Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
git clone --depth 1 https://github.com/btspoony/mstar-harnessWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/commands/btspoony/mstar-harness/amazing-pr-review)<a href="https://agentmods.dev/commands/btspoony/mstar-harness/amazing-pr-review"><img src="https://agentmods.dev/badge/commands/btspoony/mstar-harness/amazing-pr-review/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/commands/btspoony/mstar-harness/amazing-pr-review"><img src="https://agentmods.dev/badge/commands/btspoony/mstar-harness/amazing-pr-review.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00100 | $0.01194 |
| Opus 5 | $0.00050 | $0.00597 |
| Sonnet 5 | $0.00020 | $0.00239 |
| Haiku 4.5 | $0.00010 | $0.00119 |
Grade A, and why
amazing-pr-review scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured today.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 35 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Deep PR Review
Run a read-only, evidence-first review of a PR / branch / diff and decide whether it is safe to ship. Output: one verdict — computed from the finding tally, never chosen(score_pct display-only)— plus findings presented to the user, and the posted GitHub Review URL when a PR number exists(posting is mandatory then). Never auto-approve, never REQUEST_CHANGES, never merge. Read-only advisory — does not enter the plan state machine.
Procedure SSOT → mstar-audit SKILL.md(common core)+ references/pr-review.md(pr variant 全量:tier 解析、三阶段流水线、worktree isolation、posting、report archive、batch). This command is a thin launcher — every contract lives in the reference.
Boot
mstar-harness-coremstar-audit→ SKILL.md +references/pr-review.mdmstar-coding-behavior(evidence discipline)mstar-branch-worktree(worktree isolation)mstar-host→ active host reference (invoke capability for parallel subagents)
Execute
Execute mstar-audit § pr variant end to end(references/pr-review.md):
- Tier first — resolve
quick/default/deepper § Review depth (tiers)(显式 token > too-large > 敏感面 > large > small 推断阶梯;两 token 同现 → hard-stop 请用户二选一)→ 按 tier seat 计划执行(quick 1 席 / default 2 席 / deep 三阶段)。- Budget — each tier's seat plan carries a wall-clock budget(§ Review depth (tiers) Budget 列;数字 SSOT = engine 常量表,per-seat caps 用
mstar pr-review budget打印); when it runs tight, degrade per § Time budget & degradation ladder and declare every degradation in the report- notes:.
- Budget — each tier's seat plan carries a wall-clock budget(§ Review depth (tiers) Budget 列;数字 SSOT = engine 常量表,per-seat caps 用
- Isolate — create the review worktree per § Worktree isolation(real base,never assume
main;empty changeset → stop;diff snapshot pinned at setup)→ fan out seats per § Review pipeline(deep:有 pinned diff pack 时 collect 波默认折入领域席位collectFolded,kept 例外与- notes:声明见 § Review pipeline;seats read-only,evidence/findings in result payload,never post;seat prompts get--diff-fileviamstar pr-review seat-prompt). Record the review start time at worktree-setup — theelapsedclock starts here(§ Local report archive frontmatter). - Synthesize (main agent) — dedupe + tiered three-way vet (full for must-fix/should-fix; evidence-verify for nits) → tally/verdict(§ Tally and derived score)→ persist the
mstar.review/v1envelope(mandatory)→ report + GitHub Review POST per § Comment posting(posted: yes/n/a-no-pr/failed;event fixedCOMMENT)→ save local report + evidence files per § Local report archive(all three posting branches;writeelapsedinto the report frontmatter — measured minutes since the step-2 worktree-setup start time)→ then worktree cleanup(mstar pr-review worktree-cleanup). - Batch — one session = one PR per § Batch sibling PRs;其余 PR →
mstar status backlog-register登记为 audit todos,建议各自独立 session.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- today Changed · +2 lines 8cb8d7d0b7cb
- 5d ago Changed · +1 lines 075486c768bd
- 8d ago Changed · -25 lines a293168d2b22
- 12d ago First seen · 57 lines · 100 tokens per session scan A 04ff4571d12f
amazing-pr-review is a command published in the GitHub repository btspoony/mstar-harness (57 stars, last pushed today), licensed MIT. It adds 100 tokens to every session and 1,194 once invoked, about $0.0005 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other commands, from other repositories
audit
You are a Principal Engineer & Product Architect conducting a full adversarial audit of this codebase. Your job is not to be polite. Your job is to find every structural, architectural, and experiential problem — then produce an actionable plan to fix them.
check-file
Perform comprehensive analysis of $ARGUMENTS to identify code quality issues, security vulnerabilities, and optimization opportunities.
refactor-code
Command "refactor-code" from centminmod/my-claude-code-setup, covering refactoring analysis command, your task, refactoring analysis framework, core principles (for analysis) and multi-agent analysis workflow.
harness-review
Review the current change set from an opposing harness-engineering perspective.
review-spec
A command that reviews a software specification for accuracy, internal quality, and readiness for implementation. A specification describes what a feature should do and provides the reference for building it.
book-style
A command for analysing how a novel is written, including its descriptions, actions, character thoughts, and dialogue.