Agent skill

Amber Review

by ambient-code in ambient-code/platform

Perform a comprehensive code review using repository-specific standards.

MITAuto-check passedDevelopment

Install Amber Review

skills CLI
$ npx skills add ambient-code/platform --skill amber-review -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install ambient-code/platform amber-review --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/ambient-code/platform.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/amber-review .claude/skills/amber-review && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
amber-review
GitHub stars
131
Token cost
~1.4k tokens
SKILL.md length
592 words
Files
2
Skills in repo
18
Repo updated
First seen
Licence
MIT

At a glance

Perform a comprehensive code review using repository-specific standards.

  • Works in 5 steps: Load Review Context → Identify Changes to Review → Perform Review → …
  • Reviewing code changes
  • SKILL.md covers User Input, Execution Steps, When to Use This vs Individual… and Operating Principles
  • Calls git and gh

What it does

Amber Review is an agent skill from ambient-code/platform. Perform a comprehensive code review using repository-specific standards. Use when reviewing code changes, checking PR quality, auditing convention compliance, or validating changes before merge. Triggers on: "review code", "check changes", "code review", "amber review", "review PR", "audit conventions", "quality check".

Its SKILL.md is about 1.4k tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files (for example `evals/evals.json`).

It sits in Development, covering Code review and Pull requests. It works with Kubernetes. The repository describes itself as: Vision/Mission https://ambient-code.ai : Virtual team management and collaboration platform. User guides: https://ambient-code.github.io/platform/. The licence is MIT.

When your agent uses it

  • Reviewing code changes
  • Checking PR quality
  • Auditing convention compliance
  • Validating changes before merge

Example prompts

  • “review code”
  • “check changes”
  • “code review”
  • “/amber-review”

Workflow steps

5 steps, taken from the step headings in SKILL.md.

  1. Load Review Context
  2. Identify Changes to Review
  3. Perform Review
  4. Classify Findings by Severity
  5. Produce Review Report

What it can do on your machine

Read from SKILL.md and the folder at commit e15afd3. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • git
    • gh

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use git and gh, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Amber Review loads about 1.4k tokens when it runs. Until then it costs about 84 tokens; SKILL.md has 592 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~84
When it runs · the whole SKILL.md, loaded when a task matches
~1.4k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from ambient-code/platform at commit e15afd3, republished under its MIT licence (© ambient-code). 592 words, ~1,417 tokens.

Download SKILL.mdSave it as .claude/skills/amber-review/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
amber-review
description
Perform a comprehensive code review using repository-specific standards. Use when reviewing code changes, checking PR quality, auditing convention compliance, or validating changes before merge. Triggers on: "review code", "check changes", "code review", "amber review", "review PR", "audit conventions", "quality check".

Amber Review

Stringent, standards-driven code review against this repository's documented patterns, security requirements, and architectural conventions.

User Input

text
$ARGUMENTS

Consider the user input before proceeding (if not empty). The input may specify files, a PR number, a branch, or a focus area.

Execution Steps

1. Load Review Context

Read all of the following files to build your review context. Do not skip any.

  1. CLAUDE.md (master project instructions)
  2. specs/standards/backend/conventions.spec.md (Go backend, Gin, K8s integration)
  3. specs/standards/frontend/conventions.spec.md (NextJS, Shadcn UI, React Query)
  4. specs/standards/security/security.spec.md (auth, RBAC, token handling, container security)
  5. specs/standards/backend/k8s-client.spec.md (user token vs service account)
  6. specs/standards/backend/error-handling.spec.md (consistent error patterns)
  7. specs/standards/frontend/react-query.spec.md (data fetching patterns)
  8. specs/standards/control-plane/conventions.spec.md (K8s operator, reconciliation, OwnerReferences)
2. Identify Changes to Review

Determine the scope based on user input:

  • If a PR number is provided: Use gh pr diff <number> to get the diff
  • If files/paths are provided: Review those specific files
  • If a branch is provided: Diff against main
  • If no input: Review all uncommitted changes (git diff + git diff --cached)
3. Perform Review

Evaluate every changed file against the loaded standards. Apply ALL relevant checks.

