Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
git clone --depth 1 https://github.com/bovinphang/frontend-craftWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/commands/bovinphang/frontend-craft/fec-review)<a href="https://agentmods.dev/commands/bovinphang/frontend-craft/fec-review"><img src="https://agentmods.dev/badge/commands/bovinphang/frontend-craft/fec-review/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/commands/bovinphang/frontend-craft/fec-review"><img src="https://agentmods.dev/badge/commands/bovinphang/frontend-craft/fec-review.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00031 | $0.00780 |
| Opus 5 | $0.00015 | $0.00390 |
| Sonnet 5 | $0.00006 | $0.00156 |
| Haiku 4.5 | $0.00003 | $0.00078 |
Grade A, and why
fec-review scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 10d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
What it actually says
Conduct a comprehensive review of the front-end code. Read the project status and diff first, and then output the findings with evidence; do not write guesses as blocking items. If you need to combine git diff, reduce noise output by severity level (CRITICAL→LOW), and explicitly give Approve/Warning/Block conclusions, you can entrust the fec-code-reviewer subagent to execute; if the changes are mainly .ts / .tsx / .js / .jsx and you need to run typecheck/eslint, PR merge readiness check and Special conclusions on TS/JS idioms can be delegated to typescript-reviewer (reported as typescript-review-*.md). Otherwise, continue to press this command and the fec-code-review Skill process.
Execution steps
-
Determine the scope of the review:
- If the user specifies a file path, review the specified file
- If the user does not specify a file, run
git diff --name-only HEADto get a list of recently changed files - If there is no git change record, prompt the user to specify the file or directory that needs to be reviewed
-
Filter to only keep front-end related files (
.ts,.tsx,.vue,.js,.jsx,.css,.scss,.less,.html) -
Use the review dimensions of
fec-code-reviewSkill to check item by item:- Architecture (component boundaries, separation of responsibilities)
- Type safety (any usage, props type)
- Rendering and status (repeated rendering, key stability)
- Style (Token usage, responsiveness)
- Tailwind / design system (token, variant, dark mode, dynamic class)
- Accessibility (semantics, ARIA, keyboard operation)
- Maintainability (file size, naming, repetitive logic)
- Testing (critical coverage, test patterns)
- Security (XSS, sensitive information, input validation)
- Performance (first screen dependencies, repeated requests, long tasks, large lists)
- Dependency upgrade (lockfile, peer dependency, CVE, major version migration verification)
Each question must include file location, impact, confidence level, and recommended verification method.
-
Output the review report in the following format:
# Code review report > Generation time: YYYY-MM-DD HH:mm > Review tool: frontend-craft **Review Scope**: N documents ## 🔴 Must be modified (N items) - **[File:line number]** Problem description → Suggested changes ## 🟡 Suggested optimizations (N items) - **[File:line number]** Problem description → Suggested modifications ## 🔵 Optional optimization items (N items) - **[File:line number]** Problem description ## 🟢 Things done well -... ## Risk Level: Low / Medium / High **Overall Rating**: Can be merged / merged after modification / needs to be refactored -
Use the Write tool to save the report content as a Markdown file:
- Directory:
reports/in the project root directory (create it if it does not exist) - Filename:
code-review-YYYY-MM-DD-HHmmss.md(use current timestamp) - Inform the user of the report file path after saving
- Directory:
-
If the user agrees to the modification, directly repair the items that can be automatically repaired in "Must Modify".
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 10d ago First seen · 66 lines · 31 tokens per session scan A 9120330dff1c
fec-review is a command published in the GitHub repository bovinphang/frontend-craft (21 stars, last pushed 8d ago), licensed MIT. It adds 31 tokens to every session and 780 once invoked, about $0.0002 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other commands, from other repositories
audit
Audit an existing codebase. Detects stack, finds gaps, creates tasks, generates PROJECT.md.
release
Release manager for frontend and mobile. Writes App Store notes, user-facing changelog, flags stale docs and landing copy. Actions: notes | changelog | docs | sync.
close-review
Month-end close / GL compliance check — invokes accounting-reviewer to produce TM-accounting-{slug}.md with double-entry integrity, ASC 606 revenue-recognition, period-lock, and SOX ITGC gaps.
voice-compliance
Voice/telephony compliance check — invokes voice-ai-reviewer to produce TM-voice-{slug}.md with TCPA, STIR/SHAKEN, state recording-consent, EU AI Act Art. 50, and synth-voice deepfake-law gaps.
dead-code-scan
Scan for dead code, unused imports, duplicates, and zombie code across the project.
rust-critique
Deep code critique — read the target Rust code and apply the full review process. Evaluates soundness, ownership, error handling, type design, async correctness, performance, and architecture. Think like a senior Rust engineer giving honest feedback.