Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add commands/jayminwest/mulch/pr-reviewsgit clone --depth 1 https://github.com/jayminwest/mulchWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/commands/jayminwest/mulch/pr-reviews)<a href="https://agentmods.dev/commands/jayminwest/mulch/pr-reviews"><img src="https://agentmods.dev/badge/commands/jayminwest/mulch/pr-reviews.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00003 | $0.00642 |
| Opus 5 | $0.00002 | $0.00321 |
| Sonnet 5 | $0.00001 | $0.00128 |
| Haiku 4.5 | $0.00000 | $0.00064 |
Grade A, and why
pr-reviews scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 6d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
Copies of this mod
2 near-identical copies found in the catalogue:
- pr-reviews — 92% identical, 4 lines differ
- pr-reviews — 92% identical, 4 lines differ
How it starts
The opening of the file, as written. The whole thing — 65 lines — stays where its author put it; the contents beside it link to each section on GitHub.
intro
Review open pull requests for code quality, project alignment, and risks.
Argument: $ARGUMENTS — optional PR number(s) to review (e.g., 9 or 9 12 15). If empty, review all open PRs.
Steps
1. Discover PRs to review
- If
$ARGUMENTScontains PR number(s), use those - Otherwise, run
gh pr list --state open --json number,title,author,headRefName,additions,deletionsto get all open PRs - If there are no open PRs, say so and stop
2. Spawn a review team
Use the Task tool to spawn parallel agents (one per PR). Each agent should:
a. Gather context
gh pr view <number> --json title,body,author,additions,deletions,files,commits,comments,reviews,headRefName,baseRefNamegh pr diff <number>to get the full diff- Read any files touched by the PR to understand the surrounding code
b. Code quality review
- Check for correctness — does the code do what the PR claims?
- Check for bugs, edge cases, and error handling gaps
- Check adherence to project conventions (see CLAUDE.md): strict TypeScript, zero runtime deps, Biome formatting, tab indentation, 100-char line width
- Check test coverage — are new code paths tested? Do tests follow the "never mock what you can use for real" philosophy?
- Flag any security concerns (injection, unsafe input handling, etc.)
c. Project alignment review
- Does this change fit the project's architecture and direction?
- Does it follow existing patterns or introduce unnecessary new ones?
- Is the scope appropriate — does it do too much or too little?
- Are there breaking changes or backward-compatibility concerns?
d. Risk assessment
- What could go wrong if this is merged?
- Are there performance implications?
- Does it touch critical paths (config loading, expertise storage, JSONL integrity)?
- Are there dependency or compatibility risks?
- Could it conflict with other open PRs?
e. Produce a review summary
Each agent should return a structured review:
- PR:
#<number> — <title>by<author> - Verdict: Approve / Request Changes / Needs Discussion
- Summary: 2-3 sentence overview
- Strengths: What's good about this PR
- Issues: Bugs, risks, or concerns (with file:line references)
- Suggestions: Non-blocking improvements
- Project alignment: How well it fits mulch's direction
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 6d ago First seen · 65 lines · 3 tokens per session scan A 4d3251fbf867
pr-reviews is a command published in the GitHub repository jayminwest/mulch (336 stars, last pushed 3d ago), licensed MIT. It adds 3 tokens to every session and 642 once invoked, about $0.0000 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other commands, from other repositories
check_schema_version
Check the Flyway schema version of the SQLite database on a Docker volume.
aim-task
Create, view, edit, list, or check off tasks in the AIM workspace.
aim-docs
Create, read, update, list, or rewrite project-level documentation.
aim-extract
Extract reusable project decisions, rules, schemas, or patterns into memory or docs.
aim-init
Initialize and sync the AIM project workspace context.
commit
Create a git commit with context.