Review Axes
  1. Code Quality — Does it follow CLAUDE.md patterns? Naming conventions?
  2. Security — User token auth (GetK8sClientsForRequest), RBAC checks, token redaction, input validation, SecurityContext on Job pods, no secrets in code
  3. Performance — Unnecessary re-renders, missing query key parameters, N+1 queries, unbounded list operations
  4. Testing — Adequate coverage for new functionality? Tests follow existing patterns?
  5. Architecture — Follows project structure? Correct layer separation?
  6. Error Handling — No panic(), no silent failures, wrapped errors with context, generic user messages with detailed server logs
Backend-Specific Checks (Go)
  • All user operations use GetK8sClientsForRequest, never service account fallback
  • No tokens in logs (use len(token))
  • Type-safe unstructured access (unstructured.NestedMap, not direct assertions)
  • No panic() in production code
  • Errors wrapped with fmt.Errorf("context: %w", err)
  • errors.IsNotFound handled for 404 scenarios
  • OwnerReferences set on child resources (Jobs, Secrets, PVCs)
Frontend-Specific Checks (TypeScript/React)
  • Zero any types (use proper types or unknown)
  • Shadcn UI components only (no custom buttons, inputs, dialogs)
  • React Query for all data operations (no manual fetch() in components)
  • type preferred over interface
  • Single-use components colocated with their page
  • Loading and error states handled
  • Query keys include all relevant parameters
Show full SKILL.md (226 more words)Show less
Security Checks (All Components)
  • RBAC check performed before resource access
  • No tokens or secrets in logs or error messages
  • Input validated (K8s DNS labels, URL parsing)
  • Log injection prevented (no raw newlines in logged user input)
  • Generic error messages to users, detailed logs server-side
  • Container SecurityContext: AllowPrivilegeEscalation: false, Drop: ALL
4. Classify Findings by Severity
  • Blocker — Must fix before merge. Security vulnerabilities, data loss risk, service account misuse, token leaks
  • Critical — Should fix before merge. RBAC bypasses, missing error handling, any types, panic() in handlers
  • Major — Important to address. Architecture violations, missing tests, performance concerns
  • Minor — Nice-to-have. Style improvements, documentation gaps
5. Produce Review Report
markdown
# Claude Code Review

## Summary
[1-3 sentence overview]

## Findings

### Blocker
[Must fix — or "None"]

### Critical
[Should fix — or "None"]

### Major
[Important — or "None"]

### Minor
[Nice-to-have — or "None"]

## Positive Highlights
[Things done well — always include at least one]

## Recommendations
[Prioritized action items]

For each issue, include: file path and line number, what the problem is, which standard it violates, suggested fix.

When to Use This vs Individual Agents

  • /amber-review: Comprehensive single-session review across all components. Best for pre-merge quality gates.
  • Individual agents (backend-review, frontend-review, operator-review, runner-review, security-review): Specialized checks for a single component. Best for focused work on one area or ongoing automated checks.
  • /align: Codebase-wide convention scoring. Best for periodic health checks.

Operating Principles

  • Be stringent: This is a quality gate, not a rubber stamp.
  • Be specific: Reference exact file:line, exact standard, exact fix.
  • Be fair: Always acknowledge what was done well.
  • No false positives: Only flag issues backed by loaded standards.
  • Existing code is not in scope: Only review changed/added lines.

© ambient-code, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file in skills/amber-review of ambient-code/platform.

  • SKILL.md
  • evals/evals.json

Open the folder on GitHubat commit e15afd3

Compare with similar skills

Amber Review next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Amber Review compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Amber Review this skillambient-code/platform131—~1.4kAutomated safety check: PassMIT
Grix Code Reviewaskie/grix153—~799Automated safety check: PassCustom licence
NIC Code Reviewnginx/kubernetes-ingress5.1k—~5.9kAutomated safety check: WarnApache-2.0
PR Babysitteropeninterpreter/openinterpreter69k3 repos~4.2kAutomated safety check: PassApache-2.0
Understand Diff AnalysisEgonex-AI/Understand-Anything85k1 repos~1.4kAutomated safety check: PassMIT
WooCommerce Code Reviewwoocommerce/woocommerce11k3 repos~1.1kAutomated safety check: PassCustom licence

Similar skills

  • Audit Grix diffs and pull requests for correctness, regressions, security, lifecycle safety, and cross-component contract consistency.

    153 GitHub stars~799 tokensUpdated 6 days ago
    DevelopmentAuto-check passed
  • NIC Code Review

    nginx/kubernetes-ingress

    Reviews pull requests for the NGINX Kubernetes Ingress Controller with a fixed workflow, strict comment guardrails and a set output format, leaving repo detail to sibling skills.

