Agent Editor
Build a subagent definition with every option in reach and best-practice checks as you type, then export it for Claude Code or Codex. Start from the sample code reviewer, a blank agent, or a file of your own.
Lowercase letters, digits, and hyphens. Without a name, Claude Code skips the file.
Leave it blank to follow the name. Saved with .md added.
Claude Code reads this to decide when to delegate, so treat it as a routing rule: what the agent does, when to use it, and what it isn’t for.
sonnet, opus, haiku, fable, a full model ID, or inherit for the main conversation’s model. A model passed when the agent is spawned overrides it. The Codex file uses this field too.
How hard the model thinks: low, medium, high, xhigh, or max, or a whole-number budget.
How much the agent may do without asking. Unset, it uses the session’s mode. If the main conversation is in auto, acceptEdits, or bypassPermissions, the agent runs in that mode and ignores this.
Tools 3 tools
MCP tools come from the servers in mcpServers or the session. Preloading skills doesn’t limit tools, and permissionMode decides what the agent may do without asking.
Start from
Checked tools are the ones the agent can use.
Read and search
Change files
Run commands
Web
Delegate
More tools 0 of 31 on
MCP tools: mcp__server for every tool a server supplies, or mcp__server__tool for one.
Tool names or patterns, such as mcp__* for every MCP tool or mcp__github__delete_repo for one.
Written as
tools: Read, Grep, GlobSkills and turn limit
Skills loaded in full when the agent starts. It doesn’t stop the agent from using others.
Stops the agent after this many turns, each one model request plus the tool calls it makes. Output that hits the cap is marked partial.
How it runs
true always runs the agent in the background. Unset, Claude decides.
worktree runs the agent in its own git worktree, branched from your default branch rather than your current HEAD.
A memory directory that persists between runs: user (~/.claude/agent-memory/), project (.claude/agent-memory/, which you can commit), or local (.claude/agent-memory-local/, kept out of version control).
The color Claude Code shows the agent in.
Sent as the first message when this agent runs the whole session with claude --agent.
Context and caching
true skips your user, project, and local CLAUDE.md files for this agent, in Claude Code 2.1.271 and later. Managed policy still loads.
How long this agent’s prompt cache lasts, 5m or 1h. The subagentPromptCacheTtl setting wins when both are set.
MCP servers and hooks
A YAML list. Each item is the name of a server you’ve already configured, or one name mapped to a full server entry. Claude Code drops an item it can’t read and still loads the agent.
Hooks that run only for this agent, in YAML: an event such as PreToolUse, then a list of matchers and their handlers.
Undocumented
Claude Code 2.1.288 reads these fields, but its documentation doesn’t mention them, so they can change or disappear without notice.
An agent type to start as a background observer of this agent.
Text added to the end of the observer’s activity digests.
Whether this agent’s own subagents get the observer too. Only false changes anything.
System prompt
27 lines
The agent starts with this and the task it’s handed, never your conversation. Say what it does and doesn’t do, and the exact shape of its report. Leave out facts that change, such as commits, branches, and paths: they belong in the task you hand it each time.
A Markdown file with YAML frontmatter. The body is the system prompt. Switching keeps everything you’ve set for either tool.
Checks
Ready for Claude Code
No errors or warnings.
Export
Save it as .claude/agents/code-reviewer.md in your project,
or in ~/.claude/agents/ to use it in every project.
--- name: code-reviewer description: Reviews a finished change for correctness bugs, missing tests, and unsafe input handling, and reports findings with file and line references. Use after a change is written and before it is committed. Not for style nits or for writing fixes. tools: - Read - Grep - Glob model: sonnet --- You review code changes. You don't fix them. ## What to review Read the diff you're given, then the files it touches and their nearest tests. Look for: - Logic errors, unhandled edge cases, and broken error handling. - Changed behavior that no test would catch if it regressed. - Untrusted input that reaches a shell command, a query, a file path, or HTML. Skip formatting and naming preferences unless they hide a bug. ## Rules - Cite a file and line for every finding. If you can't point at the line, it isn't a finding. - Don't edit files, and don't run anything that changes them. - If the change is fine, say so. Never invent findings to fill the report. ## Report Return only this, in Markdown: **Verdict:** Approve, or Changes requested. **Findings:** One bullet per finding, most severe first: `path/to/file.ts:42`, what's wrong, why it matters, and the smallest fix. **Not checked:** Anything you couldn't verify, such as behavior that depends on code outside the diff.
Load an agent
A .md file loads as a Claude Code agent and a .toml file as a Codex
agent. Drop a whole agents folder to pick one from it.
Drop an agent file or folder here
Notes
- For Claude Code, the verdict checks the subagent schema, the naming rules, MCP server items
Claude Code would drop, hook fields, unknown keys, and anti-patterns such as
bypassPermissions. For Codex, it checks the agent file schema, plus this page’s checks for names, empty fields, skill rules that name nothing, anddanger-full-access. - Tips under a field are advice, such as listing tools explicitly. They never change the verdict.
- A loaded
.mdfile keeps its comments and formatting for every field you don’t change, and a tool list written as a comma-separated string stays one. A loaded.tomlfile is written back in a fixed key order, and its comments are lost. - Codex 0.160 checks
mcp_servers,sandbox_mode,hooks, andtoolsin an agent file but drops them when it loads the agent. Of[skills], it keeps only what turns skills off. The editor keeps the rest so a loaded file writes back unchanged, and marks it as having no effect. - Files are read in your browser. Nothing is uploaded.