Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
git clone --depth 1 https://github.com/carloshpdoc/ios-workflow-claudeWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/commands/carloshpdoc/ios-workflow-claude/review-pr)<a href="https://agentmods.dev/commands/carloshpdoc/ios-workflow-claude/review-pr"><img src="https://agentmods.dev/badge/commands/carloshpdoc/ios-workflow-claude/review-pr/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/commands/carloshpdoc/ios-workflow-claude/review-pr"><img src="https://agentmods.dev/badge/commands/carloshpdoc/ios-workflow-claude/review-pr.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00000 | $0.01170 |
| Opus 5 | $0.00000 | $0.00585 |
| Sonnet 5 | $0.00000 | $0.00234 |
| Haiku 4.5 | $0.00000 | $0.00117 |
Grade A, and why
review-pr scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 9d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 134 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Code Review PR
Project context: Values in angle brackets below (e.g.
<scheme>,<JIRA_KEY>,<flag-key-enum>) are resolved at runtime — detect them from the project (xcodebuild -list -jsonfor the scheme,git/ghfor repo & owner, the branch name for the Jira key, a codebase search for flag/font files), or ask if they cannot be inferred. This plugin ships no per-project config.
Review the pull request $ARGUMENTS and post inline comments using the authenticated GitHub user.
$ARGUMENTS can be a branch name (e.g., feature/<JIRA_KEY>-XXXX) or a PR number (e.g., 4012).
Tone & Style
- Informal and friendly. Use casual greetings like "Hey, dev!", "Yo dev,", "Nice one, dev!", etc.
- Always address the PR author as "dev" (since they are the one who opened the PR).
- Keep it light — you're a teammate, not an auditor.
- Examples of good tone:
- "Hey dev, this looks solid! Just a small thing here..."
- "Yo dev, heads up — this might bite us later because..."
- "Nice work, dev! One suggestion though..."
- "Hey dev, nothing blocking here, just a thought..."
Steps
1. Find the PR
If $ARGUMENTS is a number, use it directly. If it's a branch name, find the PR:
gh pr list --head $ARGUMENTS --json number,title,url --jq '.[0]'
If no PR is found, inform the user and stop.
2. Gather PR Context
Run these in parallel:
# PR metadata
gh pr view <number> --json title,body,state,reviewDecision,reviews,additions,deletions,changedFiles,baseRefName,headRefName
# Full diff
gh pr diff <number>
# Existing inline comments (avoid duplicating)
gh api repos/{owner}/{repo}/pulls/<number>/comments --jq '.[] | {path, line, body, user: .user.login}'
# Existing reviews
gh api repos/{owner}/{repo}/pulls/<number>/reviews --jq '.[] | {state, body, user: .user.login}'
3. Analyze the Diff
Review the diff looking for these categories of issues:
Blocking (must fix before merge):
- Security vulnerabilities (OWASP top 10)
- Crashes or force unwraps without safety
- Data loss or race conditions
- Broken functionality
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 9d ago First seen · 134 lines · 0 tokens per session scan A 6b8cfe6b1992
review-pr is a command published in the GitHub repository carloshpdoc/ios-workflow-claude (7 stars, last pushed 3mo ago), licensed Apache-2.0. It costs nothing until one of its globs matches a file; then it loads 1,170 tokens. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other commands, from other repositories
review
Multi-agent code review with parallel validation.
sdd-explore
Explore and investigate an idea or feature — reads codebase and compares approaches.
gentle-sdd-ff
Fast-forward all SDD planning phases — proposal through tasks.
simplify
The over-engineering review: five tags (delete, stdlib, native, yagni, shrink), a mandatory replacement per finding, and a real null result when there is nothing to cut.
test
Run the repository's actual test suite: every ecosystem's canonical runner — NOT run is never green.
init
Install the formatters this repository needs, with every command visible before it runs.