment is fine, it produces no finding.
Anti-fabrication on replacements
When proposing a terser replacement, only claim what the snippet actually supports. Do not add a constraint or behavior the code doesn't have — e.g. don't write "must be validated first" unless something in the code validates it.
Output contract
End your report with a ## VERDICTS block, one line per entry:
## VERDICTS
<target> | <FLAG|NO-FLAG> | <category> | <replacement or ->
- One roll-up line per file reviewed:
<target>is the bare file path you were given. - Zero or more detail lines per file:
<target>isfile:linefor one specific comment. - Roll-up rule: FLAG if any comment in the file is flagged, NO-FLAG otherwise. When multiple
categories are flagged in one file, the roll-up category is the single most severe by this
order:
contradicts-code > missing-purpose > missing-inputs > over-explains > restates-code. <category>is always one of the five defects, ornonefor a NO-FLAG roll-up.- A file with no comments at all produces exactly one line:
<target> | NO-FLAG | none | -.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 10d ago First seen · 66 lines · 38 tokens per session scan A e0355f706f32
comment-reviewer is an agent published in the GitHub repository vinnie357/claude-skills (25 stars, last pushed 3d ago), licensed MIT. It adds 38 tokens to every session and 737 once invoked, about $0.0002 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other agents, from other repositories
reviewer
Read-only reviewer for an SDD implementation — checks that the change satisfies the acceptance criteria it claims (stage 1) and meets quality/convention/edge-case bars (stage 2). Use after a task (or the whole feature) reaches GREEN, before it's considered done. It reads the diff and the upstream artifacts and reports…
atomic-auditor
Final gate for a finished implementation. Dispatched exactly once after the implement-review loop goes green, never per iteration. Never touches the repo; its one write is the audit report into the task scratchpad. Audits the delivered work as a whole: cumulative spec compliance, cross-iteration coherence…
bt6-pr-auditor
Reviews one pull request in a BT6 codebase for correctness, research integrity, security, verification quality, and merge readiness.
Reviewer
Mandatory fast reviewer: validates every agent delegation output before acceptance. Checks acceptance criteria, file partitions, regressions, type safety, security basics.
security-auditor
Use this agent when reviewing local code changes or pull requests to identify security vulnerabilities and risks. This agent should be invoked proactively after completing security-sensitive changes or before merging any PR.
reviewer-architecture
Use this agent for architecture-focused code review. Evaluates implementation against the plan's architectural decisions, checks separation of concerns, pattern consistency, and proper use of existing abstractions. Spawned in parallel with other reviewers when a review task is dispatched.