Worked Example: Repo Review Agent
A complete Claude Agent SDK agent: a custom diff tool, a stripped tool surface, a per-call path gate, an audit hook, a reviewer subagent, and a budget cap — structurally unable to modify what it reviews.
Last updated
After this section you can
- Assemble a custom tool, permissions, a hook, a subagent and budgets into one read-only agent
- Choose between removing a tool, denying it by mode and gating it in a hook, and explain what each catches
- Handle every ResultMessage subtype a bounded CI run can end with
Worked Example: Repo Review Agent
One file that puts the last three sections on a single agent: a custom tool, a stripped tool surface, a hook that sees every call, a subagent per file, and caps on turns and dollars.
A review agent should be unable to change the code it reviews, whatever it is told. That is a property of its configuration: tools it is never offered, a mode that denies anything unlisted, and a hook that checks every path. A sentence in the system prompt is not a control.