Agent skill

Review Changes

by appclawhq in appclawhq/AppClaw

Review code changes in the AppClaw repo for correctness, CLI/VSCode extension consistency, and YAML flow parsing regressions.

Apache-2.0Auto-check passedDevelopment

Install Review Changes

skills CLI
$ npx skills add appclawhq/AppClaw --skill review-changes -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install appclawhq/AppClaw review-changes --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/appclawhq/AppClaw.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/review-changes .claude/skills/review-changes && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
review-changes
GitHub stars
116
Token cost
~1.4k tokens
SKILL.md length
518 words
Files
2
Skills in repo
4
Repo updated
First seen
Licence
Apache-2.0

At a glance

Review code changes in the AppClaw repo for correctness, CLI/VSCode extension consistency, and YAML flow parsing regressions.

  • Works in 5 steps: Identify what changed → Cross-surface consistency check → YAML flow parsing validation → …
  • The user says review my changes
  • SKILL.md covers Why this matters, Review process and Important edge cases
  • Calls npm, git and npx

What it does

Review Changes is an agent skill from appclawhq/AppClaw. Review code changes in the AppClaw repo for correctness, CLI/VSCode extension consistency, and YAML flow parsing regressions. Use this skill whenever the user says "review my changes", "check my changes", "validate changes", "does this break anything", "review the diff", or any variation of wanting to verify that recent code modifications haven't broken the CLI, VSCode extension, or YAML flow parsing. Also use when the user is about to commit or push and wants a sanity check.

Its SKILL.md is about 1.4k tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files (for example `evals/evals.json`).

It sits in Development, covering Code review. It works with Visual Studio Code and Model Context Protocol. The repository describes itself as: AI-powered mobile automation agent — describe what you want in plain English, AppClaw reads the screen, reasons, and acts. LLM-agnostic, open-source, zero telemetry. The licence is Apache-2.0.

When your agent uses it

  • The user says review my changes
  • Check my changes
  • Validate changes
  • Does this break anything

Example prompts

  • “review my changes”
  • “check my changes”
  • “validate changes”
  • “/review-changes”

Requirements

  • Node.js

Workflow steps

5 steps, taken from the step headings in SKILL.md.

  1. Identify what changed
  2. Cross-surface consistency check
  3. YAML flow parsing validation
  4. TypeScript compilation check
  5. Summary report

What it can do on your machine

Read from SKILL.md and the folder at commit 9bbc6f1. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • npm
    • git
    • npx

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use npm, git and npx, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Review Changes loads about 1.4k tokens when it runs. Until then it costs about 124 tokens; SKILL.md has 518 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~124
When it runs · the whole SKILL.md, loaded when a task matches
~1.4k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from appclawhq/AppClaw at commit 9bbc6f1, republished under its Apache-2.0 licence (© appclawhq). 518 words, ~1,432 tokens.

Download SKILL.mdSave it as .claude/skills/review-changes/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
review-changes
description
Review code changes in the AppClaw repo for correctness, CLI/VSCode extension consistency, and YAML flow parsing regressions. Use this skill whenever the user says "review my changes", "check my changes", "validate changes", "does this break anything", "review the diff", or any variation of wanting to verify that recent code modifications haven't broken the CLI, VSCode extension, or YAML flow parsing. Also use when the user is about to commit or push and wants a sanity check.

Review Changes

This skill reviews code changes in AppClaw to catch breakage across two surfaces (CLI and VSCode extension) and validate YAML flow parsing. AppClaw has a fragile contract between these surfaces — the CLI emits NDJSON events that the extension parses, and changes to either side can silently break the other.

Why this matters

AppClaw has three main failure modes when code changes:

  1. CLI ↔ Extension drift — The CLI's src/json-emitter.ts defines event types. The extension's vscode-extension/src/bridge.ts mirrors those types manually. When someone adds a field to one side, the other silently ignores it, causing subtle bugs.
  2. YAML flow parsing regressions — Natural language parsing in src/flow/natural-line.ts uses regex patterns that interact in surprising ways. A change to one regex can break another flow format.
  3. Config drift — The CLI reads env vars via src/config.ts (Zod schema). The extension maps VS Code settings to env vars in bridge.ts:getEnvFromSettings(). New config options added to one side may not appear in the other.

