Agent skill

Review Endstate

by Artexis10 in Artexis10/endstate

A skill your agent uses when the user asks to review changes, review a diff, sanity-check a PR before merge, or verify uncommitted work against Endstate's locked contracts and principles.

Apache-2.0Auto-check passedDevelopment

Install Review Endstate

skills CLI
$ npx skills add Artexis10/endstate --skill review-endstate -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install Artexis10/endstate review-endstate --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/Artexis10/endstate.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/review-endstate .claude/skills/review-endstate && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
review-endstate
GitHub stars
110
Token cost
~2.2k tokens
SKILL.md length
987 words
Files
1
Skills in repo
1
Repo updated
First seen
Licence
Apache-2.0

At a glance

A skill your agent uses when the user asks to review changes, review a diff, sanity-check a PR before merge, or verify uncommitted work against Endstate's locked contracts and principles.

  • Works in 6 steps: Determine diff scope (ask if ambiguous) → Always-read inputs → Conditional contract reads → …
  • The user asks to review changes
  • SKILL.md covers Step 1 — Determine diff scope…, Step 2 — Always-read inputs, Step 3 — Conditional contract… and Step 4 — Project-specific…, plus 4 more sections
  • Calls git and gh

What it does

Review Endstate is an agent skill from Artexis10/endstate. Use when the user asks to review changes, review a diff, sanity-check a PR before merge, or verify uncommitted work against Endstate's locked contracts and principles. Trigger phrases include "review my changes", "review the diff", "sanity check this branch", "check against contracts", "review before PR". Repo-scoped to the Endstate engine.

Its SKILL.md is about 2.2k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Development, covering Code review. It works with PowerShell and Git. The repository describes itself as: Open-source engine behind Endstate: reinstall your apps and restore your settings on a fresh machine from one file. Windows via winget (Linux/macOS in progress). Go, Apache 2.0. The licence is Apache-2.0.

When your agent uses it

  • The user asks to review changes
  • Sanity-check a PR before merge
  • Verify uncommitted work against Endstates locked contracts and principles
  • Phrases include review my changes

Example prompts

  • “s locked contracts and principles. Trigger phrases include”
  • “review the diff”
  • “sanity check this branch”
  • “/review-endstate”

Workflow steps

6 steps, taken from the step headings in SKILL.md.

  1. Determine diff scope (ask if ambiguous)
  2. Always-read inputs
  3. Conditional contract reads
  4. Project-specific checklist
  5. Go-quality checklist
  6. Output

What it can do on your machine

Read from SKILL.md and the folder at commit 6f590e9. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • git
    • gh

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use git and gh, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Review Endstate loads about 2.2k tokens when it runs. Until then it costs about 90 tokens; SKILL.md has 987 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~90
When it runs · the whole SKILL.md, loaded when a task matches
~2.2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from Artexis10/endstate at commit 6f590e9, republished under its Apache-2.0 licence (© Artexis10). 987 words, ~2,167 tokens.

Download SKILL.mdSave it as .claude/skills/review-endstate/SKILL.md (or your agent's skills folder).
name
review-endstate
description
Use when the user asks to review changes, review a diff, sanity-check a PR before merge, or verify uncommitted work against Endstate's locked contracts and principles. Trigger phrases include "review my changes", "review the diff", "sanity check this branch", "check against contracts", "review before PR". Repo-scoped to the Endstate engine.

Review Endstate Changes

A structured review of a diff against Endstate's locked contracts (docs/contracts/), public commitments (PRINCIPLES.md), and Go-quality posture. Output is a four-section verdict the user can act on before merge.

Step 1 — Determine diff scope (ask if ambiguous)

Before reading anything, confirm what to review. If the user did not specify, ask:

Which diff should I review?

  1. Current uncommitted changes (git diff + git diff --cached + untracked)
  2. A branch against main (git diff main...<branch>)
  3. A specific GitHub PR (gh pr diff <num>)

Do not guess. Reviewing the wrong scope wastes the user's time and produces noise.

