1:1 mentoring with Big Tech AI engineers
LLM & Agentic

Worked Example: Repo Review Agent

A complete Claude Agent SDK agent: a custom diff tool, a stripped tool surface, a per-call path gate, an audit hook, a reviewer subagent, and a budget cap — structurally unable to modify what it reviews.

Last updated

Production9 min readFirst readPermissions & Hooks: Gating the Agent

After this section you can

  • Assemble a custom tool, permissions, a hook, a subagent and budgets into one read-only agent
  • Choose between removing a tool, denying it by mode and gating it in a hook, and explain what each catches
  • Handle every ResultMessage subtype a bounded CI run can end with
30

Worked Example: Repo Review Agent

One file that puts the last three sections on a single agent: a custom tool, a stripped tool surface, a hook that sees every call, a subagent per file, and caps on turns and dollars.

Key idea

A review agent should be unable to change the code it reviews, whatever it is told. That is a property of its configuration: tools it is never offered, a mode that denies anything unlisted, and a hook that checks every path. A sentence in the system prompt is not a control.

One review agent, four layers: each one stops a different failure
ONE TOOL CALL, FROM PROPOSAL TO RESULT RUN BOUNDS · max_turns=30 · max_budget_usd=2.00 · subagents included Claude claude-opus-5 proposes a call Tool surface Read · Grep · Glob Agent · changed_files Write, Edit, Bash: not offered PreToolUse hook logs every call denies paths outside repo Runs in repo read-only result back to Claude 1 · call 2 · listed 3 · allowed denied: the reason goes back as the tool result reviewer subagent · Read, Grep · its own context the same hook fires for its calls too Remove any layer and the agent still runs. That is why each one is chosen on purpose.

Related

More in LLM & Agentic

Get full access to all 74+ sections with code examples, diagrams, and interactive animations.

Unlock Premium