Code Review
Azure/Azurite
Review Azurite pull requests with service-aware checks for Blob, Queue, and Table behavior, API compatibility, tests, and release notes.
Reviews Azurite pull requests with checks for Blob, Queue and Table API compatibility, auth paths, persistence, tests and changelog, ending in a fixed comment format.
$ npx skills add Azure/AgentBaker --skill code-review -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install Azure/AgentBaker code-review --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/Azure/AgentBaker.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.github/skills/code-review .claude/skills/code-review && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "code-review" agent skill from https://github.com/Azure/AgentBaker/tree/main/.github/skills/code-review into .claude/skills/code-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "code-review", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/Azure/AgentBaker/tree/main/.github/skills/code-reviewType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add Azure/AgentBaker --skill code-review -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install Azure/AgentBaker code-review --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/Azure/AgentBaker.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.github/skills/code-review .agents/skills/code-review && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "code-review" agent skill from https://github.com/Azure/AgentBaker/tree/main/.github/skills/code-review into .agents/skills/code-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "code-review", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add Azure/AgentBaker --skill code-review -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install Azure/AgentBaker code-review --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/Azure/AgentBaker.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.github/skills/code-review .cursor/skills/code-review && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "code-review" agent skill from https://github.com/Azure/AgentBaker/tree/main/.github/skills/code-review into .cursor/skills/code-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "code-review", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/Azure/AgentBaker.git --path .github/skills/code-review--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add Azure/AgentBaker --skill code-review -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install Azure/AgentBaker code-review --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/Azure/AgentBaker.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.github/skills/code-review .gemini/skills/code-review && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "code-review" agent skill from https://github.com/Azure/AgentBaker/tree/main/.github/skills/code-review into .gemini/skills/code-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "code-review", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install Azure/AgentBaker code-reviewInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add Azure/AgentBaker --skill code-review -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/Azure/AgentBaker.git skills-src && mkdir -p .github/skills && cp -r skills-src/.github/skills/code-review .github/skills/code-review && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "code-review" agent skill from https://github.com/Azure/AgentBaker/tree/main/.github/skills/code-review into .github/skills/code-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "code-review", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add Azure/AgentBaker --skill code-review -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install Azure/AgentBaker code-review --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/Azure/AgentBaker.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.github/skills/code-review .opencode/skills/code-review && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "code-review" agent skill from https://github.com/Azure/AgentBaker/tree/main/.github/skills/code-review into .opencode/skills/code-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "code-review", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
code-reviewReviews Azurite pull requests with checks for Blob, Queue and Table API compatibility, auth paths, persistence, tests and changelog, ending in a fixed comment format.
The review focuses on whether changes keep Azure Storage API compatibility for the affected service (blob, queue, table or shared code), whether authentication, authorization and request validation paths regress (SharedKey, SAS, OAuth, public access), whether persistence changes work for both the default Loki metadata store and SQL-backed metadata, and whether generated protocol or model code stays aligned with its handlers and tests.
Evidence includes tests for changed behavior under tests/, targeted npm lint, build and per-service test commands, and a check whether ChangeLog.md needs an Upcoming Release entry. Cross-service shared changes are reviewed for impact on all three services, and protocol changes for status codes, headers and error shapes, plus edge cases like conditional headers and leases. The final PR comment must follow a numbered structure covering impact analysis, build and conflict resolution, tests, test suite, changelog and PR comments, each in bullets with None for empty sections.
8 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit b726787. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md.
From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Azurite Pull Request Review loads about 3.9k tokens when it runs. Until then it costs about 90 tokens; SKILL.md has 1,779 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from Azure/AgentBaker at commit b726787, republished under its MIT licence (© Azure). 1,779 words, ~3,890 tokens.
.claude/skills/code-review/SKILL.md (or your agent's skills folder).When reviewing pull requests, perform breaking change analysis to prevent regressions. VHDs remain in production for 6 months, so backward compatibility is critical.
Focus on architecture, security vulnerabilities, and logic errors. Understand the code's intent, dependencies, and concrete failure modes before you report a finding.
