Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add commands/xu-xiang/everything-claude-code-zh/code-reviewgit clone --depth 1 https://github.com/xu-xiang/everything-claude-code-zhWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/commands/xu-xiang/everything-claude-code-zh/code-review)<a href="https://agentmods.dev/commands/xu-xiang/everything-claude-code-zh/code-review"><img src="https://agentmods.dev/badge/commands/xu-xiang/everything-claude-code-zh/code-review.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00010 | $0.00555 |
| Opus 5 | $0.00005 | $0.00278 |
| Sonnet 5 | $0.00002 | $0.00111 |
| Haiku 4.5 | $0.00001 | $0.00056 |
Grade A, and why
code-review scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 4d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
What it actually says
代码审查(Code Review)命令
针对代码质量、安全性和可维护性审查代码变更:$ARGUMENTS
你的任务
- 获取已变更文件:运行
git diff --name-only HEAD - 分析每个文件的潜在问题
- 生成结构化报告
- 提供可操作的改进建议
检查项分类
安全问题(致命 - CRITICAL)
- 硬编码的凭据(Credentials)、API keys、tokens
- SQL 注入(SQL injection)漏洞
- XSS 漏洞
- 缺少输入验证(Input validation)
- 不安全的依赖项(Insecure dependencies)
- 路径穿越(Path traversal)风险
- 身份验证/授权(Authentication/authorization)缺陷
代码质量(高 - HIGH)
- 函数超过 50 行
- 文件超过 800 行
- 嵌套深度 > 4 层
- 缺少错误处理(Error handling)
- 遗留
console.log语句 - TODO/FIXME 注释
- 公开 API 缺少 JSDoc
最佳实践(中 - MEDIUM)
- 可变模式(Mutation patterns,建议改用不可变模式 immutable)
- 不必要的复杂性
- 新代码缺少测试(Missing tests)
- 可访问性(Accessibility/a11y)问题
- 性能顾虑
风格(低 - LOW)
- 命名不一致
- 缺少类型注解(Type annotations)
- 格式化问题
报告格式
针对发现的每个问题:
**[SEVERITY]** file.ts:123
问题 (Issue): [Description]
修复 (Fix): [How to fix]
判定决策
- CRITICAL(致命)或 HIGH(高)问题:阻止提交,必须修复
- MEDIUM(中)问题:建议在合并前修复
- LOW(低)问题:可选的改进建议
重要说明:绝不要批准包含安全漏洞的代码!
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 4d ago First seen · 69 lines · 10 tokens per session scan A 824d44805090
code-review is a command published in the GitHub repository xu-xiang/everything-claude-code-zh (1,927 stars, last pushed 6mo ago), licensed MIT. It adds 10 tokens to every session and 555 once invoked, about $0.0001 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other commands, from other repositories
awesome-chatgpt
Search awesome-ChatGPT-repositories for open-source GitHub repositories related to ChatGPT and LLMs.
init
Scaffold a new MindBase project (v2 layout). Usage: /mb:init [template] [-- mission ...].
commit
智能生成 Git 提交信息并提交.
doctor.es
Diagnostica problemas de inferencia LLM en Mac: asiai doctor verifica el estado de los motores, conflictos de puertos, carga de modelos y estado de la GPU.
requirement-review
需求文档多角色评审(requirement-review):需求文档 → 7-Agent 并行评审 → 重构高质量需求文档(Runtime 受控流程,0-7 阶段状态机).
claude-request
Send a prompt to Claude Code via the LLM gateway with session tracking.