    5.1k GitHub stars~5.9k tokensUpdated yesterday
    DevelopmentAuto-check: warnings
  • PR Babysitter

    openinterpreter/openinterpreter

    Watches an open GitHub pull request until it merges, handling review comments, diagnosing CI failures and retrying flaky checks along the way.

    69k GitHub starsUsed in 3 repos~4.2k tokens
    DevelopmentAuto-check passed
  • Understand Diff Analysis

    Egonex-AI/Understand-Anything

    Reads your git changes or a pull request against a prebuilt knowledge graph of the project to explain what changed, which components are affected and what is risky.

    85k GitHub starsUsed in 1 repo~1.4k tokens
    DevelopmentAuto-check passed
  • WooCommerce Code Review

    woocommerce/woocommerce

    Reviews WooCommerce code changes against the project's standards, flagging backend PHP architecture, naming, documentation, data integrity and testing violations.

    11k GitHub starsUsed in 3 repos~1.1k tokens
    DevelopmentAuto-check passed
  • Open Code Review CLI

    alibaba/open-code-review

    Runs the ocr command-line tool to review Git changes, a commit or a branch comparison with an AI model, returning line-level comments and optionally applying fixes.

    44k GitHub stars~3.1k tokensUpdated 2 days ago
    DevelopmentAuto-check passed

More from ambient-code/platform

All 18 skills in this repo
  • Align

    ambient-code/platform

    Run a convention alignment check across the codebase to measure adherence to documented standards.

    131 GitHub stars~754 tokensUpdated yesterday
    Auto-check passed
  • Cypress Demo

    ambient-code/platform

    Create a Cypress-based video demo for a feature branch with cursor, click effects, and captions.

    131 GitHub stars~879 tokensUpdated yesterday
    Auto-check: notes
  • Deploy

    ambient-code/platform

    Deploy, update manifests, and troubleshoot the ambient-ui component.

    131 GitHub stars~2.6k tokensUpdated yesterday
    Auto-check passed
  • Discover

    ambient-code/platform

    Discover domain-specific skills and context before starting any coding or spec work.

    131 GitHub stars~747 tokensUpdated yesterday
    Auto-check passed
  • Frontend Development

    ambient-code/platform

    Required context for all frontend work. An agent skill from ambient-code/platform.

    131 GitHub stars~525 tokensUpdated yesterday
    Auto-check passed
  • Gerrit Create

    ambient-code/platform

    A skill your agent uses when creating or updating Gerrit changes — pushing code for review, amending patch sets, setting reviewers and topics.

    131 GitHub stars~662 tokensUpdated yesterday
    Auto-check passed

Works with

Categories

Questions about Amber Review

What does Amber Review do?

Perform a comprehensive code review using repository-specific standards. Amber Review is an agent skill from ambient-code/platform. Perform a comprehensive code review using repository-specific standards.

When should I use Amber Review?

Amber Review fits situations like: reviewing code changes; checking PR quality; auditing convention compliance; validating changes before merge.

How do I install Amber Review in Claude Code?

Run `npx skills add ambient-code/platform --skill amber-review -a claude-code`. Or copy the skill folder (skills/amber-review in ambient-code/platform) into .claude/skills/amber-review in your project. Claude Code loads it when a task matches its description.

How do I install Amber Review in Codex?

Run `npx skills add ambient-code/platform --skill amber-review -a codex`. Or copy the skill folder (skills/amber-review in ambient-code/platform) into .agents/skills/amber-review in your project. Codex loads it when a task matches its description.

Can I use Amber Review in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add ambient-code/platform --skill amber-review -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/amber-review, .gemini/skills/amber-review, .github/skills/amber-review and .opencode/skills/amber-review in your project.

What does Amber Review need to run?

Going by SKILL.md and its folder, Amber Review needs the command-line tools its instructions call (git and gh).

Does Amber Review access the network?

SKILL.md contains no URLs. Its commands use git and gh, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Amber Review safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Amber Review use?

Amber Review is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Amber Review use?

About 1.4k tokens (SKILL.md is roughly 5.7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Amber Review?

Skills that share tags, products or a category with Amber Review: Grix Code Review (askie/grix, 153 stars), NIC Code Review (nginx/kubernetes-ingress, 5.1k stars), PR Babysitter (openinterpreter/openinterpreter, 69k stars) and Understand Diff Analysis (Egonex-AI/Understand-Anything, 85k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Amber Review?

ambient-code (a GitHub organization) maintains it in ambient-code/platform, which has 131 GitHub stars. The repository holds 18 skills in this directory. The repository was last updated on October 6, 2026.

Source: ambient-code/platform on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.