review-errors

A read-only error review looks for failures that are changed into something that appears successful to the person or system that needs to respond.

In plain words
What is it for?
Use it to inspect changed error handling and record where a caller, operator, or user could miss a failure.
Why use it?
It helps prevent timeouts, rejected operations, unavailable services, and other real failures from disappearing behind defaults, retries, or ignored errors.

Command

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add commands/coleam00/archon/review-errors
Clone the repo
git clone --depth 1 https://github.com/coleam00/Archon
Per session 0 Only the description is in the session, so the agent can decide to use it. The body loads when it is invoked.
When invoked 889 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.00000 $0.00889
Opus 5 $0.00000 $0.00445
Sonnet 5 $0.00000 $0.00178
Haiku 4.5 $0.00000 $0.00089

Measured yesterday against content hash c878b15bfd48, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade A, and why

review-errors scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured yesterday.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

.archon/workflows/sdlc/review/commands/review-errors.md · 42 lines

How it starts

The opening of the file, as written. The whole thing — 42 lines — stays where its author put it; the contents beside it link to each section on GitHub.

Error Review — Silent Failures

Find one defect: a real failure crosses the changed code and becomes indistinguishable from success to the caller, operator, or user who must react. Not every error needs logging; recovery is correct when the contract permits it and the right owner can still observe the outcome. Read-only: never modify files, commit, or post anywhere.

Read $ARTIFACTS_DIR/review/scope.md first, and the project's architecture.md if it has one. Anchor the review on the accepted work order's stated invariants, and scale depth to what the change can destroy: irreversible or destructive paths, lifecycle ownership, persisted contracts and schemas, credentials and auth boundaries, integration boundaries, and concurrency over shared state each get an explicit attempt to refute the invariant they rest on; a prose-only change gets the minimum. In light mode, verify prior findings from this lens first, then examine only the delta.

A finding needs all four

  1. Failure source — a reachable error, timeout, rejection, exhausted retry, or unavailable dependency.
  2. Suppression point — changed code catches, converts, defaults, retries, or logs-and-continues in a way that removes the failure's identity.
  3. False success — a concrete caller or user proceeds as though the operation succeeded, or cannot distinguish degraded output, with file:line.
  4. Right owner and channel — who needs the signal, and the smallest existing channel that reaches them (return type, thrown error, event, status field, log). Never invent an error subsystem for one finding.

A broad catch or fallback is not a finding by syntax alone — trace the consequence or drop it. Before judging visibility, classify the operation: required, best-effort, a capability probe, or an implementation detail — the same silence is correct for one and a defect for another.

Three probes that find what syntax scanning misses:

  • Ambiguous absence — can the returned value legitimately mean both "nothing happened" and "the operation failed"? If the caller cannot tell, the failure has no identity.
  • Fallback of the fallback — when the recovery path itself fails, does the original failure's identity survive, or does the second failure mask the first?
  • Surviving side effects — can a partial write or side effect outlive the reported failure, leaving state the caller believes was never touched?

Read the full file on GitHub · 42 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. yesterday First seen · 42 lines · 0 tokens per session scan A c878b15bfd48

Subscribe to this mod's changes

review-errors is a command published in the GitHub repository coleam00/Archon (23,313 stars, last pushed yesterday), licensed MIT. It costs nothing until one of its globs matches a file; then it loads 889 tokens. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.