review-code

A command for reviewing code in selected files or recent Git changes. Git is a tool that tracks changes to source code.

In plain words
What is it for?
Use it with a file path to review one file, or with a Git diff to review unstaged changes.
Why use it?
It helps identify security risks, bugs, missing error handling, performance problems, and maintainability issues before code is accepted.

Command

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add commands/onmyway133/claude-code-plugins/review-code
Clone the repo
git clone --depth 1 https://github.com/onmyway133/claude-code-plugins
Per session 0 Only the description is in the session, so the agent can decide to use it. The body loads when it is invoked.
When invoked 401 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.00000 $0.00401
Opus 5 $0.00000 $0.00200
Sonnet 5 $0.00000 $0.00080
Haiku 4.5 $0.00000 $0.00040

Measured 2d ago against content hash 36dbc809627d, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade A, and why

review-code scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

plugins/super/commands/review-code.md · 74 lines

What it actually says

Code Review

Perform a thorough code review on the specified files or recent changes.

Usage

/code-review [file_path | git_diff]

Arguments:

  • file_path - Path to a specific file to review
  • git_diff - Review unstaged changes (default if no argument)

Review Process

Step 1: Gather Context

If no file specified, run git diff to identify changed files. Read each file that has modifications.

Step 2: Analyze for Issues

Check each category and report findings with severity levels:

Critical (Must Fix)
  • Security vulnerabilities (injection, XSS, hardcoded secrets)
  • Data loss risks
  • Race conditions or deadlocks
  • Memory leaks or retain cycles
High (Should Fix)
  • Logic errors or incorrect behavior
  • Missing error handling for failure cases
  • Breaking API changes
  • Performance bottlenecks
Medium (Consider Fixing)
  • Code duplication that harms maintainability
  • Overly complex logic that could be simplified
  • Missing edge case handling
  • Inconsistent naming or style
Low (Optional)
  • Minor style inconsistencies
  • Opportunities for minor optimization
  • Documentation gaps

Step 3: Report Format

For each issue found:

**[SEVERITY]** Brief description
Location: `file:line`
Problem: What's wrong and why it matters
Suggestion: How to fix it

Step 4: Summary

End with:

  • Total issues by severity
  • Overall assessment (Approve / Request Changes / Needs Discussion)
  • Top 3 priorities if many issues found

Guidelines

  • Focus on correctness and security first
  • Be specific with line numbers and code snippets
  • Explain why something is an issue, not just what
  • Suggest concrete fixes, not vague improvements
  • Acknowledge good patterns when you see them
  • Skip nitpicks unless specifically asked
Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 2d ago First seen · 74 lines · 0 tokens per session scan A 36dbc809627d

Subscribe to this mod's changes

review-code is a command published in the GitHub repository onmyway133/claude-code-plugins (5 stars, last pushed 7mo ago), licensed MIT. It costs nothing until one of its globs matches a file; then it loads 401 tokens. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.