Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add commands/ecro/embedeval/reviewgit clone --depth 1 https://github.com/Ecro/embedevalWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00000 | $0.00891 |
| Opus 5 | $0.00000 | $0.00445 |
| Sonnet 5 | $0.00000 | $0.00178 |
| Haiku 4.5 | $0.00000 | $0.00089 |
Grade A, and why
review scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured yesterday.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 97 lines — stays where its author put it; the contents beside it link to each section on GitHub.
/review — Code review & quality check
Deep review of task changes. Step 4 of the embedeval 5-stage workflow. Reports to screen only — no ANALYSIS document.
Communication
- Direct, evidence-based. Cite
file:linefor every finding. - Lead with critical issues, then warnings, then nits.
- Before analyzing, reframe as: "Does this meet the stated requirements without issues?" — counters confirmation bias toward the author's intent.
- Don't fold on pushback without new evidence.
Usage
/review [task-slug] # review files relevant to PLAN-<slug>
/review # review uncommitted + last commit
Context
- Repo:
/home/noel/embedeval - PLAN (if slug given):
plans/PLAN-<slug>.md - Standards:
CLAUDE.md→ "Quality Gates" and "Learned Corrections" - Quality gates to verify pass before reviewing:
uv run ruff format --check src/uv run ruff check src/uv run mypy src/uv run pytest tests/
Steps
-
Determine scope
- Slug provided → Read PLAN; list "Affected files" and "Success criteria". Review those files plus their tests.
- No slug →
git diff HEAD~1 -- ':!plans/'plus uncommitted working tree.
-
Run quality gates first — if any fail, report and stop. Don't review on top of a broken build.
-
Invoke specialized reviewers in parallel (via
Tasktool):reviewer— general code quality and correctness (always)walkthrough-reviewer— trace happy path, errors, edge cases through changed code (when logic changed)side-effect-reviewer— blast radius of API/contract changes (when exports or public APIs changed)test-quality-reviewer— do behavioral changes have matching tests?concurrency-reviewer— threading/locking touched?resource-lifecycle-reviewer— FD/connection/thread lifetimes touched?
-
Consolidate — merge reviewer outputs, dedup, rank by severity.
Focus areas
- Correctness: API contracts, edge cases, off-by-one, None handling
- Security: input validation, secrets, injection
- Architecture: separation, coupling, cohesion
- Tests: new behavior has matching tests (CLAUDE.md "new feature = new tests")
- Embedeval-specific — cross-check against CLAUDE.md "Learned Corrections":
scoped_containsscope argument explicit (not the defaultstripped)?- Run-scoped artifacts written under
run_dir/, notoutput_dir/? - L1/L2 skipping correctly for non-compilable cases?
- L4 mutation lambdas avoid hardcoding reference literals?
- Check regex accepts API variants (k_msleep/k_sleep, printf/printk/LOG_*)?
- Pydantic v2 uses
@computed_fieldfor JSON-serialized derived fields?
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- yesterday First seen · 97 lines · 0 tokens per session scan A 01366a0f43db
review is a command published in the GitHub repository Ecro/embedeval (11 stars, last pushed 26d ago), licensed Apache-2.0. It costs nothing until one of its globs matches a file; then it loads 891 tokens. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other commands, from other repositories
checklist
Generate a custom checklist for the current feature based on user requirements.
clarify
Identify underspecified areas in the current feature spec by asking up to 5 highly targeted clarification questions and encoding answers back into the spec.
specify
Create or update the feature specification from a natural language feature description.
analyze
Perform a non-destructive cross-artifact consistency and quality analysis across spec.md, plan.md, and tasks.md after task generation.
converge
Assess the current codebase against the feature's spec, plan, and tasks, then append any remaining unbuilt work as new tasks to tasks.md so implement can complete it.
implement
Execute the implementation plan by processing and executing all tasks defined in tasks.md.