Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
git clone --depth 1 https://github.com/hiromaily/go-crypto-walletWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/commands/hiromaily/go-crypto-wallet/review-code)<a href="https://agentmods.dev/commands/hiromaily/go-crypto-wallet/review-code"><img src="https://agentmods.dev/badge/commands/hiromaily/go-crypto-wallet/review-code.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00000 | $0.00315 |
| Opus 5 | $0.00000 | $0.00158 |
| Sonnet 5 | $0.00000 | $0.00063 |
| Haiku 4.5 | $0.00000 | $0.00032 |
Grade A, and why
review-code scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 7d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
What it actually says
Self-Review Changed Code
Review your own changed or added code and fix issues if found.
Process
- Get changed files: Run
git diff --name-onlyandgit diff --cached --name-onlyto identify modified files - Get diff content: Run
git diffandgit diff --cachedto see actual changes - Review checklist: For each changed file, check:
Code Quality
- No hardcoded values that should be configurable
- No commented-out code left behind
- No debug print statements (fmt.Println, console.log, etc.)
- Proper error messages with context
- Consistent naming conventions
Architecture (for Go files)
- Domain layer has ZERO infrastructure dependencies
- Use cases depend only on interfaces they need (ISP)
- Error handling uses
fmt.Errorf("context: %w", err) - No circular dependencies
Security (for sensitive areas)
- No private keys or sensitive data logged
- No secrets hardcoded
- Input validation at system boundaries
Documentation
- Public functions have doc comments
- Complex logic has explanatory comments
- Interface definitions describe purpose
- Fix issues: If issues are found, fix them immediately
Output
Report:
- Files reviewed
- Issues found (if any)
- Fixes applied (if any)
- Verification results
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 7d ago First seen · 48 lines · 0 tokens per session scan A 7b8435f8b0a8
review-code is a command published in the GitHub repository hiromaily/go-crypto-wallet (127 stars, last pushed 4mo ago), licensed MIT. It costs nothing until one of its globs matches a file; then it loads 315 tokens. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-09-01.
Other commands, from other repositories
audit-changes
Audit only the git diff vs main (or specified base). Optimized for PR review.
agent-wallet
Use the bundled agent-wallet skill to operate a non-custodial wallet directly on-chain (EVM and Bitcoin).
CLAUDE
Command "CLAUDE" from Calhooon/bsv-wallet-cli, covering commands, files, decisions, gotchas and related.
audit
Full security audit of a Solidity/Vyper/Rust contract or directory. Runs the entire vuln-skills library and dispatches DeFi specialist subagents based on detected protocol type.
exploit
Generate a working Foundry PoC that exploits a specific finding. Compiles and passes.
mint-cert
Mint a soulbound Audit Certificate NFT on Berachain (or other supported chain) for a completed audit.