Once scope is known, capture the changed file list — every check below is conditional on what the diff actually touches.

Step 2 — Always-read inputs

Read these every review, regardless of diff:

  • PRINCIPLES.md — the seven public commitments. Pay special attention to:
    • Principle 1 (the local product is free, forever — no nag screens, no profile/feature limits, no local features gated on subscription status, no telemetry-by-default)
    • Principle 4 (hosted data is encrypted end-to-end with client-side keys — passphrase and masterKey never leave the device; server cannot decrypt)
  • CLAUDE.md — landmines and protected areas, so the review flags forbidden patterns.

Step 3 — Conditional contract reads

Read each contract only if the diff touches its domain. Cite the specific section number when flagging a violation.

Diff touchesRead
go-engine/internal/backup/**, hosted backup auth/crypto, JWT/JWKS, KDF, encryption envelope, R2 storage layout, subscription statedocs/contracts/hosted-backup-contract.md
Any --json envelope, error shapes, error codes, cliVersion/schemaVersion, endstate capabilitiesdocs/contracts/cli-json-contract.md
Anything emitted to stderr as JSONL, phase/item/summary/error/artifact events, --events jsonldocs/contracts/event-contract.md
Capabilities handshake, GUI ↔ engine boundary, anything the GUI readsdocs/contracts/gui-integration-contract.md
Capture artifact layout, profile composition, restore safety, config portabilitydocs/contracts/capture-artifact-contract.md, profile-contract.md, restore-safety-contract.md, config-portability-contract.md

If the diff modifies behavior covered by a spec under openspec/specs/, confirm the same commit (or branch) carries a corresponding openspec/changes/<id>/ proposal.

Step 4 — Project-specific checklist

Run each check against the diff. Skip checks that don't apply (e.g., no new HTTP routes → skip ownership check); never skip because "it probably looks fine."

  • API version header. Any new substrate API call site verifies that the response carries X-Endstate-API-Version: 1.0 (or compatible major). Refuses to write on major mismatch; warns on minor mismatch for read paths. (hosted-backup-contract.md §11)
  • Ownership + 404, not 403. Any new authenticated route enforces userId from JWT == userId on the row, AND returns 404 (not 403) on cross-user access to avoid existence leaks. (hosted-backup-contract.md §7 "Ownership enforcement")
  • Crypto hygiene. Any new crypto code uses crypto/rand exclusively (no math/rand). AES-GCM nonces are freshly generated per call from CSPRNG. Auth tags are verified before any plaintext is returned to the caller. AAD binds chunk index where chunks are involved. (hosted-backup-contract.md §3)
  • Error envelope. Any new error path returns the standard envelope (success: false, error.code SCREAMING_SNAKE_CASE, error.message, optional detail/remediation/docsKey). No bare strings, no ad-hoc shapes. (cli-json-contract.md "Error Object")
  • Event ordering. Any new streaming output respects ordering invariants — first event is phase, monotonic phase transitions, last event is summary, schema v1 required fields (version, runId, timestamp, event). (event-contract.md §"Event Fundamentals" and §"Schema v1")
  • Stdout vs stderr split. Any new command emits the JSON envelope on stdout and streaming events on stderr ([Console]::Error.WriteLine() equivalent in Go). Never mix.
  • OpenSpec coupling. If the change modifies behavior covered by an existing spec, the same commit references an openspec/changes/<id>/ proposal. New behavior without a spec change is a missing artifact.
  • Tests for new behavior. New behavior has new tests under the matching *_test.go (e.g., changes in internal/commands/restore.go add cases to internal/commands/restore_test.go). Tests are hermetic — no real winget calls, no network, no shared state. Match the table-driven, single-purpose pattern in existing _test.go files.
  • JSONC parsing. Any new code reading a .jsonc file uses manifest.StripJsoncComments before unmarshalling. Raw json.Unmarshal on .jsonc is forbidden. (CLAUDE.md Landmine #1)
  • Capabilities reflect CLI changes. New or changed CLI flags/commands appear in the capabilities output.
  • Restore entries back up. Restore entries carry backup: true; capture/restore paths never include secrets or credentials.
  • UX language (only if user-facing strings change). New error messages, status reasons, or progress strings line up with docs/ux-language.md (lives in the GUI repo endstate-gui). If unavailable to read, flag it as "verify against GUI repo before merge" rather than silently passing.
Show full SKILL.md (298 more words)Show less

