Code Review Checklist
shareAI-lab/learn-claude-code
Reviews code against a five-part checklist covering security, correctness, performance, maintainability and testing, and reports findings in a fixed format.
Rebuild the dev environment: uv, Python tiers, pins, traps. An agent skill from athola/claude-night-market.
$ npx skills add athola/claude-night-market --skill night-market-build-and-env -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install athola/claude-night-market night-market-build-and-env --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/athola/claude-night-market.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/night-market-build-and-env .claude/skills/night-market-build-and-env && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "night-market-build-and-env" agent skill from https://github.com/athola/claude-night-market/tree/master/.claude/skills/night-market-build-and-env into .claude/skills/night-market-build-and-env/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "night-market-build-and-env", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/athola/claude-night-market/tree/master/.claude/skills/night-market-build-and-envType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add athola/claude-night-market --skill night-market-build-and-env -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install athola/claude-night-market night-market-build-and-env --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/athola/claude-night-market.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.claude/skills/night-market-build-and-env .agents/skills/night-market-build-and-env && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "night-market-build-and-env" agent skill from https://github.com/athola/claude-night-market/tree/master/.claude/skills/night-market-build-and-env into .agents/skills/night-market-build-and-env/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "night-market-build-and-env", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add athola/claude-night-market --skill night-market-build-and-env -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install athola/claude-night-market night-market-build-and-env --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/athola/claude-night-market.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.claude/skills/night-market-build-and-env .cursor/skills/night-market-build-and-env && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "night-market-build-and-env" agent skill from https://github.com/athola/claude-night-market/tree/master/.claude/skills/night-market-build-and-env into .cursor/skills/night-market-build-and-env/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "night-market-build-and-env", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/athola/claude-night-market.git --path .claude/skills/night-market-build-and-env--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add athola/claude-night-market --skill night-market-build-and-env -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install athola/claude-night-market night-market-build-and-env --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/athola/claude-night-market.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.claude/skills/night-market-build-and-env .gemini/skills/night-market-build-and-env && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "night-market-build-and-env" agent skill from https://github.com/athola/claude-night-market/tree/master/.claude/skills/night-market-build-and-env into .gemini/skills/night-market-build-and-env/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "night-market-build-and-env", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install athola/claude-night-market night-market-build-and-envInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add athola/claude-night-market --skill night-market-build-and-env -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/athola/claude-night-market.git skills-src && mkdir -p .github/skills && cp -r skills-src/.claude/skills/night-market-build-and-env .github/skills/night-market-build-and-env && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "night-market-build-and-env" agent skill from https://github.com/athola/claude-night-market/tree/master/.claude/skills/night-market-build-and-env into .github/skills/night-market-build-and-env/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "night-market-build-and-env", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add athola/claude-night-market --skill night-market-build-and-env -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install athola/claude-night-market night-market-build-and-env --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/athola/claude-night-market.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.claude/skills/night-market-build-and-env .opencode/skills/night-market-build-and-env && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "night-market-build-and-env" agent skill from https://github.com/athola/claude-night-market/tree/master/.claude/skills/night-market-build-and-env into .opencode/skills/night-market-build-and-env/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "night-market-build-and-env", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
night-market-build-and-envRebuild the dev environment: uv, Python tiers, pins, traps. An agent skill from athola/claude-night-market.
Night Market Build And Env is an agent skill from athola/claude-night-market. Rebuild the dev environment: uv, Python tiers, pins, traps. Use when onboarding or toolchain breaks. Do not use for daily commands; use night-market-operations.
Its SKILL.md is about 2.7k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Development. It works with Python. The repository describes itself as: 23 Claude Code plugins: TDD enforcement hooks, git/PR workflows, spec-driven development, code review, project lifecycle, fix-from-error, maintenance automation, context… The licence is MIT.
Read from SKILL.md and the folder at commit 9f3eb00. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
uvmakergghcargogitpython3brewnodenpmruffFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use uv, gh, git and npm, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Night Market Build And Env loads about 2.7k tokens when it runs. Until then it costs about 47 tokens; SKILL.md has 1,359 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from athola/claude-night-market at commit 9f3eb00, republished under its MIT licence (© athola). 1,359 words, ~2,709 tokens.
.claude/skills/night-market-build-and-env/SKILL.md (or your agent's skills folder).Recreate a working claude-night-market development environment from a bare machine, verify it in under an hour, and avoid the traps that have broken it before. Everything below was verified against the repo on 2026-07-02 (v1.9.15).
