Memory

Agent Design Review

Try it

Review an LLM agent design and find where it will be unreliable, expensive, or unsafe. Use when asked to review an agent architecture, critique a multi-step/...

What it does

Review an LLM agent design and find where it will be unreliable, expensive, or unsafe. Use when asked to review an agent architecture, critique a multi-step/tool-using agent, debug an agent that loops or goes off-task, or harden an agent before launch. Produces a structured review — task fit, control flow, tools, memory/context, failure handling, cost, and safety — with prioritised findings and fixes.

The skill document

Agent Design Review Skill

Most agents don't fail because the model is weak — they fail because the design lets them loop, call the wrong tool, lose the thread across steps, or burn tokens with no stopping rule. This skill reviews an agent's architecture against the decisions that actually determine reliability, and ranks the fixes — so "it works in the demo but not in prod" becomes a specific list of changes. (Writing a new agent spec? Use agent-spec.)

Working from a brief

Given a sketch ("a research agent that searches, reads, and writes a report"), deliver the full review anyway — infer the likely control flow and tools, label the inference, and flag what to confirm. Never withhold the review for missing detail.

Required Inputs

Ask for these only if they aren't already provided (else infer and label):

  • What the agent does — its goal, and what a successful run produces.
  • Control flow — single prompt, plan-then-execute, ReAct loop, or multi-agent; and the stopping condition.
  • Tools & actions — what it can call, and which actions have side effects (write, send, pay).
  • Memory & context — what state carries across steps, and how context is kept in budget.
  • Constraints — latency, cost per run, and the trust boundary (untrusted input? real-world actions?).

Output Format

Agent Review: [agent]

1. Summary — will this be reliable in production? The top 3 risks and the single change that helps most.

2. Findings by dimension — for each, what's sound and what's fragile:

DimensionFindingSeverityFix
Control flowno max-steps / no progress check → loopsHighstep budget + "am I making progress?" check + halt
Tool useoverlapping tools confuse selectionMedfewer, sharply-described tools; allowlist
Contextfull history re-sent each step → cost + driftHighsummarise/scope memory per step
Failure handlingone tool error aborts the runMedretry/backoff + graceful degradation
Safetyacts without confirmation on writesHighhuman/confirm gate on side-effecting actions

3. Reliability checklist — termination guarantee (it always stops), error recovery, idempotency of side-effecting actions, and determinism where it matters.

4. Cost & latency — where tokens/steps are spent and how to cut them (cheaper model for sub-steps, caching, fewer round-trips) without losing quality. Pair with llm-cost-latency-budget.

5. Safety — untrusted input/tool output handled as data not instructions, least-privilege tools, and confirmation gates on high-impact actions. Pair with llm-guardrails-spec.

6. Prioritised fix plan — ordered by impact-to-effort.

Quality Checks

  • The agent has a guaranteed stopping condition (step/budget cap + progress check) — no unbounded loops
  • Side-effecting actions are idempotent or gated by a confirmation
  • Tools are few and sharply described so selection is unambiguous; access is least-privilege
  • Context strategy keeps the window in budget across steps (no naive full-history resend)
  • Tool errors are recovered, not fatal — retry/backoff and graceful degradation
  • Findings are severity-ranked and the fix plan is ordered by impact

Anti-Patterns

  • Do not approve an agent with no termination guarantee — "it usually stops" is an outage waiting to happen
  • Do not let it take irreversible actions without a confirmation gate
  • Do not give it many overlapping tools — selection accuracy drops as the toolset grows
  • Do not resend the whole history every step — cost and drift both climb
  • Do not treat tool/retrieved output as trusted instructions — it's the injection surface

Based On

LLM agent design practice — bounded control flow, least-privilege tool use, context management, error recovery, and safety gating.

Related skills

Create CompleteTech LLC security, safety, permissions, and production-readiness review artifacts for agentic development workflows, including risk intake, to...

11 installs

Audit installed AI agent skills against the OWASP Agentic Skills Top 10 and emit text, JSON, SARIF, or HTML reports.

29 installs1 stars

Design evaluation suites, interpret agent benchmarks, and compare CrewAI, LangChain, AutoGen, and others.

22 installs1 stars

Security and compliance auditing tool for AI agents. Scans code for vulnerabilities, checks GDPR/CCPA compliance, generates risk reports with remediation guidance.

Audit whether AI agents can actually use your product — docs, APIs, onboarding, errors, and discoverability, evaluated from a non-human user's perspective. U...

Create CompleteTech LLC agentic development proposals, statements of work, discovery recaps, pilot recommendations, evaluation plans, risk/control plans, imp...

11 installs