Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add commands/s977043/river-review/setup-teamgit clone --depth 1 https://github.com/s977043/river-reviewWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/commands/s977043/river-review/setup-team)<a href="https://agentmods.dev/commands/s977043/river-review/setup-team"><img src="https://agentmods.dev/badge/commands/s977043/river-review/setup-team.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00024 | $0.00743 |
| Opus 5 | $0.00012 | $0.00371 |
| Sonnet 5 | $0.00005 | $0.00149 |
| Haiku 4.5 | $0.00002 | $0.00074 |
Grade A, and why
setup-team scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 4d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
What it actually says
Task
River Review をこのプロジェクトでセットアップします。以下の手順を順に実行してください。
Step 1: 現状確認
.river/rules.mdが存在するか確認する。.river-review.json/.river-review.yamlが存在するか確認する(CLI / GitHub Actions パスの設定ファイル)。package.jsonのscriptsにreview等のエントリがないか確認する。
ls -la .river/ 2>/dev/null || echo ".river/ が見つかりません"
ls .river-review.* 2>/dev/null || echo ".river-review.* が見つかりません"
Step 2: .river/rules.md の生成
.river/rules.md がなければ作成する。
テンプレートは ${CLAUDE_PLUGIN_ROOT:-.}/.river/rules.template.md にある。
テンプレートの内容を .river/rules.md として Write ツールで保存する(親ディレクトリは自動作成される)。
作成後、ユーザーにプロジェクト固有のルール(アーキテクチャ方針、禁止パターン、セキュリティ要件)を記入するよう案内する。
Step 3: 統合モードの確認
Adopter Playbook に基づいて、ユーザーに最適な統合モードを提示する:
| モード | 用途 | 設定ファイル |
|---|---|---|
| Plugin(このモード) | エージェント主導のインタラクティブレビュー | .river/rules.md |
| GitHub Actions | PR 自動レビュー | .river-review.json |
CLI (river run) |
ローカルまたは任意の CI | .river-review.json |
現在は Plugin モード(インタラクティブレビュー)を使用中です。
Step 4: インストール確認
Claude Code にプラグインが正しくインストールされているか確認:
# Claude Code でインストール済みの場合は以下で確認できる
cat "${CLAUDE_PLUGIN_ROOT}/package.json" 2>/dev/null | grep '"version"' || echo "プラグイン ROOT が設定されていません"
インストールされていない場合は以下を案内する:
claude plugin add s977043/river-review
Step 5: 動作確認
セットアップが完了したら /review-local を実行して動作確認を行う。
Output
以下のサマリを出力してください:
## River Review セットアップ結果
- .river/rules.md: [作成済み / 既存 / 作成が必要]
- .river-review.json: [あり / なし(Plugin モードでは不要)]
- プラグイン: [インストール済み / 未インストール]
- 推奨次アクション: [具体的なステップ]
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 4d ago First seen · 73 lines · 24 tokens per session scan A 7f93fcb13aaf
setup-team is a command published in the GitHub repository s977043/river-review (3 stars, last pushed today), licensed MIT. It adds 24 tokens to every session and 743 once invoked, about $0.0001 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other commands, from other repositories
adversarial-review
Run an adversarial Gemini code review that challenges the implementation approach and design choices.
logic-fix-all
Autonomous audit-and-fix — after consent, scan the target, fix every logic issue found (all severities), verify each fix, and report anything unresolved.
logic-health
Sweep a whole codebase or directory for logic correctness — use before a release or to identify risk hotspots.
logic-review
Review code for logic bugs — use when you suspect something is wrong but have no failing test yet.
logic-diff
Check two code versions for semantic equivalence — use after a refactor or rewrite.
logic-explain
Trace execution step by step — use when code behavior is surprising or confusing.