Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add commands/vepo/issues/review_code_structuregit clone --depth 1 https://github.com/vepo/issuesWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00019 | $0.00536 |
| Opus 5 | $0.00010 | $0.00268 |
| Sonnet 5 | $0.00004 | $0.00107 |
| Haiku 4.5 | $0.00002 | $0.00054 |
Grade A, and why
Review Code Structure scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured yesterday.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 92 lines — stays where its author put it; the contents beside it link to each section on GitHub.
You are a senior Java architect reviewing the Issues codebase. Produce a read-only structural audit — do not change code unless the user explicitly asks to fix findings afterward.
Prerequisites: Read ARCHITECTURE.md and docs/domain-specification.md before auditing.
Scope
Default: full repository (src/main/java/dev/vepo/issues/, src/main/webui/, tests).
If the user names a package or path, restrict scope but still check cross-package imports.
Output
Write one report:
reports/code-structure-review-{sequential}-{dd-MM-yyyy-HH-mm-ss}.md
Severity: critical | major | minor | suggestion.
Do not ask for confirmation before starting. Do not apply refactors in this command.
Phase 1 — Inventory
- List feature packages from ARCHITECTURE.md §5.
- Build type inventory: endpoints, repositories, services, entities, Request/Response records.
Phase 2 — Layer compliance
Read issues-layered-architecture.mdc.
| Check | Pass criteria |
|---|---|
| Endpoint → Repository bypass | Endpoints with multi-entity logic use *Service |
| Service → EntityManager | Services use repositories, not EM directly |
| Repository purity | No business rules or HTTP in repositories |
Phase 3 — HTTP contract
Read issues-http-contract.mdc.
- All
*Request/*Responseare records ArchitectureTestwould pass
Phase 4 — Bounded contexts
Read issues-bounded-contexts.mdc.
- Package dependency direction matches domain spec
- No unrelated cross-package repository access
Phase 5 — Duplication
- Repeated ticket/workflow validation logic
- Duplicate Angular HTTP calls
- Similar Response mapping patterns
Phase 6 — Frontend structure
- Services centralize API calls
- Components stay presentation-focused
Report template
# Code structure review — Issues
## Summary
(2–3 sentences)
## Findings
### Critical
- ...
### Major
- ...
### Minor / suggestions
- ...
## Recommended next steps
1. ...
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- yesterday First seen · 92 lines · 19 tokens per session scan A d51557304f95
Review Code Structure is a command published in the GitHub repository vepo/issues (8 stars, last pushed 1mo ago), licensed Apache-2.0. It adds 19 tokens to every session and 536 once invoked, about $0.0001 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other commands, from other repositories
plan
Run /plan — see .claude/commands/plan.md for the authoritative spec.
wire-harness
Run /wire-harness — see .claude/commands/wire-harness.md for the authoritative spec.
build
Run /build — see .claude/commands/build.md for the authoritative spec.
ship
Run /ship — see .claude/commands/ship.md for the authoritative spec.
onboard
Run /onboard — see .claude/commands/onboard.md for the authoritative spec.
review
Run /review — see .claude/commands/review.md for the authoritative spec.