One rule dominates: every Python tool runs through uv run. uv is
Astral's Python package and environment manager. On first uv run it
creates .venv/ and syncs it from uv.lock. Never install repo
dependencies with bare pip.
Install in this order. "via uv" means the tool resolves from uv.lock
automatically. There is no manual install step for those rows.
| # | Tool | Required? | Install hint | Verify command |
|---|---|---|---|---|
| 1 | uv | REQUIRED | official installer at astral.sh/uv | uv --version |
| 2 | Python 3.12 | REQUIRED | uv python install 3.12 | python3 --version |
| 3 | make + bash | REQUIRED | GNU make 3.82+ (Xcode CLT ships 3.81, which ignores .SHELLFLAGS; brew install make, run gmake) | make --version |
| 4 | ruff >=0.14.13 | via uv | none (dev dependency in uv.lock) | uv run ruff --version |
| 5 | bandit | via uv | none (pre-commit env is pinned separately, see traps) | uv run bandit --version |
| 6 | mypy >=1.13 | via uv | none | uv run mypy --version |
| 7 | pre-commit >=4 | via uv | uv run pre-commit install | uv run pre-commit --version |
| 8 | Python 3.9 | optional | uv python install 3.9 | uv venv --python 3.9 /tmp/py39-check |
| 9 | node + npm | optional | needed for conjure Gemini delegation | node --version |
| 10 | Rust + cargo | optional | rustup (only for make skrills-build) | cargo --version |
| 11 | skrills binary | optional | make skrills-build or make skrills-install | make skrills-verify |
| 12 | mdbook | optional | cargo install mdbook; builds book/ | mdbook --version |
| 13 | gh CLI | optional | cli.github.com (releases and Discussions) | gh --version |
Notes on the optional rows:
.github/workflows/python39-compat.yml.package.json pins
@google/gemini-cli at ^0.25.1. Run npm install at the repo root
only if you use conjure delegation.make validate-skills,
make analyze-skills) has a Python fallback, so you can skip Rust
entirely.gh discussion subcommand. They are reachable only through
gh api graphql.Version numbers observed on the reference machine (2026-07-02):
uv 0.8.22, Python 3.12.3, ruff 0.14.13, mypy 1.19.1, bandit 1.9.2,
pre-commit 4.5.1. Newer versions of uv are fine. The ruff version must
match uv.lock (see traps).
Run these in order after installing rows 1-3 above. Each step lists the output shape that means success.
Step 1: clone and check uv.
git clone git@github.com:athola/claude-night-market.git
cd claude-night-market
uv --versionExpected: a single line like uv 0.8.22. Any 0.8+ version works. CI
pins astral-sh/setup-uv@v8.2.0.
Step 2: validate all plugin structures (also proves the venv syncs).
make validate-allExpected: one block per plugin (26 directories) shaped like:
>>> Validating plugins/abstract:
Plugin Validation Report: abstract
...
OK Plugin validation passedBlue "Recommendations" lines are advisory and fine. A red failure line
or (validation failed) is not.
Step 3: run one fast plugin test suite.
make -C plugins/leyline testExpected: verbose pytest output ending with a coverage table and a
summary like 710 passed, 6 warnings in 9.96s (counts and timing
drift, but zero failures is the invariant). This proves uv run, pytest,
and per-plugin coverage thresholds all work.
Step 4: install the git hooks.
uv run pre-commit installExpected: pre-commit installed at .git/hooks/pre-commit. From now on
commits run the full hook chain (file validation, bandit, ruff, mypy,
changed-plugin tests, structure validation). Never bypass it with
--no-verify; CONSTITUTION.md forbids that.
If any step fails, load night-market-debugging-playbook.
This is the number-one onboarding misconception. The README says "Python 3.9+ for hooks", and newcomers read that as "the repo runs on 3.9". It does not. There are three tiers:
| Tier | Version | Enforced by | Why |
|---|---|---|---|
| Root tooling (pytest, ruff, mypy) | 3.12 | root pyproject.toml requires-python = ">=3.12", ruff target-version = "py312", mypy python_version = "3.12" | dev toolchain runs inside the uv venv |
| Plugin packages | varies, 3.9 to 3.12 | each plugins/<name>/pyproject.toml | plugins are independent deployables (ADR-0001) |
| Hook import chains | 3.9 | .github/workflows/python39-compat.yml | hooks run under the HOST system Python (macOS 3.9.6), outside any venv |
Per-plugin requires-python as of 2026-07-02 (22 of 26 plugin dirs
have a pyproject.toml):
<3.14), imbue, leyline, minister,
sanctum, scryWhy the hook tier exists: Claude Code executes hook scripts with
whatever interpreter the host provides, not the repo venv. A hook file
AND everything it transitively imports must therefore stay
3.9-compatible, even inside a plugin whose package requires 3.12. CI
enforces this with two gates in python39-compat.yml: gate 1 runs
ruff check --select UP007 --target-version py39 on hook files (bare
X | Y union annotations), gate 2 builds a real 3.9 venv with
uv venv --python 3.9 and runs hook tests with
--override-ini="addopts=".
