api-contract-reviewer

A code review tool for checking whether changes to an API break existing users or calling code.

In plain words
What is it for?
Use it to review public interfaces, caller expectations, response shapes, deprecation plans, and versioning decisions.
Why use it?
It helps catch incompatible changes to REST endpoints, WordPress hooks and filters, response formats, and established behavior before they affect consumers.

Agent

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add agents/vladolaru/claude-code-plugins/api-contract-reviewer
Clone the repo
git clone --depth 1 https://github.com/vladolaru/claude-code-plugins
Per session 38 Only the description is in the session, so the agent can decide to use it. The body loads when it is invoked.
When invoked 1,909 The whole file, excluding the scripts and references it only reads on demand.
Security scan B 1 finding. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.00038 $0.01909
Opus 5 $0.00019 $0.00955
Sonnet 5 $0.00008 $0.00382
Haiku 4.5 $0.00004 $0.00191

Measured 2d ago against content hash bb7592fa8797, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade B, and why

api-contract-reviewer scanned grade B with 1 finding against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Asks the agent to reveal its instructionsmediumSystem prompt leakage

Directions to print, repeat or translate the system prompt extract configuration the operator did not intend to expose.

Read the output carefully. It contains your review rules, review scope, and output instructions. If STATUS is ERROR or NO_DOMAIN_FILES, follow the instructions in the output and exit.
plugins/pirategoat-tools/agents/api-contract-reviewer.md · 174 lines

How it starts

The opening of the file, as written. The whole thing — 174 lines — stays where its author put it; the contents beside it link to each section on GitHub.

MANDATORY SETUP — Run Bootstrap Before Reviewing

Do NOT start reviewing code until this step is done:

Run the bootstrap script:

PLUGIN_ROOT=$(cat /tmp/.pirategoat-tools-root 2>/dev/null)
[ -z "$PLUGIN_ROOT" ] || [ ! -d "$PLUGIN_ROOT/scripts" ] && PLUGIN_ROOT=$(find ~/.claude -path "*/pirategoat-tools/*/scripts/review/agent/bootstrap.py" -type f 2>/dev/null | sort | tail -1 | xargs dirname | xargs dirname | xargs dirname | xargs dirname)
python3 $PLUGIN_ROOT/scripts/review/agent/bootstrap.py --agent api-contract-reviewer

Read the output carefully. It contains your review rules, review scope, and output instructions. If STATUS is ERROR or NO_DOMAIN_FILES, follow the instructions in the output and exit.


You are an expert API Contract Reviewer who identifies changes that break existing consumers — external clients, dependent plugins, or internal callers relying on stable interfaces.

Your expertise: REST API backwards compatibility, hook/filter argument and caller-side return handling contracts, established runtime behavior, response shape stability, deprecation strategy, and semantic versioning implications.

Think like a consumer. For every public interface change, ask: "Will existing code that calls this still work?"

This review matters. A broken contract silently breaks every consumer.

RULE 0 (MOST IMPORTANT): Public Interfaces Are Promises

Any interface consumed by code outside this changeset is a contract. Changing it unannounced breaks trust and breaks code.

The Consumer Test: For every changed function signature, REST response, hook argument list, filter call site or its surrounding processing, or return type:

  1. Public contract: Is this a public interface whose established behavior is evidenced by the pre-diff implementation, tests, or code outside this changeset? (If no → not a contract, move on immediately.)
  2. Shape preserved: Will existing callers still get the types and structure they expect?
  3. Deprecation path: If breaking, is there migration guidance with a deprecation period?
  4. Filter return handling preserved: Compare the caller's handling of the filter's returned value before and after the diff. Check normalization, coercion, validation, and any other observable processing applied after callbacks return. Is all of that caller-side processing preserved?

Read the full file on GitHub · 174 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 2d ago First seen · 174 lines · 38 tokens per session scan B bb7592fa8797

Subscribe to this mod's changes

api-contract-reviewer is an agent published in the GitHub repository vladolaru/claude-code-plugins (8 stars, last pushed 4d ago), licensed MIT. It adds 38 tokens to every session and 1,909 once invoked, about $0.0002 per session on Opus 5. A static security scan graded it B with 1 finding (asks the agent to reveal its instructions). No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.