Analyze PRs for these compatibility scenarios:
1. Linux Provisioning Script Changes
parts/linux/cloud-init/artifacts/ run during critical VM bootstrap and are used in both:vhdbuilder/packer/*.json)pkg/agent/const.go)pkg/agent/datamodel/linux_sig_version.jsonsource statements that break dependency chainsubuntu/, mariner/)parts/common/components.json or allowed sources (packages.aks.azure.com)parts/common/components.json for Renovate updateshotfix-scripts: auto-generated block in parts/linux/cloud-init/nodecustomdata.yml, or resets parts/linux/cloud-init/artifacts/aks-node-controller-hotfix.json to {}, always confirm with the PR owner that all affected VHDs have been republished with the fix baked in or are out of the 6-month support window. Premature removal means nodes provisioned via scale-up on the old buggy VHD will no longer receive the hotfix. These files are auto-generated by hotfix/hotfix_generate.py (via the hotfix-generate GH Action) — see that script for how version/scripts_version are computed.2. Windows Bidirectional Compatibility
staging/cse/windows/ (CSE scripts) or vhdbuilder/packer/windows/ (VHD scripts)3. aks-node-controller Migration (Dual-Mode Support)
4. PIS / VHD Caching — basePrep vs nodePrep split (Windows + Linux)
parts/windows/kuberneteswindowssetup.ps1.template (BasePrep/NodePrep) and Linux parts/linux/cloud-init/artifacts/cse_main.sh (basePrep/nodePrep):basePrep — gated only by the base_prep.complete marker (C:\AzureData\ Windows, /opt/azure/containers/ Linux). Skipped on PIS real nodes because the marker is baked into the VHD.nodePrep — runs whenever PreProvisionOnly is false (every real node); skipped only on the bake VM.PreProvisionOnly=true ({{GetPreProvisionOnly}}) and writes the marker after basePrep succeeds (Windows finally; Linux cse_start.sh).basePrep in-memory state is gone. (Non-PIS: both run in one execution, no reboot between phases, so state carries — but don't rely on it.)basePrep: TLS bootstrap tokens, any kubeconfig embedding a token (e.g. Windows Write-BootstrapKubeConfig → c:\k\bootstrap-config), secrets, expiring SAS URLs/creds, per-node identity/name/certs. Baked into the VHD and never refreshed (real nodes skip basePrep) → stale. Write it in nodePrep.nodePrep reading a variable that only basePrep set (not re-derived from CustomData) — empty on PIS nodes.basePrep that auto-starts on the real node before nodePrep refreshes its config — it runs against the stale baked config (e.g. a kubelet unit starting from the bake-time bootstrap-config before nodePrep rewrites the token).nodePrep — defeats caching, slows provisioning. Keep it in basePrep.basePrep = static, non-secret, valid for every node booting weeks later. nodePrep = node-specific, secret, expiring, or CustomData-derived.base_prep.complete marker; cluster-wide non-secrets (CA cert, apiserver FQDN, service CIDR); pre-existing basePrep writes unless the PR newly depends on them.5. Package/Dependency Update PRs (Renovate)
Context: Renovate bot automatically creates PRs to update component versions in parts/common/components.json. These components are cached on VHDs during build and directly affect node stability, GPU workloads, networking, and security. Updated packages are downloaded from packages.aks.azure.com or upstream registries during VHD build.
What to check: Every version bump—even patch versions—can introduce regressions that affect production nodes.
Analysis steps for every package update PR:
parts/common/components.json to extract exact old → new versions for each OS/release entry.downloadLocation and downloadURIs structure in components.json remains valid for the new version. New versions sometimes change the artifact naming convention or repository layout.components.json, including latestVersion and previousLatestVersion, and ignore testdata and fixtures. First distinguish components for which AKS-RP selects a version from components that simply use the version baked into the VHD; the latter do not require version coordination. If AKS-RP access is unavailable, state that this check was not completed and request confirmation from the component owner rather than assuming coordination. Passing CI is not proof of coordination: a missing cached version can still be downloaded at runtime, allowing provisioning to succeed with increased latency.Risk assessment for package updates:
Review output for package update PRs must include a detailed version diff analysis:
Header:
## Package Update Analysis: <component-name>
**Version change**: X.Y.Z → A.B.C (<major|minor|patch> update)
**OS variants affected**: Ubuntu 22.04, Ubuntu 24.04, Azure Linux 3.0 (list all)
**OS variants NOT updated**: <list any missing, or "None — full coverage">Detailed changelog between versions: Use web search, GitHub releases, or upstream project documentation to find the exact differences between the old and new version. Present each change as a line item with its own risk tag:
### Changes between X.Y.Z and A.B.C
| Change | Description | Risk |
|--------|-------------|------|
| Feature | <brief description of new feature> | 🟢 Low / 🟡 Medium / 🔴 High |
| Bug fix | <brief description of bug fixed> | 🟢 Low / 🟡 Medium / 🔴 High |
| Breaking | <description of breaking change> | 🔴 High |
| Security | CVE-YYYY-XXXXX: <description> | 🟢 Low / 🟡 Medium / 🔴 High |
| Deprecation | <what was deprecated and migration path> | 🟡 Medium / 🔴 High |
| Config change | <default value changed or option removed> | 🟡 Medium / 🔴 High |
| Performance | <perf improvement or regression> | 🟢 Low / 🟡 Medium |For each individual change, assess risk by considering:
If upstream changelog is unavailable, explicitly state: "Upstream changelog not found for this version range. Manual testing recommended before merge."