Review process

When triggered, perform these checks in order:

Step 1: Identify what changed

Run git diff (staged + unstaged) and git diff --cached to see all pending changes. Categorize the changed files:

  • Shared contract files (high risk): src/json-emitter.ts, src/flow/types.ts, src/config.ts
  • CLI-side flow files (medium risk): src/flow/natural-line.ts, src/flow/parse-yaml-flow.ts, src/flow/run-yaml-flow.ts, src/flow/variable-resolver.ts, src/flow/llm-parser.ts
  • Extension files (medium risk): anything under vscode-extension/src/
  • Other files (lower risk): agent, perception, vision, etc.
Step 2: Cross-surface consistency check

If any shared contract files changed, or if extension/CLI files changed:

Event type check:

  • Read src/json-emitter.ts (the JsonEvent type union)
  • Read vscode-extension/src/bridge.ts (the AppclawEvent type and individual event interfaces)
  • Compare every event variant — field names, types, optional vs required
  • Flag any mismatch (missing fields, type differences, new events not mirrored)

Config mapping check:

  • Read src/config.ts (the Zod schema for env vars)
  • Read the getEnvFromSettings() function in vscode-extension/src/bridge.ts
  • Read vscode-extension/package.json contributes.configuration section
  • Verify every env var the CLI reads has a corresponding VS Code setting + mapping

Report format:

## Cross-Surface Consistency

### Event Types
- [OK] connected — fields match
- [DRIFT] flow_done — CLI has `failedPhase?: string` and `phaseResults?: unknown[]`, extension bridge is missing both
- [NEW] screen — not handled in extension's formatEvent (returns null)

### Config Mapping
- [OK] LLM_PROVIDER — mapped via llmProvider setting
- [MISSING] NEW_CONFIG_VAR — added to CLI config but no VS Code setting exists
Show full SKILL.md (201 more words)Show less
Step 3: YAML flow parsing validation

Run the test suites to verify parsing still works:

bash
# Run vitest for flow parsing, variable resolution, and cross-surface validation
cd /Users/saikrishna/Documents/git/appclaw && npm test

# Run the integration verification script
npx tsx tests/verify-parsing.ts

If tests fail, report which tests failed and why. If tests pass, confirm that.

Then, if natural-line.ts or parse-yaml-flow.ts changed, do an additional manual audit:

  • Read the changed regex patterns
  • Check each example YAML flow file against the parser mentally:
    • examples/flows/google-search.yaml (legacy structured: tap:, type:, done:)
    • examples/flows/vodqa-natural.yaml (natural language flat)
    • examples/flows/settings-wifi-on.yaml (structured with comments)
    • examples/flows/youtube-search-appium3.yaml (mixed natural + structured)
    • tests/flows/youtube-phased.yaml (phased with variables)
    • flows/youtube.yaml (legacy flat with phases)
  • Flag any step that would now parse differently or fail
Step 4: TypeScript compilation check
bash
cd /Users/saikrishna/Documents/git/appclaw && npm run typecheck

Report any type errors, especially ones related to the changed files.

Step 5: Summary report

Present findings as a structured report:

# Change Review Summary

## Files Changed
- list of files with risk level

## Cross-Surface Issues
- any drift or mismatches found (or "None found")

## YAML Parsing
- test results (pass/fail counts)
- any regressions identified

## Type Check
- clean or errors found

## Recommendations
- specific fixes needed, if any

Be direct — if everything looks good, say so briefly. If there are issues, be specific about what's wrong and suggest the fix.

Important edge cases

  • If the user only changed files that don't affect the CLI/extension contract (e.g., only src/agent/ files), skip the cross-surface check and say so.
  • Tests use vitest (npm test). The cross-surface contract test (tests/flow/cross-surface.test.ts) automatically validates CLI ↔ extension event parity.
  • The extension has its own build step (cd vscode-extension && npm run compile). If extension files changed, run that too.

© appclawhq, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file in .agents/skills/review-changes of appclawhq/AppClaw.

  • SKILL.md
  • evals/evals.json

Open the folder on GitHubat commit 9bbc6f1

Compare with similar skills

Review Changes next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Review Changes compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Review Changes this skillappclawhq/AppClaw116—~1.4kAutomated safety check: PassApache-2.0
Graph-Based Change Reviewtirth8205/code-review-graph32k1 repos~331Automated safety check: PassMIT
YugabyteDB Backport Reviewyugabyte/yugabyte-db11k—~2.5kAutomated safety check: PassCustom licence
Liveagent Code ReviewStack-Cairn/LiveAgent2.2k—~2kAutomated safety check: PassMIT
Code Review Graph Navigatorhandsontable/handsontable22k—~939Automated safety check: PassCustom licence
Code Reviewnteract/semiotic2.7k—~1.5kAutomated safety check: PassApache-2.0

Similar skills

  • Graph-Based Change Review

    tirth8205/code-review-graph

    Reviews a change set using a code knowledge graph for risk scores, blast radius and test gaps, and ends with a merge recommendation.

