Code Review Checklist
shareAI-lab/learn-claude-code
Reviews code against a five-part checklist covering security, correctness, performance, maintainability and testing, and reports findings in a fixed format.
Delegate a coding task to the Grok Build CLI as a background implementer, then review its diff and land it yourself.
$ npx skills add amElnagdy/delegate-skills --skill grok-delegate -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install amElnagdy/delegate-skills grok-delegate --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/amElnagdy/delegate-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/grok-delegate .claude/skills/grok-delegate && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "grok-delegate" agent skill from https://github.com/amElnagdy/delegate-skills/tree/master/skills/grok-delegate into .claude/skills/grok-delegate/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "grok-delegate", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/amElnagdy/delegate-skills/tree/master/skills/grok-delegateType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add amElnagdy/delegate-skills --skill grok-delegate -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install amElnagdy/delegate-skills grok-delegate --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/amElnagdy/delegate-skills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/grok-delegate .agents/skills/grok-delegate && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "grok-delegate" agent skill from https://github.com/amElnagdy/delegate-skills/tree/master/skills/grok-delegate into .agents/skills/grok-delegate/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "grok-delegate", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add amElnagdy/delegate-skills --skill grok-delegate -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install amElnagdy/delegate-skills grok-delegate --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/amElnagdy/delegate-skills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/grok-delegate .cursor/skills/grok-delegate && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "grok-delegate" agent skill from https://github.com/amElnagdy/delegate-skills/tree/master/skills/grok-delegate into .cursor/skills/grok-delegate/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "grok-delegate", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/amElnagdy/delegate-skills.git --path skills/grok-delegate--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add amElnagdy/delegate-skills --skill grok-delegate -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install amElnagdy/delegate-skills grok-delegate --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/amElnagdy/delegate-skills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/grok-delegate .gemini/skills/grok-delegate && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "grok-delegate" agent skill from https://github.com/amElnagdy/delegate-skills/tree/master/skills/grok-delegate into .gemini/skills/grok-delegate/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "grok-delegate", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install amElnagdy/delegate-skills grok-delegateInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add amElnagdy/delegate-skills --skill grok-delegate -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/amElnagdy/delegate-skills.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/grok-delegate .github/skills/grok-delegate && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "grok-delegate" agent skill from https://github.com/amElnagdy/delegate-skills/tree/master/skills/grok-delegate into .github/skills/grok-delegate/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "grok-delegate", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add amElnagdy/delegate-skills --skill grok-delegate -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install amElnagdy/delegate-skills grok-delegate --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/amElnagdy/delegate-skills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/grok-delegate .opencode/skills/grok-delegate && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "grok-delegate" agent skill from https://github.com/amElnagdy/delegate-skills/tree/master/skills/grok-delegate into .opencode/skills/grok-delegate/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "grok-delegate", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
grok-delegateDelegate a coding task to the Grok Build CLI as a background implementer, then review its diff and land it yourself.
Grok Delegate is an agent skill from amElnagdy/delegate-skills. Delegate a coding task to the Grok Build CLI as a background implementer, then review its diff and land it yourself. Use this whenever the user wants to hand implementation work to Grok — phrasings like "have Grok do X", "delegate this to Grok", "run it through Grok", "use Grok Build to implement/fix/refactor", or "have grok CLI do this" — or to run a queue of coding tasks through Grok while staying the reviewer. Prefer it when the user will review the diff and commit it themselves. DO NOT USE for tasks small…
Its SKILL.md is about 2.6k tokens, which your agent loads only when the skill is triggered. The skill folder holds 7 other files, including scripts and reference files (for example `references/dispatch-and-poll.md`, `references/multi-task-queues.md` and `references/review-and-land.md`). Compatibility notes: Requires the grok CLI (Grok Build) installed and authenticated (grok login, or XAIAPIKEY; beta access needs an eligible xAI subscription), Node 18+, and git…
It sits in Development, covering Code review. It works with Git. The repository describes itself as: Delegate a coding task to a separate coding agent CLI, review the diff, land the commit yourself — one per implementer. The licence is MIT.
5 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 8ef0210. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Ships 1 file in scripts/ (JavaScript), which the agent can run.
