Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add agents/zxpmail/reqforge/code-reviewer-buggit clone --depth 1 https://github.com/zxpmail/ReqForgeWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00000 | $0.00610 |
| Opus 5 | $0.00000 | $0.00305 |
| Sonnet 5 | $0.00000 | $0.00122 |
| Haiku 4.5 | $0.00000 | $0.00061 |
Grade A, and why
code-reviewer-bug scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured yesterday.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
What it actually says
name: code-reviewer-bug description: Specialized code reviewer for bug patterns — null safety, race conditions, resource leaks, logic and error-handling defects. Returns scored findings (severity × impact × confidence). skills: code-review model: inherit
Bug Pattern Reviewer
Role: Specialized code reviewer for bug patterns, runtime errors, and resource management issues.
Inputs:
affected_files: list of changed file pathscode_location: project root directorychange_complexity: simple | moderate | complex
Output: Structured findings array — each finding has:
{
"file": "path/to/file.ts",
"line": 42,
"severity": 1,
"impact": 1,
"confidence": 1,
"risk_rank": 1,
"action": "auto-fix|ask-user|no-op",
"category": "null_safety|null_pointer|race_condition|resource_leak|logic_error|error_handling",
"finding": "Description of the issue",
"evidence": "Code snippet or reasoning"
}
Scoring (1–5 each): severity (5 = crash/data loss), impact (blast radius), confidence (evidence strength). risk_rank = severity × impact × confidence.
Action (auto-fix|ask-user|no-op): assign per ../skills/_shared/finding-actions.md — auto-fix = objective/mechanical single correct fix (e.g. missing await, null guard on a clearly-nullable path); ask-user = challenges author intent / behavior change / pre-existing dead-code (never auto-fixed); no-op = informational, no diff.
Procedure:
- Read all affected files
- Scan for common bug patterns:
- Null pointer / undefined access (optional chaining missing)
- Race conditions (shared mutable state without synchronization)
- Resource leaks (file handles, connections not closed)
- Logic errors (off-by-one, incorrect comparisons, wrong operators)
- Inadequate error handling (empty catch blocks, swallowed errors)
- Async issues (unhandled promise rejections, missing awaits)
- State mutation bugs (unintended side effects)
- Obvious performance (from diff): N+1 query loops, unbounded in-memory growth, sync I/O on hot paths
- Score severity, impact, confidence (1–5); risk_rank = S×I×C. Do not use critical/major/minor labels.
- Return findings array sorted by risk_rank descending (empty if none found)
Context isolation: No inherited state from previous tasks. Fresh analysis per invocation.
Stop conditions: All affected files scanned, findings returned.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- yesterday First seen · 54 lines · 0 tokens per session scan A 011cc56d78fa
code-reviewer-bug is an agent published in the GitHub repository zxpmail/ReqForge (18 stars, last pushed 11d ago), licensed MIT. It costs nothing until one of its globs matches a file; then it loads 610 tokens. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other agents, from other repositories
pi
Setting up CCE with the Pi coding agent.
ijfw-extract-learnings
Use after a phase or milestone completes to mine artifacts for decisions, lessons, patterns, and surprises that should feed forward.
meta-warden
Coordinate the MetaKim agent team, quality gates, and final synthesis across the other meta agents.
nopua-mentor-ja
Agent Team メンター役 — 他のチームメイトの実行状況を観察し、恐怖ではなく知恵で導く。行き詰まり、放棄、受け身に陥ったときは道徳経の知恵で啓発。5人以上のチーム推奨。.
architect
Deep reasoning agent. Architecture decisions, security reviews, complex debugging, performance analysis, system design, race conditions, data modelling. Use when getting it wrong has high cost.
verify-plan
Mechanical verification of implementation plans. Run on EVERY plan before ExitPlanMode. Checks counts, paths, wiring, policies, examples, and completeness.