    32k GitHub starsUsed in 1 repo~331 tokens
    DevelopmentAuto-check passed
  • YugabyteDB Backport Review

    yugabyte/yugabyte-db

    Checks a YugabyteDB backport revision on Phorge against the original diff it was ported from and flags differences, tracing unexplained code back to master.

    11k GitHub stars~2.5k tokensUpdated today
    DevelopmentAuto-check passed
  • Liveagent Code Review

    Stack-Cairn/LiveAgent

    Review an open GitHub pull request or the current local branch and working tree with parallel, independent reviewers and evidence-based validation.

    2.2k GitHub stars~2k tokensUpdated today
    DevelopmentAuto-check passed
  • Code Review Graph Navigator

    handsontable/handsontable

    Queries a pre-built, Tree-sitter-based code graph of the whole monorepo instead of grepping call chains, for exploring, debugging, refactoring or reviewing code.

    22k GitHub stars~939 tokensUpdated today
    DevelopmentAuto-check passed
  • Code Review

    nteract/semiotic

    Review Semiotic pull requests for behavioral bugs, regressions, contract drift, and missing evidence.

    2.7k GitHub stars~1.5k tokensUpdated today
    DevelopmentAuto-check passed
  • Roam

    Cranot/roam-code

    Codebase comprehension via roam-code CLI. An agent skill from Cranot/roam-code.

    517 GitHub stars~2.4k tokensUpdated 5 days ago
    DevelopmentAuto-check passed

More from appclawhq/AppClaw

  • Generate Appclaw Flow

    appclawhq/AppClaw

    Generate YAML flow files for AppClaw mobile automation. An agent skill from appclawhq/AppClaw.

    116 GitHub stars~3.4k tokensUpdated 1 mo ago
    Auto-check: notes
  • Use Appclaw CLI

    appclawhq/AppClaw

    Use the AppClaw CLI to run YAML flows, start the interactive TUI shell, explore apps, record/replay sessions, configure devices, and troubleshoot.

    116 GitHub stars~4.6k tokensUpdated 1 mo ago
    Auto-check: notes
  • Use Appclaw Agent CLI

    appclawhq/AppClaw

    Use the appclaw-agent CLI to directly open, inspect, and interact with a mobile app via terminal commands — without writing a YAML flow.

    116 GitHub stars~775 tokensUpdated 1 mo ago
    Auto-check passed

Categories

Questions about Review Changes

What does Review Changes do?

Review code changes in the AppClaw repo for correctness, CLI/VSCode extension consistency, and YAML flow parsing regressions. Review Changes is an agent skill from appclawhq/AppClaw. Review code changes in the AppClaw repo for correctness, CLI/VSCode extension consistency, and YAML flow parsing regressions.

When should I use Review Changes?

Review Changes fits situations like: the user says review my changes; check my changes; validate changes; does this break anything.

How do I install Review Changes in Claude Code?

Run `npx skills add appclawhq/AppClaw --skill review-changes -a claude-code`. Or copy the skill folder (.agents/skills/review-changes in appclawhq/AppClaw) into .claude/skills/review-changes in your project. Claude Code loads it when a task matches its description.

How do I install Review Changes in Codex?

Run `npx skills add appclawhq/AppClaw --skill review-changes -a codex`. Or copy the skill folder (.agents/skills/review-changes in appclawhq/AppClaw) into .agents/skills/review-changes in your project. Codex loads it when a task matches its description.

Can I use Review Changes in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add appclawhq/AppClaw --skill review-changes -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/review-changes, .gemini/skills/review-changes, .github/skills/review-changes and .opencode/skills/review-changes in your project.

What does Review Changes need to run?

Going by SKILL.md and its folder, Review Changes needs the command-line tools its instructions call (npm, git and npx). Our summary lists: Node.js.

Does Review Changes access the network?

SKILL.md contains no URLs. Its commands use npm, git and npx, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Review Changes safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Review Changes use?

Review Changes is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Review Changes use?

About 1.4k tokens (SKILL.md is roughly 5.7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Review Changes?

Skills that share tags, products or a category with Review Changes: Graph-Based Change Review (tirth8205/code-review-graph, 32k stars), YugabyteDB Backport Review (yugabyte/yugabyte-db, 11k stars), Liveagent Code Review (Stack-Cairn/LiveAgent, 2.2k stars) and Code Review Graph Navigator (handsontable/handsontable, 22k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Review Changes?

appclawhq (a GitHub organization) maintains it in appclawhq/AppClaw, which has 116 GitHub stars. The repository holds 4 skills in this directory. The repository was last updated on September 3, 2026.

Source: appclawhq/AppClaw on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.