Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add commands/superplanehq/superplane/component-reviewgit clone --depth 1 https://github.com/superplanehq/superplaneWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/commands/superplanehq/superplane/component-review)<a href="https://agentmods.dev/commands/superplanehq/superplane/component-review"><img src="https://agentmods.dev/badge/commands/superplanehq/superplane/component-review.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00009 | $0.00345 |
| Opus 5 | $0.00005 | $0.00172 |
| Sonnet 5 | $0.00002 | $0.00069 |
| Haiku 4.5 | $0.00001 | $0.00034 |
Grade A, and why
component-review scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 4d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
What it actually says
You are reviewing a SuperPlane component implementation. Follow the rules in .cursor/commands/component-review.rules.md in order, one by one.
Input:
- Use the user's selection or the provided component name/path.
- If the component is ambiguous, ask one clarifying question before proceeding.
Process:
- Identify whether this is a core component (
pkg/components/...) or an integration component (pkg/integrations/...). - Locate the component's
Name(),Label(),Description(),Documentation(),Icon(),Color(),ExampleOutput(), andConfiguration(). - Evaluate each rule from the rules file in order.
Output:
- For every rule, output a subtitle with the rule name, then a single line with the result:
- Subtitle format:
### <short rule name> - Result line (OK):
OK - Result line (NOT OK):
NOT OK: <evidence>
- Subtitle format:
- If a rule fails evidence must cite concrete files and identifiers (function names, constants, files).
- If a rule fails, include a short, actionable hint after the evidence on the same line.
- After listing all rules, add a brief "Summary" section listing only failed rules (names + evidence + actionable hint)
Constraints:
- Do not skip rules.
- Provide OK/NOT OK only (no "N/A").
- Keep the output concise and scannable.
Extensibility:
- Anyone can add rules by editing
.cursor/commands/component-review.rules.md. - The command must always read the rules file and apply any new rules in order.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 4d ago First seen · 33 lines · 9 tokens per session scan A c6e52c3067a3
component-review is a command published in the GitHub repository superplanehq/superplane (5,700 stars, last pushed yesterday), licensed Apache-2.0. It adds 9 tokens to every session and 345 once invoked, about $0.0000 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other commands, from other repositories
fix-pr-review-comments
Analyze PR comments, implement fixes, and post targeted responses.
OPSX: Sync
Sync delta specs from a change to main specs.
framework-builder
Run the real Limitless framework builder for a topic.
test-summary
Command "test-summary" from vishnu2kmohan/mcp-server-langgraph, covering generate comprehensive test summary, 🧪 test summary generation, step 1: determine test scope, step 2: run tests and collect results and run tests with json output.
review-pr
Comprehensive PR review checklist to ensure code quality, testing, and best practices.
release-prep
Automated release readiness validation.