Consequences you must respect in hook-reachable code:
timezone.utc, never datetime.UTC (a 3.11+ alias). The root
ruff config extend-ignores UP017 specifically so autofix does not
reintroduce the alias. This break recurred three times before the
ignore plus an AST guard test held the line.yaml, anthropic) in hook entrypoints.
The system interpreter has none of the repo's dependencies, and an
unguarded import makes every git commit emit ModuleNotFoundError.| Trap | Symptom | Fix or guard |
|---|---|---|
setup-uv@v8 bare tag | CI fails: the bare v8 tag does not exist upstream | pin exact tag astral-sh/setup-uv@v8.2.0 (commit f81d89a5). Guard: scripts/check_pinned_versions.py |
| bandit 1.9+ under system 3.9 | pre-commit bandit hook env fails to install | .pre-commit-config.yaml pins rev: 1.8.6, the last release supporting 3.9 (commit 25bf5a9d). The project-venv bandit (1.9.x via uv run) is a different install and is fine |
stale .uv-tools binary shadows ruff | bare ruff reports an old version (0.7.3 observed) and disagrees with CI | root Makefile sets UV_TOOL_DIR ?= $(abspath .)/.uv-tools and prepends .uv-tools/ruff/bin to PATH. Always lint via make lint or uv run ruff, never bare ruff. Guard: scripts/check_ruff_version.py compares uv.lock to PyPI |
| root pytest silently skips plugins | uv run pytest at the root collects only tests/, never plugin tests | root pyproject.toml sets norecursedirs = ["plugins/*", ...] on purpose (root conftest.py documents ImportPathMismatchError). Run make -C plugins/<name> test or make <name>-test |
| imbue coverage artifacts | every pytest run in plugins/imbue writes htmlcov/, coverage.xml | imbue's pytest addopts force --cov=scripts with term, html, and xml reports. Artifacts are gitignored. Expect them and never commit them |
make skrills-build fails | Error: skrills repo not found at $HOME/skrills | SKRILLS_REPO defaults to $(HOME)/skrills. Set SKRILLS_REPO=/path/to/skrills or skip: make validate-skills falls back to a Python checker when no skrills binary exists |
| plugins run from a cache dir | plugin hook cannot find a file by relative path | installed plugins execute from the Claude Code cache dir, not the repo. Hooks must never use paths relative to the current working directory |
VOW_SHADOW_MODE, quality gates): use night-market-config-catalog.uv --version prints a version at the repo root.uv run ruff --version prints the uv.lock version (0.14.13 as
of 2026-07-02), not the .uv-tools version.make validate-all prints Plugin validation passed for every
plugin and no (validation failed) lines.make -C plugins/leyline test ends with N passed and zero
failures, plus a coverage table.uv run pre-commit install created .git/hooks/pre-commit.Compiled 2026-07-02 against repo v1.9.15 (branch discussions-fix-1.9.14). Observed tool versions and test counts in this file are snapshots and will drift. Re-verify with:
rg -n "requires-python" pyproject.tomlrg -n "requires-python" plugins/*/pyproject.tomlrg -n -A1 'name = "ruff"$' uv.lockrg -n "setup-uv" .github/workflows/*.ymlrg -n -B2 "id: bandit" .pre-commit-config.yamlrg -n "UV_TOOL_DIR|SKRILLS_REPO \?=" Makefilerg -n "norecursedirs" pyproject.tomlrg -n -A8 "addopts" plugins/imbue/pyproject.tomlrg -n "gemini-cli" package.jsonmake -C plugins/leyline test© athola, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in .claude/skills/night-market-build-and-env of athola/claude-night-market.
