Find Regression Risk
dotnet/maui
Checks a pull request for lines that undo a recent bug fix by comparing what the PR removes with what labeled bug-fix PRs added to the same files.
A skill your agent uses when the user asks to review changes, review a diff, sanity-check a PR before merge, or verify uncommitted work against Endstate's locked contracts and principles.
$ npx skills add Artexis10/endstate --skill review-endstate -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install Artexis10/endstate review-endstate --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/Artexis10/endstate.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/review-endstate .claude/skills/review-endstate && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "review-endstate" agent skill from https://github.com/Artexis10/endstate/tree/main/.claude/skills/review-endstate into .claude/skills/review-endstate/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "review-endstate", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/Artexis10/endstate/tree/main/.claude/skills/review-endstateType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add Artexis10/endstate --skill review-endstate -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install Artexis10/endstate review-endstate --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/Artexis10/endstate.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.claude/skills/review-endstate .agents/skills/review-endstate && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "review-endstate" agent skill from https://github.com/Artexis10/endstate/tree/main/.claude/skills/review-endstate into .agents/skills/review-endstate/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "review-endstate", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add Artexis10/endstate --skill review-endstate -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install Artexis10/endstate review-endstate --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/Artexis10/endstate.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.claude/skills/review-endstate .cursor/skills/review-endstate && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "review-endstate" agent skill from https://github.com/Artexis10/endstate/tree/main/.claude/skills/review-endstate into .cursor/skills/review-endstate/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "review-endstate", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/Artexis10/endstate.git --path .claude/skills/review-endstate--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add Artexis10/endstate --skill review-endstate -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install Artexis10/endstate review-endstate --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/Artexis10/endstate.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.claude/skills/review-endstate .gemini/skills/review-endstate && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "review-endstate" agent skill from https://github.com/Artexis10/endstate/tree/main/.claude/skills/review-endstate into .gemini/skills/review-endstate/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "review-endstate", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install Artexis10/endstate review-endstateInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add Artexis10/endstate --skill review-endstate -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/Artexis10/endstate.git skills-src && mkdir -p .github/skills && cp -r skills-src/.claude/skills/review-endstate .github/skills/review-endstate && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "review-endstate" agent skill from https://github.com/Artexis10/endstate/tree/main/.claude/skills/review-endstate into .github/skills/review-endstate/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "review-endstate", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add Artexis10/endstate --skill review-endstate -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install Artexis10/endstate review-endstate --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/Artexis10/endstate.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.claude/skills/review-endstate .opencode/skills/review-endstate && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "review-endstate" agent skill from https://github.com/Artexis10/endstate/tree/main/.claude/skills/review-endstate into .opencode/skills/review-endstate/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "review-endstate", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
review-endstateA skill your agent uses when the user asks to review changes, review a diff, sanity-check a PR before merge, or verify uncommitted work against Endstate's locked contracts and principles.
Review Endstate is an agent skill from Artexis10/endstate. Use when the user asks to review changes, review a diff, sanity-check a PR before merge, or verify uncommitted work against Endstate's locked contracts and principles. Trigger phrases include "review my changes", "review the diff", "sanity check this branch", "check against contracts", "review before PR". Repo-scoped to the Endstate engine.
Its SKILL.md is about 2.2k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Development, covering Code review. It works with PowerShell and Git. The repository describes itself as: Open-source engine behind Endstate: reinstall your apps and restore your settings on a fresh machine from one file. Windows via winget (Linux/macOS in progress). Go, Apache 2.0. The licence is Apache-2.0.
6 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 6f590e9. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
gitghFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use git and gh, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Review Endstate loads about 2.2k tokens when it runs. Until then it costs about 90 tokens; SKILL.md has 987 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from Artexis10/endstate at commit 6f590e9, republished under its Apache-2.0 licence (© Artexis10). 987 words, ~2,167 tokens.
.claude/skills/review-endstate/SKILL.md (or your agent's skills folder).A structured review of a diff against Endstate's locked contracts (docs/contracts/), public commitments (PRINCIPLES.md), and Go-quality posture. Output is a four-section verdict the user can act on before merge.
Before reading anything, confirm what to review. If the user did not specify, ask:
Which diff should I review?
