checklist

A command that outputs a ready-to-copy checklist for reviewing code changes.

In plain words
What is it for?
Use it during pull-request or code reviews to check responsibilities, input validation, secrets, tests, type checks, logging, and related issues.
Why use it?
It helps reviewers check code quality, security, configuration, tests, style, and error handling without recreating the checklist each time.

Command

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add commands/hculap/better-code/checklist
Clone the repo
git clone --depth 1 https://github.com/hculap/better-code
Per session 9 Only the description is in the session, so the agent can decide to use it. The body loads when it is invoked.
When invoked 519 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.00009 $0.00519
Opus 5 $0.00005 $0.00260
Sonnet 5 $0.00002 $0.00104
Haiku 4.5 $0.00001 $0.00052

Measured yesterday against content hash 5f3b5fb13975, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade A, and why

checklist scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured yesterday.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

plugins/code-standards/commands/checklist.md · 62 lines

How it starts

The opening of the file, as written. The whole thing — 62 lines — stays where its author put it; the contents beside it link to each section on GitHub.

Code Review Checklist

Output the lightweight review checklist ready for copy/paste into PR comments or code reviews.

Checklist Output

## Code Review Checklist

### Quick Validation
- [ ] Can I explain this code in 30 seconds?
- [ ] File sizes within limits? (target: 100-300 LOC, warning: 400, critical: 800)
- [ ] Function sizes within limits? (target: 10-30 LOC, warning: 50, critical: 80)
- [ ] One responsibility per module/class?

### Code Quality
- [ ] No hidden global state or surprising side effects?
- [ ] Errors handled meaningfully (no silent failures)?
- [ ] No swallowed exceptions or empty catch blocks?
- [ ] Appropriate logging at boundaries?

### Configuration & Security
- [ ] Config validated at startup?
- [ ] No secrets or credentials in code?
- [ ] External input validated and sanitized?
- [ ] Using parameterized queries (if applicable)?

### Testing
- [ ] Tests cover the important behavior?
- [ ] Tests focus on behavior, not implementation?
- [ ] Edge cases and error paths tested?

### Style & Consistency
- [ ] Formatting/lint checks pass?
- [ ] Type checks pass (if applicable)?
- [ ] Naming is clear and consistent?
- [ ] Comments explain "why", not "what"?

### Principles Check
- [ ] **KISS**: Is this the simplest solution?
- [ ] **DRY**: No real duplication? (not premature abstraction)
- [ ] **YAGNI**: No features built "for later"?
- [ ] **SRP**: Each module has one reason to change?

Additional Context

If settings exist in .claude/code-standards.local.md, read them and adjust the thresholds in the checklist to match the project's configured limits.

For example, if strict thresholds are configured:

  • Change "target: 100-300 LOC, max: 400-600" to "target: 100-200 LOC, max: 250"
  • Change "target: 10-30 LOC, max: 50" to "target: 10-20 LOC, max: 30"

Output Format

Present the checklist in a clean, copyable format. If the user mentions they want it for a specific platform (GitHub PR, Jira, etc.), adjust formatting as needed.

Read the full file on GitHub · 62 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. yesterday First seen · 62 lines · 9 tokens per session scan A 5f3b5fb13975

Subscribe to this mod's changes

checklist is a command published in the GitHub repository hculap/better-code (2 stars, last pushed 7mo ago), licensed MIT. It adds 9 tokens to every session and 519 once invoked, about $0.0000 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.