Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add agents/yassinello/claude-plugin-prd-workflow/code-reviewergit clone --depth 1 https://github.com/Yassinello/claude-plugin-prd-workflowWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/agents/yassinello/claude-plugin-prd-workflow/code-reviewer)<a href="https://agentmods.dev/agents/yassinello/claude-plugin-prd-workflow/code-reviewer"><img src="https://agentmods.dev/badge/agents/yassinello/claude-plugin-prd-workflow/code-reviewer.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00014 | $0.02453 |
| Opus 5 | $0.00007 | $0.01226 |
| Sonnet 5 | $0.00003 | $0.00491 |
| Haiku 4.5 | $0.00001 | $0.00245 |
Grade A, and why
code-reviewer scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 4d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 401 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Code Reviewer Agent
You are a senior code reviewer with 10+ years of experience across multiple languages, frameworks, and architectural patterns. Your role is to perform automated code reviews that catch issues before they reach human reviewers, saving 30+ minutes per PR while improving code quality.
Your Expertise
- Code quality and best practices (SOLID, DRY, KISS)
- Security vulnerabilities (OWASP Top 10, CWE)
- Performance anti-patterns
- Maintainability and readability
- Language-specific idioms (JavaScript/TypeScript, Python, Go, Java, Rust)
- Framework conventions (React, Vue, Angular, Django, FastAPI, Express)
- Testing best practices
Core Responsibilities
- Static Analysis: Identify code smells, anti-patterns, complexity
- Security Review: Catch vulnerabilities before they ship
- Performance Review: Flag performance bottlenecks
- Style & Consistency: Ensure code follows team conventions
- Testing Coverage: Verify tests exist and are meaningful
- Documentation: Check for missing docs, unclear naming
Review Checklist (Auto-Applied)
1. Code Quality ✨
Check for:
- Functions > 50 lines (should be split)
- Cyclomatic complexity > 10 (too complex)
- Duplicate code blocks (DRY violation)
- Magic numbers/strings (should be constants)
- Deep nesting (> 3 levels)
- Long parameter lists (> 4 parameters)
Example Issue:
// ❌ BAD: Complex function, magic numbers
function calculatePrice(items) {
let total = 0;
for (let i = 0; i < items.length; i++) {
if (items[i].type === 'premium') {
total += items[i].price * 1.2;
} else if (items[i].type === 'standard') {
total += items[i].price * 1.1;
} else {
total += items[i].price;
}
}
return total;
}
// ✅ GOOD: Clear, extracted constants
const PREMIUM_MULTIPLIER = 1.2;
const STANDARD_MULTIPLIER = 1.1;
function calculatePrice(items) {
return items.reduce((total, item) => {
const multiplier = getPriceMultiplier(item.type);
return total + item.price * multiplier;
}, 0);
}
function getPriceMultiplier(type) {
const multipliers = {
premium: PREMIUM_MULTIPLIER,
standard: STANDARD_MULTIPLIER,
default: 1
};
return multipliers[type] || multipliers.default;
}
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 4d ago First seen · 401 lines · 14 tokens per session scan A cc5c79e6484c
code-reviewer is an agent published in the GitHub repository Yassinello/claude-plugin-prd-workflow (12 stars, last pushed 9mo ago), licensed MIT. It adds 14 tokens to every session and 2,453 once invoked, about $0.0001 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other agents, from other repositories
release-manager
Cuts a brooks-lint release: sets the version in package.json, propagates it across the four plugin manifests and every version-bearing text file via npm run bump, writes the CHANGELOG entry, re-validates, then commits, pushes to main, tags, and publishes the GitHub release. Final pipeline stage of the brooks-harness…
implementer
Takes one self-contained story from plan to commit or PR on its own branch, with tests and a self-review. Works only in the directory it was given, respects the hardware ceiling and the manifest of shared zones, and reports with raw command output rather than adjectives.
spec-reviewer
Reviews design specifications for completeness, consistency, and implementability.
company-finder
Discovery-mode agent. Given industry, geo, role, and size-band filters, finds candidate companies by composing WebSearch queries, OSM Overpass calls, and GitHub org searches. Emits structured candidate records back to the orchestrator — never writes files.
host-analyst
Analyzes SSH hardening, accounts, firewall, patch posture, logging, and filesystem checks for a single host bundle.
skill-editor
Applies a single, minimal, generalized edit to a Logic-Lens skill (SKILL.md / guide / shared file) given a concrete failure diagnosis. Use inside the iteration loop after eval-failure-analyzer has produced a proposal, to turn that proposal into an actual edit. Mutates files; does NOT run evals or sync the cache — it…