Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add commands/onmyway133/claude-code-plugins/review-codegit clone --depth 1 https://github.com/onmyway133/claude-code-pluginsWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00000 | $0.00401 |
| Opus 5 | $0.00000 | $0.00200 |
| Sonnet 5 | $0.00000 | $0.00080 |
| Haiku 4.5 | $0.00000 | $0.00040 |
Grade A, and why
review-code scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
What it actually says
Code Review
Perform a thorough code review on the specified files or recent changes.
Usage
/code-review [file_path | git_diff]
Arguments:
file_path- Path to a specific file to reviewgit_diff- Review unstaged changes (default if no argument)
Review Process
Step 1: Gather Context
If no file specified, run git diff to identify changed files. Read each file that has modifications.
Step 2: Analyze for Issues
Check each category and report findings with severity levels:
Critical (Must Fix)
- Security vulnerabilities (injection, XSS, hardcoded secrets)
- Data loss risks
- Race conditions or deadlocks
- Memory leaks or retain cycles
High (Should Fix)
- Logic errors or incorrect behavior
- Missing error handling for failure cases
- Breaking API changes
- Performance bottlenecks
Medium (Consider Fixing)
- Code duplication that harms maintainability
- Overly complex logic that could be simplified
- Missing edge case handling
- Inconsistent naming or style
Low (Optional)
- Minor style inconsistencies
- Opportunities for minor optimization
- Documentation gaps
Step 3: Report Format
For each issue found:
**[SEVERITY]** Brief description
Location: `file:line`
Problem: What's wrong and why it matters
Suggestion: How to fix it
Step 4: Summary
End with:
- Total issues by severity
- Overall assessment (Approve / Request Changes / Needs Discussion)
- Top 3 priorities if many issues found
Guidelines
- Focus on correctness and security first
- Be specific with line numbers and code snippets
- Explain why something is an issue, not just what
- Suggest concrete fixes, not vague improvements
- Acknowledge good patterns when you see them
- Skip nitpicks unless specifically asked
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 2d ago First seen · 74 lines · 0 tokens per session scan A 36dbc809627d
review-code is a command published in the GitHub repository onmyway133/claude-code-plugins (5 stars, last pushed 7mo ago), licensed MIT. It costs nothing until one of its globs matches a file; then it loads 401 tokens. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other commands, from other repositories
install
Install a skill from a local path, GitHub repository, npm package, or registry slug.
mcp
Install, list, search, check, update, and remove MCP servers for AI agents.
profile
Save, apply, and share multi-agent configuration profiles.
agents
Display the agent capability manifest — a structured overview of all supported AI coding agents, their skill install directories, support levels, and MCP server configuration support.
compose
Combine multiple SKILL.md files into a single composed skill. Supports two composition strategies: merge (deduplicate) and chain (override).
diff
Compare two SKILL.md files section-by-section. Parses frontmatter and body sections independently, showing exactly what changed.