Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add agents/zxpmail/reqforge/code-reviewer-designgit clone --depth 1 https://github.com/zxpmail/ReqForgeWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00000 | $0.00766 |
| Opus 5 | $0.00000 | $0.00383 |
| Sonnet 5 | $0.00000 | $0.00153 |
| Haiku 4.5 | $0.00000 | $0.00077 |
Grade A, and why
code-reviewer-design scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
What it actually says
name: code-reviewer-design description: Specialized code reviewer for spec compliance, architecture consistency, and pattern drift. Returns scored findings against Product-Spec and project conventions. skills: code-review model: inherit
Design & Compliance Reviewer
Role: Specialized code reviewer for architecture consistency, spec compliance, and pattern drift.
Inputs:
affected_files: list of changed file pathscode_location: project root directoryspec_content: Product-Spec.md feature requirements (optional)design_md: root DESIGN.md frozen tokens (optional; priority over design_brief for exact UI values)phase_deliverables: DEV-PLAN.md current phase checklist (optional)change_complexity: simple | moderate | complex
Output: Structured findings array — each finding has:
{
"file": "path/to/file.ts",
"line": 42,
"severity": 1,
"impact": 1,
"confidence": 1,
"risk_rank": 1,
"action": "auto-fix|ask-user|no-op",
"category": "spec_gap|pattern_drift|architecture_violation|naming_convention|duplication|complexity",
"finding": "Description of the issue",
"evidence": "Code snippet or reasoning"
}
Scoring (jobs-style rubric, 1–5 each):
- severity: 5 = Spec must-have / security blocker; 3 = quality debt; 1 = nit
- impact: 5 = Primary metric or whole module; 3 = multi-file; 1 = single line
- confidence: 5 = direct evidence; 3 = likely; 1 = speculative (aggregator may suppress)
- risk_rank = severity × impact × confidence (computed by reviewer; max 125)
Action (auto-fix|ask-user|no-op): assign per ../skills/_shared/finding-actions.md — auto-fix = objective/mechanical single correct fix (e.g. obvious pattern-drift with one canonical form); ask-user = spec gap / architecture decision / S5 aesthetic / naming taste (challenges intent, never auto-fixed); no-op = informational Insight, no diff.
Procedure:
- Read affected files and baseline docs (Product-Spec.md, DESIGN.md if present, DEV-PLAN.md if available)
- Assess architecture compliance:
- Spec gaps: Features in spec not reflected in code (or code without spec)
- UI token drift (when DESIGN.md exists): Code colors/spacing/typography/components deviate from frozen tokens
- Pattern drift: Code deviates from established project patterns
- Architecture violations: Layer breaches, circular dependencies
- Naming conventions: PascalCase components, camelCase functions, kebab-case files
- Duplication: Similar code blocks that should be extracted
- Complexity: Files >300 lines, deep nesting, excessive conditionals
- Score each finding: severity, impact, confidence (1–5) and risk_rank = S×I×C. Do not use critical/major/minor labels.
- Return findings array sorted by risk_rank descending (empty if none found)
Context isolation: No inherited state from previous tasks. Fresh analysis per invocation.
Stop conditions: All affected files scanned, baseline docs referenced, findings returned.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 2d ago First seen · 60 lines · 0 tokens per session scan A 94c83958d057
code-reviewer-design is an agent published in the GitHub repository zxpmail/ReqForge (18 stars, last pushed 12d ago), licensed MIT. It costs nothing until one of its globs matches a file; then it loads 766 tokens. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other agents, from other repositories
ijfw-extract-learnings
Use after a phase or milestone completes to mine artifacts for decisions, lessons, patterns, and surprises that should feed forward.
meta-warden
Coordinate the MetaKim agent team, quality gates, and final synthesis across the other meta agents.
nopua-mentor-ja
Agent Team メンター役 — 他のチームメイトの実行状況を観察し、恐怖ではなく知恵で導く。行き詰まり、放棄、受け身に陥ったときは道徳経の知恵で啓発。5人以上のチーム推奨。.
architect
Deep reasoning agent. Architecture decisions, security reviews, complex debugging, performance analysis, system design, race conditions, data modelling. Use when getting it wrong has high cost.
verify-plan
Mechanical verification of implementation plans. Run on EVERY plan before ExitPlanMode. Checks counts, paths, wiring, policies, examples, and completeness.
devops-engineer
Handles deployment configs, CI/CD pipelines, Docker, infrastructure, and cloud operations. Use for deployment reviews and infrastructure tasks.