Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
git clone --depth 1 https://github.com/Kenmege/codex-claude-companionWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/commands/kenmege/codex-claude-companion/review)<a href="https://agentmods.dev/commands/kenmege/codex-claude-companion/review"><img src="https://agentmods.dev/badge/commands/kenmege/codex-claude-companion/review/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/commands/kenmege/codex-claude-companion/review"><img src="https://agentmods.dev/badge/commands/kenmege/codex-claude-companion/review.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00019 | $0.00482 |
| Opus 5 | $0.00010 | $0.00241 |
| Sonnet 5 | $0.00004 | $0.00096 |
| Haiku 4.5 | $0.00002 | $0.00048 |
Grade A, and why
review scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 9d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
What it actually says
/claude-review:review
Preflight
- Prefer the helper binary
codex-claudeif it is available on PATH. - If it is not available, tell the user to install the helper with
npm install -g codex-claude-companionafter npmjs publish, or from a cloned checkout withnpm install -g ..
Plan
Runs an agentic Claude pass over the current diff. Claude has read-only access to Read, Glob, Grep, Task (sub-agents), WebFetch, WebSearch, and Bash limited to the git-safe wrapper plus node/npm verification commands. Edits, writes, and shell mutations are blocked.
Default model is Claude Code's opus alias at xhigh effort. The helper auto-switches
to the Opus 1M alias (opus[1m]) when the diff
exceeds the inline envelope.
Commands
Use the exact argument tail the user supplied after /claude-review:review.
- Preferred:
codex-claude review <user-arguments>
Useful flags:
--preset quick|ship|security|research|deep— choose a role workflow.--legacy— disable agentic mode (structured output only, no tool access).--model <name>/--effort <level>— override profile.--mcp-config <file-or-json>— attach MCP servers (repeatable).--max-budget-usd <n>— cap review spend.--add-dir <path>— grant tool access to extra directories.--quiet/--debug— adjust rendered detail and job-log diagnostics.
Do not make edits or apply fixes from this command. The agent is read-only.
Verification
If the helper exits non-zero, report that failure exactly and stop.
Summary
Return the helper stdout verbatim.
Next Steps
If the user wants a harsher pass, suggest /claude-review:adversarial-review,
/claude-review:elite-review, /claude-review:deep-review, or
/claude-review:security-review.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 9d ago First seen · 57 lines · 19 tokens per session scan A 900b0095825d
review is a command published in the GitHub repository Kenmege/codex-claude-companion (2 stars, last pushed 6d ago), licensed Apache-2.0. It adds 19 tokens to every session and 482 once invoked, about $0.0001 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other commands, from other repositories
review-pr
Review a pull request (GitHub) or merge request (GitLab) and provide detailed feedback.
pr-reviewer
Review a Git branch as a PR against the base branch (auto-resolved — main/master) judged by THIS repo's contract (CLAUDE.md + .claude/skills/). Three-dot diff, route changed paths to skills, verify (eslint/prettier/tsc + tests), tiered report + confidence. Optional gated fix + commit after the report.
hatch3r-pr-resolve
Read open PR comments, evaluate each against current code via the rigor contract, implement accepted findings, reply inline. Multi-platform.
merge-check
A pre-merge checklist command for a GitHub pull request. A pull request is a proposed code change, and the command checks whether it meets the project’s documented requirements before merging.
release-kick
A release command for the River Review project that checks release instructions and pull-request state, updates an out-of-date branch, and verifies the release after merging.
plan-merge-order
A command that plans the order for merging several pull requests (PRs), which are proposed code changes reviewed before entering a shared branch. It checks their status and file changes, then studies dependencies and overlap to reduce rebasing work.