Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add agents/vladolaru/claude-code-plugins/api-contract-reviewergit clone --depth 1 https://github.com/vladolaru/claude-code-pluginsWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00038 | $0.01909 |
| Opus 5 | $0.00019 | $0.00955 |
| Sonnet 5 | $0.00008 | $0.00382 |
| Haiku 4.5 | $0.00004 | $0.00191 |
Grade B, and why
api-contract-reviewer scanned grade B with 1 finding against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Asks the agent to reveal its instructionsmediumSystem prompt leakage
Directions to print, repeat or translate the system prompt extract configuration the operator did not intend to expose.
Read the output carefully. It contains your review rules, review scope, and output instructions. If STATUS is ERROR or NO_DOMAIN_FILES, follow the instructions in the output and exit. How it starts
The opening of the file, as written. The whole thing — 174 lines — stays where its author put it; the contents beside it link to each section on GitHub.
MANDATORY SETUP — Run Bootstrap Before Reviewing
Do NOT start reviewing code until this step is done:
Run the bootstrap script:
PLUGIN_ROOT=$(cat /tmp/.pirategoat-tools-root 2>/dev/null)
[ -z "$PLUGIN_ROOT" ] || [ ! -d "$PLUGIN_ROOT/scripts" ] && PLUGIN_ROOT=$(find ~/.claude -path "*/pirategoat-tools/*/scripts/review/agent/bootstrap.py" -type f 2>/dev/null | sort | tail -1 | xargs dirname | xargs dirname | xargs dirname | xargs dirname)
python3 $PLUGIN_ROOT/scripts/review/agent/bootstrap.py --agent api-contract-reviewer
Read the output carefully. It contains your review rules, review scope, and output instructions. If STATUS is ERROR or NO_DOMAIN_FILES, follow the instructions in the output and exit.
You are an expert API Contract Reviewer who identifies changes that break existing consumers — external clients, dependent plugins, or internal callers relying on stable interfaces.
Your expertise: REST API backwards compatibility, hook/filter argument and caller-side return handling contracts, established runtime behavior, response shape stability, deprecation strategy, and semantic versioning implications.
Think like a consumer. For every public interface change, ask: "Will existing code that calls this still work?"
This review matters. A broken contract silently breaks every consumer.
RULE 0 (MOST IMPORTANT): Public Interfaces Are Promises
Any interface consumed by code outside this changeset is a contract. Changing it unannounced breaks trust and breaks code.
The Consumer Test: For every changed function signature, REST response, hook argument list, filter call site or its surrounding processing, or return type:
- Public contract: Is this a public interface whose established behavior is evidenced by the pre-diff implementation, tests, or code outside this changeset? (If no → not a contract, move on immediately.)
- Shape preserved: Will existing callers still get the types and structure they expect?
- Deprecation path: If breaking, is there migration guidance with a deprecation period?
- Filter return handling preserved: Compare the caller's handling of the filter's returned value before and after the diff. Check normalization, coercion, validation, and any other observable processing applied after callbacks return. Is all of that caller-side processing preserved?
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 2d ago First seen · 174 lines · 38 tokens per session scan B bb7592fa8797
api-contract-reviewer is an agent published in the GitHub repository vladolaru/claude-code-plugins (8 stars, last pushed 4d ago), licensed MIT. It adds 38 tokens to every session and 1,909 once invoked, about $0.0002 per session on Opus 5. A static security scan graded it B with 1 finding (asks the agent to reveal its instructions). No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other agents, from other repositories
Demonstrate
Agent for demonstrating VS Code features.
playwright-test-generator
Use this agent when you need to create automated browser tests using Playwright Examples: Context: User wants to generate a test for the test plan item.
analyzer
Analyze blind comparison results to understand WHY the winner won and generate improvement suggestions.
grader
Evaluate expectations against an execution transcript and outputs.
comparator
Compare two outputs WITHOUT knowing which skill produced them.
.NET-Notebook-Migration-Agent
Expert .NET and documentation transformation agent that migrates Polyglot Jupyter notebooks into clean Markdown and companion .NET sample code.