Shell commands in SKILL.md call:
nodenpmFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use npm, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names these keys or tokens, usually read from environment variables:
XAI_API_KEYFrom names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Requires the `grok` CLI (Grok Build) installed and authenticated (`grok login`, or `XAI_API_KEY`; beta access needs an eligible xAI subscription), Node 18+, and git. The orchestrating agent must be able to run shell commands and read files. Shell examples assume bash/zsh (macOS/Linux, or Git Bash/WSL on Windows).
From compatibility in the SKILL.md frontmatter.
Grok Delegate loads about 2.6k tokens when it runs, and up to ~10k if it reads all its reference files. Until then it costs about 155 tokens; SKILL.md has 1,241 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.
The full file from amElnagdy/delegate-skills at commit 8ef0210, republished under its MIT licence (© amElnagdy). 1,241 words, ~2,599 tokens.
.claude/skills/grok-delegate/SKILL.md (or your agent's skills folder). This skill also uses 5 other files; get the full folder from GitHub.For a trusted repository rejected by Git's ownership check, the relay supports
--trust-git-root <exact-worktree-root>. This opt-in affects only relay Git checks, without persistent
Git config or Grok permission changes. See dispatch and poll.
You are the orchestrator. This skill lets you hand a bounded coding task to a separate
implementer — the Grok Build CLI (grok) — then review what it produced and land it yourself. You
write the brief and own the judgment; Grok does the typing under an explicit autonomy profile; you
verify and commit.
Nothing here is specific to one orchestrating agent. The loop needs only the ability to run a shell command and read a file, so it works the same whether you are Claude Code, Cursor, OpenCode with a selected model, or any comparable agent. (It is designed for Claude Code and Cursor; treat other orchestrators as designed-for, not yet proven.)
grok CLI is not installed, not authenticated, or the account lacks Grok Build beta access.grok version succeeds. If not, install on any platform with
npm i -g @xai-official/grok (or use the installer from xAI's official Grok CLI docs) and
authenticate (grok login, or grok login --device-auth on headless hosts, or set
XAI_API_KEY).grok is on PATH. command -v grok shows the active binary and grok version
its version — the relay records the version it ran into result.json, so a stale binary is visible
after the fact.--cd at) the target git repository.Run these five steps per task. Steps 1, 4, and 5 are your judgment; 2 and 3 are mechanical.
Grok sees only the text you send — no orchestrator chat history, no shared context. Everything the task needs goes in the brief: the goal, the current state, what to change, what to leave untouched, the project's actual gate commands (discover them from the repo's CLAUDE.md/AGENTS.md/Makefile — do not assume), and a report contract. Tell Grok it will not commit (you will). Keep one task per brief. Full guidance and a template: references/writing-the-brief.md.
Send the brief to Grok with the bundled helper. It wraps grok -p, captures the run, and writes a
structured result.json — so your only job is "run a command, read a file." (<skill-dir> below is
this skill's installed directory — the folder containing this SKILL.md, i.e. the directory you loaded
the skill from. Claude Code prints it as "Base directory for this skill" when the skill loads; on other
orchestrators use that same directory — if unsure where it landed, run
find ~ -name relay.mjs -path '*grok-delegate*' and substitute the directory above it.)
node "<skill-dir>/scripts/relay.mjs" --brief brief.txt --cd /path/to/repo
# read-only (review/diagnosis; best-effort — verify touchedFiles): add --read-only
# continue the previous Grok session: add --resume-last (send only the delta brief)
# hard time limit (watchdog): add --timeout 2h (default: off; implementation runs routinely need 1-2h)
# see all options: node .../relay.mjs --helpThe helper defaults to a write-capable (workspace-write) autonomy profile — --always-approve plus
--sandbox workspace — and writes its artifacts to a temp dir, so the repo under review stays clean.
It never commits — see step 5. Mechanics, flags, and the result.json shape:
references/dispatch-and-poll.md.