Step 5 — Go-quality checklist

  • Sensitive buffers zeroed. Passphrase bytes, derived masterKey, DEK, and any plaintext key material are zeroed (for i := range b { b[i] = 0 }) immediately after use. Don't rely on GC.
  • Errors carry context. Errors are wrapped with fmt.Errorf("doing X: %w", err) not returned bare. Caller-visible errors at command boundaries map to a stable error.code.
  • Deferred cleanup. Every Open/Create/NewWriter/transaction has a matching defer Close() (or equivalent), placed immediately after the success check.
  • Dependency justification. Any new entry in go-engine/go.mod is justified — the project's posture is minimal-dependency and audit-friendly. Prefer stdlib; if a third-party module is added, the review notes the reason. Crypto deps in particular need to be widely-used and well-audited (e.g., golang.org/x/crypto over a one-author module).

Step 6 — Output

Produce exactly four sections, in this order. Every item names the file and (where useful) the line number, and cites the contract section when applicable.

### Blocking issues
Items that violate a locked contract, principle, or invariant. Must be fixed before merge.

### Should fix
Items that are likely defects or near-future maintenance debt. Catch before merge if possible.

### Worth considering
Subjective design or style notes. Take or leave.

### Off-contract behavior
Anywhere the diff disagrees with a contract — name the contract and the section.
Even if the user accepts the divergence, the contract must be amended in the same change.

If a section is empty, write _None._ rather than omitting it. Empty sections signal that the check was actually performed.

Boundary rules

  • Don't review with insufficient information. If the diff is too large to load fully, or scope is ambiguous, ask first. A partial review that reads as complete is worse than no review.
  • Don't fabricate. Don't claim a contract section exists unless verified by reading. Don't claim a file is missing without confirming via Read or Glob. Quote the contract when flagging a violation.
  • Don't restate the diff. The user can see the diff. The review is the analysis on top.
  • Don't expand scope. Do not flag pre-existing issues outside the diff. If you see one and it's important, mention it in Worth considering clearly labeled as pre-existing.

Reference patterns

  • Test patterns to match: go-engine/internal/commands/restore_test.go, capture_test.go, report_test.go — table-driven, hermetic, one assertion per test
  • OpenSpec change layout: openspec/changes/add-hosted-backup-contract/ is a current example

© Artexis10, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .claude/skills/review-endstate of Artexis10/endstate.

Open the folder on GitHubat commit 6f590e9

Compare with similar skills

Review Endstate next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Review Endstate compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Review Endstate this skillArtexis10/endstate110—~2.2kAutomated safety check: PassApache-2.0
Find Regression Riskdotnet/maui23k—~1.1kAutomated safety check: PassMIT
Evaluate PR Testsdotnet/maui23k—~2.9kAutomated safety check: PassMIT
Worktrunk Tend CI Guidancemax-sixty/worktrunk9.2k—~6.4kAutomated safety check: PassCustom licence
Code Review ChecklistshareAI-lab/learn-claude-code78k4 repos~1.1kAutomated safety check: PassMIT
Open Code Review CLIalibaba/open-code-review46k—~3.1kAutomated safety check: PassApache-2.0

Similar skills

  • Official

    Checks a pull request for lines that undo a recent bug fix by comparing what the PR removes with what labeled bug-fix PRs added to the same files.

