Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add commands/rcdelacruz/claude-code-agents/workflow-review-codegit clone --depth 1 https://github.com/rcdelacruz/claude-code-agentsWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00009 | $0.01965 |
| Opus 5 | $0.00005 | $0.00983 |
| Sonnet 5 | $0.00002 | $0.00393 |
| Haiku 4.5 | $0.00001 | $0.00197 |
Grade A, and why
workflow-review-code scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 324 lines — stays where its author put it; the contents beside it link to each section on GitHub.
You are in CODE REVIEW MODE.
Use code-reviewer agent to perform thorough code quality analysis.
Review Process
1. Initial Assessment (5 mins)
- Review overall code structure
- Check file organization
- Assess naming conventions
- Verify TypeScript usage
2. Architecture Review (10 mins)
Component Architecture
- Server vs Client Components used correctly
- Props properly typed with interfaces
- Components are focused and single-purpose
- Proper separation of concerns
Data Flow
- Data fetching in Server Components
- Mutations via Server Actions or tRPC
- State management appropriate for use case
- No prop drilling (use Context or state management)
Code Organization
- Files in correct directories
- Consistent naming (camelCase, PascalCase, kebab-case)
- Imports organized (React, libraries, local)
- No circular dependencies
3. TypeScript Review (10 mins)
Type Safety
// ❌ BAD: Any types
function processData(data: any) { }
// ✅ GOOD: Proper types
function processData(data: User) { }
// ❌ BAD: Type assertions
const user = data as User
// ✅ GOOD: Type guards
if (isUser(data)) {
// data is User
}
Type Coverage
- No
anytypes (except unavoidable cases) - Functions have return type annotations
- Interfaces defined for complex objects
- Generics used where appropriate
- Type guards for runtime checks
4. React Best Practices (15 mins)
Hooks Usage
// ❌ BAD: Conditional hooks
if (condition) {
useEffect(() => { })
}
// ✅ GOOD: Hooks at top level
useEffect(() => {
if (condition) { }
}, [condition])
// ❌ BAD: Missing dependencies
useEffect(() => {
fetchData(userId)
}, []) // userId missing!
// ✅ GOOD: All dependencies
useEffect(() => {
fetchData(userId)
}, [userId])
Component Patterns
- Hooks only in components/custom hooks
- Proper dependency arrays in useEffect
- Memoization used appropriately (useMemo, useCallback)
- No inline function definitions in JSX (if used in deps)
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 2d ago First seen · 324 lines · 9 tokens per session scan A dc7885842577
workflow-review-code is a command published in the GitHub repository rcdelacruz/claude-code-agents (2 stars, last pushed 10mo ago), licensed MIT. It adds 9 tokens to every session and 1,965 once invoked, about $0.0000 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other commands, from other repositories
git
Git operations with intelligent commit messages and workflow optimization.
checklist
Generate a custom checklist for the current feature based on user requirements.
clarify
Identify underspecified areas in the current feature spec by asking up to 5 highly targeted clarification questions and encoding answers back into the spec.
specify
Create or update the feature specification from a natural language feature description.
analyze
Perform a non-destructive cross-artifact consistency and quality analysis across spec.md, plan.md, and tasks.md after task generation.
constitution
Create or update the project constitution from interactive or provided principle inputs.