The helper blocks until Grok finishes, so back it with whatever your orchestrator offers and resume when it returns:
run_in_background: true; you are notified on completion.… & in bash/zsh (including Git Bash/WSL), or your shell's equivalent (Start-Job
in PowerShell, start /b in cmd). The run is done when result.json exists with a status. (A
pre-run usage error — bad args or an empty brief — instead exits with code 2 and a stderr message and
writes no result file, so check the exit code too. A missing grok binary exits 127 but does write
a result.json with status grok_unavailable.)Do not trust progress trackers over reality: a run is finished when result.json is written and the
process has exited. Read the working tree, not a status line. The implementer's full report is
the finalMessage field in result.json (also printed in full on stdout between the report markers).
Grok's result.json includes its own summary and gate claims. Re-verify, don't accept:
touchedFiles in the result is your starting point.guard-skills) — this skill produces the work; those skills judge it.Full checklist: references/review-and-land.md.
The orchestrator commits. Only after the gates pass and the diff holds:
--resume-last (don't restate the whole task) and
review again.Grok's default permission mode is ask, which blocks on approval prompts in a headless pipe. The
relay therefore always sets autonomy explicitly:
| Relay flag | What Grok gets | Use when |
|---|---|---|
| (default) | --always-approve --sandbox workspace | Normal implementation — writes scoped to the working tree |
--read-only | --sandbox read-only --always-approve | Review / diagnosis — kernel-enforced sandbox, not total (see caveat below) |
--full-access | --always-approve --sandbox off | Explicit opt-in when the task needs unrestricted tools |
--always-approve alone would approve all tools (writes, shell, network) — closer to unrestricted
than to a workspace-scoped write. Pairing it with --sandbox workspace is what keeps the default
safe. Reach for --full-access only when the human asks for it.
--read-only is kernel-enforced, not total. On grok 1.0.25 the read-only sandbox (Seatbelt on
macOS, Landlock on Linux) denies grok's own write/search_replace tools and shell redirects with
EPERM, so --always-approve only auto-approves tools inside the sandbox. The profile is not
total, though: it still permits writes to /tmp, /var/tmp and ~/.grok/, so a repo under one of
those paths is not protected, and on macOS it does not restrict child-process network. Always
confirm touchedFiles afterward; treat the diff, not the flag, as the guarantee. The relay
automates a reporting tripwire: it compares parsed git porcelain and fingerprints the working-tree
identity and index entries of Git-visible paths that were already dirty. readOnlyViolation is true
when either signal proves a change, false when coverage is complete and detects none, and null when
coverage is incomplete. Ignored paths, submodule internals, perfect restores, and attribution of
concurrent changes remain outside it, so the diff
review stays the guarantee.
Delegation is something the human opts into. Once they have ("run this queue", "proceed"), committing verified, gate-passing work is the agreed contract — that is the whole point. Two limits on that mandate: surface, don't absorb (report Grok's design decisions, defensible-but-unasked turns, and non-blocking nitpicks rather than silently keeping them) and stop for scope changes (if correct completion needs going beyond the brief, ask — don't expand the mandate yourself). The full treatment is in references/review-and-land.md.
relay.mjs flags, the
result.json contract, backgrounding per orchestrator, and recovery when a run misbehaves.--resume-last.© amElnagdy, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 5 other files (scripts, references) in skills/grok-delegate of amElnagdy/delegate-skills.
Open the folder on GitHubat commit 8ef0210
Grok Delegate next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Grok Delegate this skillamElnagdy/delegate-skills | 2.3k | — | ~2.6k | Automated safety check: Pass | MIT | |
| Code Review ChecklistshareAI-lab/learn-claude-code | 78k | 5 repos | ~1.1k | Automated safety check: Pass | MIT | |
| Open Code Review CLIalibaba/open-code-review | 45k | — | ~3.1k | Automated safety check: Pass | Apache-2.0 | |
| Understand Diff AnalysisEgonex-AI/Understand-Anything | 86k | — | ~1.4k | Automated safety check: Pass | MIT | |
| Open Code Review Delegatealibaba/open-code-review | 45k | — | ~2k | Automated safety check: Pass | Apache-2.0 | |
| Code Reviewflutter/flutter | 179k | — | ~1.4k | Automated safety check: Pass | BSD-3-Clause |
shareAI-lab/learn-claude-code
Reviews code against a five-part checklist covering security, correctness, performance, maintainability and testing, and reports findings in a fixed format.
alibaba/open-code-review
Runs the ocr command-line tool to review Git changes, a commit or a branch comparison with an AI model, returning line-level comments and optionally applying fixes.