Overall risk assessment:
### Overall Risk: 🟢 Low / 🟡 Medium / 🔴 High
**Justification**: <1-2 sentence summary of why this risk level was chosen>
**Recommendation**: Approve / Request more info / Flag for manual testingDynamic Dependency Tracing:
source statements in bash scripts to trace dependency chainsvhdbuilder/packer/) that reference changed filesparts/common/components.json for Renovate updatesHistorical Context:
Test Coverage Assessment:
Report only substantive findings that the changed code supports. Each finding must identify a concrete failure mode.
For each finding:
Risk indicators to include:
Severity (pick one):
Category (pick one):
If there are no substantive findings, return no findings.
© Azure, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in .github/skills/code-review of Azure/AgentBaker.
Open the folder on GitHubat commit b726787
Azurite Pull Request Review next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Azurite Pull Request Review this skillAzure/AgentBaker | 157 | — | ~3.9k | Automated safety check: Pass | MIT | |
| Code ReviewAzure/Azurite | 2.3k | — | ~734 | Automated safety check: Pass | MIT | |
| Open Code Review CLIalibaba/open-code-review | 44k | — | ~3.1k | Automated safety check: Pass | Apache-2.0 | |
| Code Reviewyaklang/yakit | 7.8k | — | ~1.4k | Automated safety check: Notes | AGPL-3.0 | |
| Verdaccio Code Reviewverdaccio/verdaccio | 18k | — | ~853 | Automated safety check: Pass | MIT | |
| Code Reviewoaslananka/kicad-mcp-pro | 119 | — | ~3.9k | Automated safety check: Pass | MIT |
Azure/Azurite
Review Azurite pull requests with service-aware checks for Blob, Queue, and Table behavior, API compatibility, tests, and release notes.
alibaba/open-code-review
Runs the ocr command-line tool to review Git changes, a commit or a branch comparison with an AI model, returning line-level comments and optionally applying fixes.
yaklang/yakit
对 Yakit 仓库的代码改动做规范化 code review:按代码逻辑、TS 定义、UI 引用与 Props、CSS 样式、依赖版本、配置项六个维度审查,检查测试用例缺失,强制执行 tsc 类型检查与 vitest 测试验证,输出「结果汇总 / 明细解释 / 合并结论」三块报告,经用户确认后写入文件。当用户要求 review、审查、评审代码改动,或在提交、合并、提 PR…
verdaccio/verdaccio
Reviews a verdaccio diff, branch or PR against the repository's review guide, verifies each finding in the code and reports only actionable issues.
oaslananka/kicad-mcp-pro
A skill your agent uses for GitHub Copilot pull request and code reviews in oaslananka/kicad-mcp-pro.
Azure/sap-automation
Review pull requests in the SAP Deployment Automation Framework.
Works with
Categories
Reviews Azurite pull requests with checks for Blob, Queue and Table API compatibility, auth paths, persistence, tests and changelog, ending in a fixed comment format. The review focuses on whether changes keep Azure Storage API compatibility for the affected service (blob, queue, table or shared code), whether authentication, authorization and request validation paths regress (SharedKey, SAS, OAuth, public access), whether persistence changes work for both the default Loki metadata store and SQL-backed metadata, and whether generated protocol or model code stays aligned with its handlers and tests.
Azurite Pull Request Review fits situations like: reviewing a pull request to the Azurite storage emulator; checking that a change preserves Blob, Queue or Table API behavior; deciding whether a user-visible change needs a ChangeLog entry; verifying persistence changes against both metadata store types.
Run `npx skills add Azure/AgentBaker --skill code-review -a claude-code`. Or copy the skill folder (.github/skills/code-review in Azure/AgentBaker) into .claude/skills/code-review in your project. Claude Code loads it when a task matches its description.
Run `npx skills add Azure/AgentBaker --skill code-review -a codex`. Or copy the skill folder (.github/skills/code-review in Azure/AgentBaker) into .agents/skills/code-review in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add Azure/AgentBaker --skill code-review -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/code-review, .gemini/skills/code-review, .github/skills/code-review and .opencode/skills/code-review in your project.
SKILL.md names no scripts, command-line tools or credentials: Azurite Pull Request Review is instructions for the agent only. Our summary lists: A checkout of the Azurite repository; Node.js and npm to run lint, build and tests.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Azurite Pull Request Review is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 3.9k tokens (SKILL.md is roughly 16k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Azurite Pull Request Review: Code Review (Azure/Azurite, 2.3k stars), Open Code Review CLI (alibaba/open-code-review, 44k stars), Code Review (yaklang/yakit, 7.8k stars) and Verdaccio Code Review (verdaccio/verdaccio, 18k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
Azure (a GitHub organization, an official publisher) maintains it in Azure/AgentBaker, which has 157 GitHub stars. The repository was last updated on October 7, 2026.
Source: Azure/AgentBaker on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.