    23k GitHub stars~1.1k tokensUpdated yesterday
    DevelopmentAuto-check passed
  • Official

    Reviews the tests added in a pull request for fix coverage, quality, edge cases and test type, and recommends lighter test types where they would do.

    23k GitHub stars~2.9k tokensUpdated yesterday
    Testing & QAAuto-check passed
  • Worktrunk Tend CI Guidance

    max-sixty/worktrunk

    Adds Worktrunk-specific rules to the tend CI workflows: Codecov polling, Rust test commands, labels and review criteria for pull requests handled in CI.

    9.2k GitHub stars~6.4k tokensUpdated today
    DevelopmentAuto-check passed
  • Code Review Checklist

    shareAI-lab/learn-claude-code

    Reviews code against a five-part checklist covering security, correctness, performance, maintainability and testing, and reports findings in a fixed format.

    78k GitHub starsUsed in 4 repos~1.1k tokens
    DevelopmentAuto-check passed
  • Open Code Review CLI

    alibaba/open-code-review

    Runs the ocr command-line tool to review Git changes, a commit or a branch comparison with an AI model, returning line-level comments and optionally applying fixes.

    46k GitHub stars~3.1k tokensUpdated yesterday
    DevelopmentAuto-check passed
  • Open Code Review Delegate

    alibaba/open-code-review

    Has the host agent do the code review itself while the ocr CLI handles file selection and rule lookup, covering workspace changes, branch ranges or single commits.

    46k GitHub stars~2.3k tokensUpdated yesterday
    DevelopmentAuto-check passed

Works with

Questions about Review Endstate

What does Review Endstate do?

A skill your agent uses when the user asks to review changes, review a diff, sanity-check a PR before merge, or verify uncommitted work against Endstate's locked contracts and principles. Review Endstate is an agent skill from Artexis10/endstate. Use when the user asks to review changes, review a diff, sanity-check a PR before merge, or verify uncommitted work against Endstate's locked contracts and principles.

When should I use Review Endstate?

Review Endstate fits situations like: the user asks to review changes; sanity-check a PR before merge; verify uncommitted work against Endstates locked contracts and principles; phrases include review my changes.

How do I install Review Endstate in Claude Code?

Run `npx skills add Artexis10/endstate --skill review-endstate -a claude-code`. Or copy the skill folder (.claude/skills/review-endstate in Artexis10/endstate) into .claude/skills/review-endstate in your project. Claude Code loads it when a task matches its description.

How do I install Review Endstate in Codex?

Run `npx skills add Artexis10/endstate --skill review-endstate -a codex`. Or copy the skill folder (.claude/skills/review-endstate in Artexis10/endstate) into .agents/skills/review-endstate in your project. Codex loads it when a task matches its description.

Can I use Review Endstate in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add Artexis10/endstate --skill review-endstate -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/review-endstate, .gemini/skills/review-endstate, .github/skills/review-endstate and .opencode/skills/review-endstate in your project.

What does Review Endstate need to run?

Going by SKILL.md and its folder, Review Endstate needs the command-line tools its instructions call (git and gh).

Does Review Endstate access the network?

SKILL.md contains no URLs. Its commands use git and gh, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Review Endstate safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Review Endstate use?

Review Endstate is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Review Endstate use?

About 2.2k tokens (SKILL.md is roughly 8.7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Review Endstate?

Skills that share tags, products or a category with Review Endstate: Find Regression Risk (dotnet/maui, 23k stars), Evaluate PR Tests (dotnet/maui, 23k stars), Worktrunk Tend CI Guidance (max-sixty/worktrunk, 9.2k stars) and Code Review Checklist (shareAI-lab/learn-claude-code, 78k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Review Endstate?

Artexis10 (a GitHub user) maintains it in Artexis10/endstate, which has 110 GitHub stars. The repository was last updated on October 6, 2026.

Source: Artexis10/endstate on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.