Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add commands/sgaunet/claude-plugins/analyze-prgit clone --depth 1 https://github.com/sgaunet/claude-pluginsWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/commands/sgaunet/claude-plugins/analyze-pr)<a href="https://agentmods.dev/commands/sgaunet/claude-plugins/analyze-pr"><img src="https://agentmods.dev/badge/commands/sgaunet/claude-plugins/analyze-pr.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00023 | $0.01566 |
| Opus 5 | $0.00012 | $0.00783 |
| Sonnet 5 | $0.00005 | $0.00313 |
| Haiku 4.5 | $0.00002 | $0.00157 |
Grade A, and why
analyze-pr scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 4d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 142 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Analyze Pull Request Command
Perform comprehensive analysis of a pull request including code review, security scan, and test coverage.
Process
-
Detect Repository Type: Use the
detect-repo-hostskill to identify the hosting service (GitHub, GitLab, or Forgejo) and extract owner/repo details. -
Fetch PR Details: Use the appropriate CLI
-
GitHub:
gh pr view <number> --json title,body,author,files,commits,gh pr diff <number> -
GitLab:
glab mr view <number>,glab mr diff <number> -
Forgejo:
fgj pr view <number> -R <owner>/<repo> --jsonfor metadata.fgjhas nopr diffsubcommand — obtain the diff via a git fallback:- From the
fgj pr viewJSON, read the head and base branch names. git fetch origingit diff origin/<base>...origin/<head>
This works for same-repo PRs (both branches exist on
origin); it does not cover cross-fork PRs whose head lives in a different repository. As a secondary option, fetch the diff directly from the Forgejo API:GET <api_base>/repos/<owner>/<repo>/pulls/<n>.diff, where<api_base>is the field returned by thedetect-repo-hostskill (e.g.https://git.sylvlab.fr/api/v1). Never hardcode a host — it breaks on every other Forgejo instance. - From the
-
-
Analyze Changes: Launch 4 parallel Sonnet agents to independently review the pull request:
Agent #1: Code Quality Review (
code-review-enforceragent)- Review modified files for code quality issues
- Check for logic errors, error handling, performance issues
- Verify adherence to coding standards
- Return: list of issues with severity levels and line numbers
Agent #2: Security Analysis (
security-auditoragent)- Scan for security vulnerabilities in modified files
- Focus on auth/crypto changes, input validation, SQL injection
- Check for exposed secrets or sensitive data
- Return: list of security findings with CVSS-like severity ratings
Agent #3: Test Coverage Assessment
- Analyze modified files to identify new functionality
- Check if corresponding tests were added
- Evaluate test quality and edge case coverage
- Return: coverage report with missing test scenarios
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 4d ago First seen · 142 lines · 23 tokens per session scan A 60ca20f4886a
analyze-pr is a command published in the GitHub repository sgaunet/claude-plugins (16 stars, last pushed 2d ago), licensed MIT. It adds 23 tokens to every session and 1,566 once invoked, about $0.0001 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other commands, from other repositories
security-audit-static
Static security audit of AI-built code — map trust boundaries, cross-reference documented intent, self-refute every finding, and report only evidence-backed risks.
performance-audit-static
Static performance audit of AI-built code — find N+1 queries and request waterfalls, over-fetching, missing indexes, and caching opportunities, ranked by effort and impact.
document-app
Reverse-engineer an AI-built codebase into the system documents reviewers and auditors need — a core set (architecture, flows, permissions, variables) plus conditional docs (emails, cron, SEO, automation) when they apply.
plan-okrs
Brainstorm team-level OKRs aligned with company objectives — qualitative objectives with measurable key results.
write-stories
Break a feature into backlog items — user stories, job stories, or WWA format with acceptance criteria.
battlecard
Create a sales-ready competitive battlecard — positioning, feature comparison, objection handling, and win strategies.