Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
git clone --depth 1 https://github.com/ReviewToolkits/cext-review-toolkitWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/commands/reviewtoolkits/cext-review-toolkit/hotspots)<a href="https://agentmods.dev/commands/reviewtoolkits/cext-review-toolkit/hotspots"><img src="https://agentmods.dev/badge/commands/reviewtoolkits/cext-review-toolkit/hotspots.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00055 | $0.00622 |
| Opus 5 | $0.00028 | $0.00311 |
| Sonnet 5 | $0.00011 | $0.00124 |
| Haiku 4.5 | $0.00006 | $0.00062 |
Grade A, and why
hotspots scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 8d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 60 lines — stays where its author put it; the contents beside it link to each section on GitHub.
C Extension Hotspots
Run the three highest-value agents to find the worst functions to fix first: refcount-auditor, error-path-analyzer, and c-complexity-analyzer. Answers the question: "Where should I focus my review efforts?"
Scope: "$ARGUMENTS" (default: entire project)
Plugin root: <plugin_root> refers to the directory containing this command file's parent -- i.e., the plugins/cext-review-toolkit/ directory. Resolve it relative to this file's location.
Workflow
- Run
python <plugin_root>/scripts/discover_extension.py [scope]to detect the extension layout - If no C extension found, inform the user and stop
- Check the
code_generationfield. If"cython"or"mypyc", skip refcount-auditor and error-path-analyzer (95-100% FP rate on generated code) and rely on c-complexity-analyzer alone. - Run with at most 2 agents in parallel, feeding discovery context:
- refcount-auditor -- find reference counting errors
- error-path-analyzer -- find error handling bugs
- c-complexity-analyzer -- find the hardest-to-maintain code
- Synthesize into a prioritized hotspot report:
# C Extension Hotspots
## Extension: [name]
## Critical Issues (FIX)
[Refcount leaks, NULL dereferences, error handling bugs]
- [agent]: Issue in `function` (file.c:line) -- [description]
## Complexity Hotspots
| Rank | Function | File | Score | Lines | Top Issue |
|------|----------|------|-------|-------|-----------|
| 1 | func | f.c | 8.5 | 450 | Deep nesting |
## Error-Prone Functions
[Functions with both high complexity AND refcount/error issues -- these are
the highest-priority targets because they're hard to reason about AND have bugs]
## Recommended Fix Order
1. [Highest-impact fix -- typically a FIX finding in a high-complexity function]
2. [Next]
3. [Next]
For detailed analysis of a specific aspect:
/cext-review-toolkit:explore . refcounts deep
/cext-review-toolkit:explore . errors deep
Usage
/cext-review-toolkit:hotspots # Entire project
/cext-review-toolkit:hotspots src/ # Specific directory
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 8d ago First seen · 60 lines · 55 tokens per session scan A 6e80953188fd
hotspots is a command published in the GitHub repository ReviewToolkits/cext-review-toolkit (28 stars, last pushed 1mo ago), licensed MIT. It adds 55 tokens to every session and 622 once invoked, about $0.0003 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other commands, from other repositories
qa-changes
This skill should be used when the user asks to "QA a pull request", "test PR changes", "verify a PR works", "functionally test changes", or when an automated workflow triggers QA validation of code changes. Provides a structured methodology for setting up the environment, exercising changed behavior, and reporting…
doctor
Diagnosticar y reparar problemas del framework Don Cheli, git y entorno. Usa cuando el usuario dice "doctor", "problemas del framework", "don cheli no funciona", "repair Don Cheli", "debug setup", "setup broken", "framework broken", "reparar entorno". Detecta y repara issues de configuración, git y dependencias…
fix
Universal debugging and fix application with semantic code analysis.
doctor
Badi configuration validation. Checks all Badi components and produces a diagnostic report.
gh-issue-use-cypress
Like /gh-issue-use-browser, but pinned to the Cypress MCP — use when your project runs the Cypress MCP for browser automation. Example — /gh-issue-use-cypress "Composer > Save" saving toasts failure but the record persists.
http-service
Build, review or debug a Bun HTTP service. Loads the http-service skill, then works the task through its workflow.