Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
git clone --depth 1 https://github.com/hmj1026/dhpkWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/commands/hmj1026/dhpk/review-pending)<a href="https://agentmods.dev/commands/hmj1026/dhpk/review-pending"><img src="https://agentmods.dev/badge/commands/hmj1026/dhpk/review-pending/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/commands/hmj1026/dhpk/review-pending"><img src="https://agentmods.dev/badge/commands/hmj1026/dhpk/review-pending.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00025 | $0.00451 |
| Opus 5 | $0.00013 | $0.00226 |
| Sonnet 5 | $0.00005 | $0.00090 |
| Haiku 4.5 | $0.00003 | $0.00045 |
Grade A, and why
review-pending scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured yesterday.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
What it actually says
Context
- Git status: !
git status -sb - Changed files: !
git diff --stat HEAD 2>/dev/null | tail -20
Task
Step 1 — 確認審查範圍
優先順序如下(取第一個有效來源):
| 優先順序 | 條件 | 審查範圍 |
|---|---|---|
| 1 | 有 --files "<paths>" 參數 |
參數指定的路徑 |
| 2 | 以上皆無 | git diff HEAD --name-only 的修改清單 |
若兩者皆無(nothing to review)→ 直接回報「無待審檔案」,不啟動 agent。
Step 2 — 啟動 code-reviewer
將確認好的檔案清單與 context 傳給 code-reviewer agent 執行審查。
Agent prompt 應包含:
- 待審檔案清單(含相對路徑)
- 當前 git diff --stat(讓 agent 了解變更規模)
Step 3 — 轉達結果
直接輸出 code-reviewer 的審查報告。
Output
轉達 code-reviewer 的輸出(格式由 agent 定義):
## Code Review
PASS/WARN/FIX: <items>
Verdict: APPROVE | WARNING | BLOCK
APPROVE = 無 CRITICAL/HIGH;WARNING = 有 HIGH;BLOCK = 有任何 CRITICAL。
Examples
/review-pending
/review-pending --files "src/models/Order.php,src/services/OrderService.php"
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- yesterday Changed · -8 lines · -4 tokens per session scan B → A e82f2ae5307b
- 7d ago First seen · 65 lines · 29 tokens per session scan B 1dea339ce55f
review-pending is a command published in the GitHub repository hmj1026/dhpk (2 stars, last pushed yesterday), licensed MIT. It adds 25 tokens to every session and 451 once invoked, about $0.0001 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-09-05.
Other commands, from other repositories
review
A read-only review command that asks a reviewer agent to examine a branch or the current uncommitted changes. It returns a four-part acceptance report, including high-risk changes and whether the work matches a supplied specification.
review
Comprehensive multi-agent code quality and architecture review with cross-validation.
config
View and configure Argus settings.
help
Show Argus help and common workflows.
welcome
Welcome to Argus - getting started guide.
delegate-review
Run OCR in delegation mode — OCR handles file selection and rules, the host agent performs the actual review.