- Current uncommitted changes (
git diff+git diff --cached+ untracked)- A branch against
main(git diff main...<branch>)- A specific GitHub PR (
gh pr diff <num>)
Do not guess. Reviewing the wrong scope wastes the user's time and produces noise.
Once scope is known, capture the changed file list — every check below is conditional on what the diff actually touches.
Read these every review, regardless of diff:
PRINCIPLES.md — the seven public commitments. Pay special attention to:masterKey never leave the device; server cannot decrypt)CLAUDE.md — landmines and protected areas, so the review flags forbidden patterns.Read each contract only if the diff touches its domain. Cite the specific section number when flagging a violation.
| Diff touches | Read |
|---|---|
go-engine/internal/backup/**, hosted backup auth/crypto, JWT/JWKS, KDF, encryption envelope, R2 storage layout, subscription state | docs/contracts/hosted-backup-contract.md |
Any --json envelope, error shapes, error codes, cliVersion/schemaVersion, endstate capabilities | docs/contracts/cli-json-contract.md |
Anything emitted to stderr as JSONL, phase/item/summary/error/artifact events, --events jsonl | docs/contracts/event-contract.md |
| Capabilities handshake, GUI ↔ engine boundary, anything the GUI reads | docs/contracts/gui-integration-contract.md |
| Capture artifact layout, profile composition, restore safety, config portability | docs/contracts/capture-artifact-contract.md, profile-contract.md, restore-safety-contract.md, config-portability-contract.md |
If the diff modifies behavior covered by a spec under openspec/specs/, confirm the same commit (or branch) carries a corresponding openspec/changes/<id>/ proposal.
Run each check against the diff. Skip checks that don't apply (e.g., no new HTTP routes → skip ownership check); never skip because "it probably looks fine."
X-Endstate-API-Version: 1.0 (or compatible major). Refuses to write on major mismatch; warns on minor mismatch for read paths. (hosted-backup-contract.md §11)userId from JWT == userId on the row, AND returns 404 (not 403) on cross-user access to avoid existence leaks. (hosted-backup-contract.md §7 "Ownership enforcement")crypto/rand exclusively (no math/rand). AES-GCM nonces are freshly generated per call from CSPRNG. Auth tags are verified before any plaintext is returned to the caller. AAD binds chunk index where chunks are involved. (hosted-backup-contract.md §3)success: false, error.code SCREAMING_SNAKE_CASE, error.message, optional detail/remediation/docsKey). No bare strings, no ad-hoc shapes. (cli-json-contract.md "Error Object")phase, monotonic phase transitions, last event is summary, schema v1 required fields (version, runId, timestamp, event). (event-contract.md §"Event Fundamentals" and §"Schema v1")[Console]::Error.WriteLine() equivalent in Go). Never mix.openspec/changes/<id>/ proposal. New behavior without a spec change is a missing artifact.*_test.go (e.g., changes in internal/commands/restore.go add cases to internal/commands/restore_test.go). Tests are hermetic — no real winget calls, no network, no shared state. Match the table-driven, single-purpose pattern in existing _test.go files..jsonc file uses manifest.StripJsoncComments before unmarshalling. Raw json.Unmarshal on .jsonc is forbidden. (CLAUDE.md Landmine #1)capabilities output.backup: true; capture/restore paths never include secrets or credentials.docs/ux-language.md (lives in the GUI repo endstate-gui). If unavailable to read, flag it as "verify against GUI repo before merge" rather than silently passing.masterKey, DEK, and any plaintext key material are zeroed (for i := range b { b[i] = 0 }) immediately after use. Don't rely on GC.fmt.Errorf("doing X: %w", err) not returned bare. Caller-visible errors at command boundaries map to a stable error.code.Open/Create/NewWriter/transaction has a matching defer Close() (or equivalent), placed immediately after the success check.go-engine/go.mod is justified — the project's posture is minimal-dependency and audit-friendly. Prefer stdlib; if a third-party module is added, the review notes the reason. Crypto deps in particular need to be widely-used and well-audited (e.g., golang.org/x/crypto over a one-author module).Produce exactly four sections, in this order. Every item names the file and (where useful) the line number, and cites the contract section when applicable.
### Blocking issues
Items that violate a locked contract, principle, or invariant. Must be fixed before merge.
### Should fix
Items that are likely defects or near-future maintenance debt. Catch before merge if possible.
### Worth considering
Subjective design or style notes. Take or leave.
