Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add commands/bookedsolidtech/helixir/review-prgit clone --depth 1 https://github.com/bookedsolidtech/helixirWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/commands/bookedsolidtech/helixir/review-pr)<a href="https://agentmods.dev/commands/bookedsolidtech/helixir/review-pr"><img src="https://agentmods.dev/badge/commands/bookedsolidtech/helixir/review-pr.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00000 | $0.01529 |
| Opus 5 | $0.00000 | $0.00764 |
| Sonnet 5 | $0.00000 | $0.00306 |
| Haiku 4.5 | $0.00000 | $0.00153 |
Grade A, and why
review-pr scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 3d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 198 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Fetch a pull request diff, run code-reviewer analysis, translate findings to owner voice, and post a single batched inline GitHub review.
Usage
/review-pr <PR#> [--tier standard|senior|chief] [--task T-NNN]
Arguments:
<PR#>— pull request number (required)--tier— review depth:standard(default),senior, orchief--task— optional JSONL task ID to markcompletedafter the review posts (e.g.--task T-047)
Step 1 — Check prerequisites
Before anything else:
- Read
.rea/policy.yaml— confirm autonomy level is L1 or higher - Check for
.rea/HALT— if present, stop immediately - Verify
ghCLI is available:gh --version - Confirm caller is in a git repo with a GitHub remote:
gh repo view --json nameWithOwner
Extract owner/repo for use in API calls.
Step 2 — Fetch PR context
Run these in parallel:
gh pr view <PR#> --json title,body,headRefName,baseRefName,state,commits
gh pr diff <PR#>
gh pr view <PR#> --json commits --jq '.commits[-1].oid'
Store:
COMMIT_SHA— the latest commit OID (use in the review payload)PR_TITLE— for contextPR_DIFF— the full diff text (pass to code-reviewer)
If the PR is merged or closed, warn the user: "PR #N is already closed — review will post but won't block a merge."
If gh pr diff returns an empty diff, stop and report: "Empty diff — nothing to review."
Step 3 — Run code-reviewer analysis
Invoke the code-reviewer agent with the diff and the specified tier.
Pass this context to code-reviewer:
Tier: <standard|senior|chief>
Review the following git diff and produce structured findings as a JSON array.
Each finding must include:
- file: string (file path from diff header)
- line: number (line number in the NEW file)
- start_line?: number (for multi-line spans, the start line)
- severity: "high" | "medium" | "low"
- issue: string (the specific problem — no hedging)
- suggestion_code?: string (the corrected code, if applicable)
Output ONLY the JSON array. No prose. No markdown wrapper. Example:
[
{
"file": "src/gateway/middleware/chain.ts",
"line": 42,
"severity": "high",
"issue": "Non-null assertion will throw if upstream returns undefined",
"suggestion_code": "const result = upstream ?? defaultValue;"
}
]
If there are no findings, output: []
DIFF:
<paste full diff here>
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 3d ago First seen · 198 lines · 0 tokens per session scan A abd5c25bd741
review-pr is a command published in the GitHub repository bookedsolidtech/helixir (5 stars, last pushed 2mo ago), licensed MIT. It costs nothing until one of its globs matches a file; then it loads 1,529 tokens. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other commands, from other repositories
ijfw-audit
Run the IJFW audit gate for the current workflow phase. Usage: /ijfw-audit [phase name].
core-review
Review code changes against SpecOps project-specific patterns. Catches recurring failure modes from real PRs — tool abstraction violations, generated file drift, cross-platform gaps, variable inconsistencies, and more. Complements full-review-gate (generic quality) and pr-fix (applying bot comments).
ship-pr
Commit all changes to a new branch, push, and open a PR for review. The original branch stays clean.
_registry-protocol
This protocol is MANDATORY for ALL commands, agents, and phases.
coograph-verify
Verify that the described work is complete and correct. Provide evidence for every claim. You verify — you do not implement or fix style.
ship
Pre-release gate — run the full gate, responsive + render checks, then produce the release checklist (README badge/current/changelog). Use before tagging a release.