Open the folder on GitHubat commit 9f3eb00
Night Market Build And Env next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Night Market Build And Env this skillathola/claude-night-market | 341 | — | ~2.7k | Automated safety check: Pass | MIT | |
| Code Review ChecklistshareAI-lab/learn-claude-code | 78k | 4 repos | ~1.1k | Automated safety check: Pass | MIT | |
| Minimizing Ty Ecosystem Changesastral-sh/ruff | 50k | — | ~4.6k | Automated safety check: Pass | MIT | |
| Merge Dependabot PRsonyx-dot-app/onyx | 32k | 1 repos | ~2.2k | Automated safety check: Pass | MIT | |
| Summarise Ecosystem Resultsastral-sh/ruff | 50k | — | ~2.2k | Automated safety check: Pass | MIT | |
| Senior Architect Toolkitmaslennikov-ig/claude-code-orchestrator-kit | 260 | 8 repos | ~1.2k | Automated safety check: Notes | Custom licence |
shareAI-lab/learn-claude-code
Reviews code against a five-part checklist covering security, correctness, performance, maintainability and testing, and reports findings in a fixed format.
astral-sh/ruff
A skill your agent uses when a user says "minimize this ty ecosystem change", "reproduce this ecosystem result", "investigate a primer difference", "investigate a mypyprimer difference"…
onyx-dot-app/onyx
Triages and lands a batch of open Dependabot PRs in the Onyx repo, where main is gated exclusively by GitHub's merge queue: approves and enqueues green PRs, closes superseded duplicates, fixes…
astral-sh/ruff
A skill your agent uses when a user says "summarise ecosystem results", "summarize this ty ecosystem report", "what changed in this ecosystem run?", or asks to summarise or summarize ty ecosystem…
maslennikov-ig/claude-code-orchestrator-kit
Comprehensive software architecture skill for designing scalable, maintainable systems using ReactJS, NextJS, NodeJS, Express, React Native, Swift, Kotlin…
kedro-org/kedro
Run Kedro's local lint / format / type-check / tests on changed files (uses the project's pre-commit hooks, ruff, mypy, pytest, lint-imports, detect-secrets, Make targets — in the right venv), or…
athola/claude-night-market
Run and interpret repo diagnostic scripts (ratchets, validators, token stats).
athola/claude-night-market
Evaluate Claude skill quality through auditing. An agent skill from athola/claude-night-market.
athola/claude-night-market
Coordinates Claude agent teams via filesystem protocol. An agent skill from athola/claude-night-market.
athola/claude-night-market
Delegates execution to eight CLIs (Gemini, Qwen, MiniMax, GLM, Muse, Codex, OpenCode, Glimmer).
athola/claude-night-market
Guide minimal code via a decision ladder with full safety, edge, and negative-case coverage.
athola/claude-night-market
Build a project skill library in .claude/skills/ via discovery, parallel authoring, and review.
Works with
Categories
Rebuild the dev environment: uv, Python tiers, pins, traps. An agent skill from athola/claude-night-market. Night Market Build And Env is an agent skill from athola/claude-night-market. Rebuild the dev environment: uv, Python tiers, pins, traps.
Night Market Build And Env fits situations like: toolchain breaks; use night-market-operations.
Run `npx skills add athola/claude-night-market --skill night-market-build-and-env -a claude-code`. Or copy the skill folder (.claude/skills/night-market-build-and-env in athola/claude-night-market) into .claude/skills/night-market-build-and-env in your project. Claude Code loads it when a task matches its description.
Run `npx skills add athola/claude-night-market --skill night-market-build-and-env -a codex`. Or copy the skill folder (.claude/skills/night-market-build-and-env in athola/claude-night-market) into .agents/skills/night-market-build-and-env in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add athola/claude-night-market --skill night-market-build-and-env -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/night-market-build-and-env, .gemini/skills/night-market-build-and-env, .github/skills/night-market-build-and-env and .opencode/skills/night-market-build-and-env in your project.
Going by SKILL.md and its folder, Night Market Build And Env needs the command-line tools its instructions call (uv, make, rg, gh, cargo and git). Our summary lists: Python 3; Node.js.
SKILL.md contains no URLs. Its commands use uv, gh, git and npm, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Night Market Build And Env is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 2.7k tokens (SKILL.md is roughly 11k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Night Market Build And Env: Code Review Checklist (shareAI-lab/learn-claude-code, 78k stars), Minimizing Ty Ecosystem Changes (astral-sh/ruff, 50k stars), Merge Dependabot PRs (onyx-dot-app/onyx, 32k stars) and Summarise Ecosystem Results (astral-sh/ruff, 50k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
athola (a GitHub user) maintains it in athola/claude-night-market, which has 341 GitHub stars. The repository holds 152 skills in this directory. The repository was last updated on October 9, 2026.
Source: athola/claude-night-market on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.