### Off-contract behavior
Anywhere the diff disagrees with a contract — name the contract and the section.
Even if the user accepts the divergence, the contract must be amended in the same change.If a section is empty, write _None._ rather than omitting it. Empty sections signal that the check was actually performed.
Read or Glob. Quote the contract when flagging a violation.Worth considering clearly labeled as pre-existing.go-engine/internal/commands/restore_test.go, capture_test.go, report_test.go — table-driven, hermetic, one assertion per testopenspec/changes/add-hosted-backup-contract/ is a current example© Artexis10, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in .claude/skills/review-endstate of Artexis10/endstate.
Open the folder on GitHubat commit 6f590e9
Review Endstate next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Review Endstate this skillArtexis10/endstate | 110 | — | ~2.2k | Automated safety check: Pass | Apache-2.0 | |
| Find Regression Riskdotnet/maui | 23k | — | ~1.1k | Automated safety check: Pass | MIT | |
| Evaluate PR Testsdotnet/maui | 23k | — | ~2.9k | Automated safety check: Pass | MIT | |
| Worktrunk Tend CI Guidancemax-sixty/worktrunk | 9.2k | — | ~6.4k | Automated safety check: Pass | Custom licence | |
| Code Review ChecklistshareAI-lab/learn-claude-code | 78k | 4 repos | ~1.1k | Automated safety check: Pass | MIT | |
| Open Code Review CLIalibaba/open-code-review | 46k | — | ~3.1k | Automated safety check: Pass | Apache-2.0 |
dotnet/maui
Checks a pull request for lines that undo a recent bug fix by comparing what the PR removes with what labeled bug-fix PRs added to the same files.
dotnet/maui
Reviews the tests added in a pull request for fix coverage, quality, edge cases and test type, and recommends lighter test types where they would do.
max-sixty/worktrunk
Adds Worktrunk-specific rules to the tend CI workflows: Codecov polling, Rust test commands, labels and review criteria for pull requests handled in CI.
shareAI-lab/learn-claude-code
Reviews code against a five-part checklist covering security, correctness, performance, maintainability and testing, and reports findings in a fixed format.
alibaba/open-code-review
Runs the ocr command-line tool to review Git changes, a commit or a branch comparison with an AI model, returning line-level comments and optionally applying fixes.
alibaba/open-code-review
Has the host agent do the code review itself while the ocr CLI handles file selection and rule lookup, covering workspace changes, branch ranges or single commits.
Works with
Categories
A skill your agent uses when the user asks to review changes, review a diff, sanity-check a PR before merge, or verify uncommitted work against Endstate's locked contracts and principles. Review Endstate is an agent skill from Artexis10/endstate. Use when the user asks to review changes, review a diff, sanity-check a PR before merge, or verify uncommitted work against Endstate's locked contracts and principles.
Review Endstate fits situations like: the user asks to review changes; sanity-check a PR before merge; verify uncommitted work against Endstates locked contracts and principles; phrases include review my changes.
Run `npx skills add Artexis10/endstate --skill review-endstate -a claude-code`. Or copy the skill folder (.claude/skills/review-endstate in Artexis10/endstate) into .claude/skills/review-endstate in your project. Claude Code loads it when a task matches its description.
Run `npx skills add Artexis10/endstate --skill review-endstate -a codex`. Or copy the skill folder (.claude/skills/review-endstate in Artexis10/endstate) into .agents/skills/review-endstate in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add Artexis10/endstate --skill review-endstate -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/review-endstate, .gemini/skills/review-endstate, .github/skills/review-endstate and .opencode/skills/review-endstate in your project.
Going by SKILL.md and its folder, Review Endstate needs the command-line tools its instructions call (git and gh).
SKILL.md contains no URLs. Its commands use git and gh, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Review Endstate is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 2.2k tokens (SKILL.md is roughly 8.7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Review Endstate: Find Regression Risk (dotnet/maui, 23k stars), Evaluate PR Tests (dotnet/maui, 23k stars), Worktrunk Tend CI Guidance (max-sixty/worktrunk, 9.2k stars) and Code Review Checklist (shareAI-lab/learn-claude-code, 78k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
Artexis10 (a GitHub user) maintains it in Artexis10/endstate, which has 110 GitHub stars. The repository was last updated on October 6, 2026.
Source: Artexis10/endstate on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.