Getting it into your agent
This one installs as part of its plugin. Adding the marketplace and installing the plugin brings it with everything else the plugin ships.
/plugin marketplace add vsladkov/claudex-stereo/plugin install stereoWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/commands/vsladkov/claudex-stereo/adversarial-review)<a href="https://agentmods.dev/commands/vsladkov/claudex-stereo/adversarial-review"><img src="https://agentmods.dev/badge/commands/vsladkov/claudex-stereo/adversarial-review/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/commands/vsladkov/claudex-stereo/adversarial-review"><img src="https://agentmods.dev/badge/commands/vsladkov/claudex-stereo/adversarial-review.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00013 | $0.02268 |
| Opus 5 | $0.00006 | $0.01134 |
| Sonnet 5 | $0.00003 | $0.00454 |
| Haiku 4.5 | $0.00001 | $0.00227 |
Grade A, and why
adversarial-review scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured yesterday.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 174 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Read ${CLAUDE_PLUGIN_ROOT}/skills/model-routing/SKILL.md first and apply its routing and job
rules. The rules below are specific to this command.
Run one adversarial review. Position it as a challenge review that questions the chosen implementation, design choices, tradeoffs, and assumptions, not merely as a stricter pass over implementation defects.
Raw slash-command arguments:
$ARGUMENTS
Core constraint:
- This command is review-only.
- Do not fix issues, apply patches, or suggest that you are about to make changes.
- Keep the framing focused on whether the current approach is the right one, what assumptions it depends on, and where the design could fail under real-world conditions.
Parse and route
Parse --model, --effort, --wait, --background, --base, --pr, --scope, and the
remaining focus text from the raw arguments. Default to the companion's normal model for a missing
--model. No workspace role default applies to this command.
- A model that does not start with
claude:takes the Codex path below, including one with an optionalcodex:prefix. Preserve the user's raw arguments byte-for-byte when invoking the companion; it strips the prefix. claude:session,claude:inherit, and the four explicit Claude aliases take the Claude path. Reject any otherclaude:*value using the routing skill's availability rule.- Reject
--effortwhen the selected model is anyclaude:*route. Effort is a Codex runtime control; tell the user to remove it or choose a Codex model. - Reject
--backgroundwith a Claude model before inspecting the repository: "--backgroundcreates durable Codex jobs visible in/stereo:status. A Claude agent review is bound to this session and would not survive it. Remove--backgroundto run the Claude review in the foreground, or choose a Codex model for a durable background review." --waitis accepted but redundant on the Claude path, which is always foreground.
Codex path
Execution mode rules:
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- yesterday Changed · -2 lines a2f5e5805074
- 3d ago Changed · +2 lines ddfeecf42e9e
- 10d ago First seen · 174 lines · 13 tokens per session scan A b778d0ba495b
adversarial-review is a command published in the GitHub repository vsladkov/claudex-stereo (3 stars, last pushed yesterday), licensed Apache-2.0. It adds 13 tokens to every session and 2,268 once invoked, about $0.0001 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other commands, from other repositories
done
Finish a task - document, create PR or merge, close.
check
Quick sanity check - code (inline 6-perspective) or plan (--plan).
plan
Structured planning - explore codebase, design architecture, evaluate options, produce detailed implementation plan.
worktree
Worktree lifecycle management - create, list, remove, info on interactive worktrees.
end
End a work session - a settlement pass that reconciles uncommitted / unpushed work + session context into git, the tracker, and a session snapshot file. --session (aliases --snapshot, --pre-compact, --compact) skips settlement and only writes the shared snapshot, keeping the session going.
start
Start session - restore context, show tasks, select work item.