Egonex-AI/Understand-Anything
Reads your git changes or a pull request against a prebuilt knowledge graph of the project to explain what changed, which components are affected and what is risky.
alibaba/open-code-review
Has the host agent do the code review itself while the ocr CLI handles file selection and rule lookup, covering workspace changes, branch ranges or single commits.
flutter/flutter
Performs a comprehensive, multi-step code review of pull requests or local code changes, using iterative refinement (generation, critique, synthesis) to ensure high-quality, actionable feedback.
prisma/orm
Fetches a pull request's canonical review state as JSON, validates it, and renders markdown, a text summary and triage target files from it using bundled scripts.
amElnagdy/delegate-skills
Delegate a coding task to Aider (aider) as a background implementer, then review its diff and land it yourself.
amElnagdy/delegate-skills
Delegate a coding task to the Qoder CLI (qodercli) as a background implementer, then review its diff and land it yourself.
amElnagdy/delegate-skills
Delegate a coding task to the Warp Agent CLI (oz) as a background implementer, then review its diff and land it yourself.
amElnagdy/delegate-skills
Delegate a coding task to the Google Antigravity CLI (agy) as a background implementer, then review its diff and land it yourself.
amElnagdy/delegate-skills
Delegate a coding task to a separate Claude Code CLI process or another Claude session as an implementer, then review its diff and land it yourself.
amElnagdy/delegate-skills
Delegate a coding task to the Cline coding agent CLI (cline) as a background implementer, then review its diff and land it yourself.
Works with
Categories
Delegate a coding task to the Grok Build CLI as a background implementer, then review its diff and land it yourself. Grok Delegate is an agent skill from amElnagdy/delegate-skills. Delegate a coding task to the Grok Build CLI as a background implementer, then review its diff and land it yourself.
Grok Delegate fits situations like: wants to hand implementation work to Grok — phrasings like have Grok do X; delegate this to Grok; run it through Grok; use Grok Build to implement/fix/refactor.
Run `npx skills add amElnagdy/delegate-skills --skill grok-delegate -a claude-code`. Or copy the skill folder (skills/grok-delegate in amElnagdy/delegate-skills) into .claude/skills/grok-delegate in your project. Claude Code loads it when a task matches its description.
Run `npx skills add amElnagdy/delegate-skills --skill grok-delegate -a codex`. Or copy the skill folder (skills/grok-delegate in amElnagdy/delegate-skills) into .agents/skills/grok-delegate in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add amElnagdy/delegate-skills --skill grok-delegate -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/grok-delegate, .gemini/skills/grok-delegate, .github/skills/grok-delegate and .opencode/skills/grok-delegate in your project.
Going by SKILL.md and its folder, Grok Delegate needs JavaScript for the scripts in its folder, the command-line tools its instructions call (node and npm) and credentials named XAI_API_KEY. Our summary lists: Node.js; A credential in XAI_API_KEY. Compatibility (from SKILL.md): Requires the `grok` CLI (Grok Build) installed and authenticated (`grok login`, or `XAI_API_KEY`; beta access needs an eligible xAI subscription), Node 18+, and git. The orchestrating agent must be able to run shell commands and read files. Shell examples assume bash/zsh (macOS/Linux, or Git Bash/WSL on Windows)..
SKILL.md contains no URLs. Its commands use npm, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.
Grok Delegate is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.
About 2.6k tokens (SKILL.md is roughly 10k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 7.6k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Grok Delegate: Code Review Checklist (shareAI-lab/learn-claude-code, 78k stars), Open Code Review CLI (alibaba/open-code-review, 45k stars), Understand Diff Analysis (Egonex-AI/Understand-Anything, 86k stars) and Open Code Review Delegate (alibaba/open-code-review, 45k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
amElnagdy (a GitHub user) maintains it in amElnagdy/delegate-skills, which has 2,336 GitHub stars. The repository holds 18 skills in this directory. The repository was last updated on October 7, 2026.
Source: amElnagdy/delegate-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.