Official agent skill

Biome Code Review

by biomejs in biomejs/biome

Use only for reviewing completed Biome PRs, branches, commit ranges, diffs, or working trees against business logic and requirements.

OfficialApache-2.0Auto-check passedDevelopment

Install Biome Code Review

skills CLI
$ npx skills add biomejs/biome --skill biome-code-review -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install biomejs/biome biome-code-review --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/biomejs/biome.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/biome-code-review .claude/skills/biome-code-review && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
biome-code-review
GitHub stars
26k
Token cost
~2.8k tokens
SKILL.md length
1,197 words
Files
5 (incl. references)
Skills in repo
12
Repo updated
First seen
Licence
Apache-2.0

At a glance

Use only for reviewing completed Biome PRs, branches, commit ranges, diffs, or working trees against business logic and requirements.

  • Works in 5 steps: Read branch, upstream, and every… → Use the supplied base when present.… → Fetch the selected base once. → …
  • Tasks that involve Linting and formatting
  • SKILL.md covers Invocation, Safety Boundary, Establish Scope and Behavioral Boundary, plus 6 more sections
  • Calls gh and git

What it does

Biome Code Review is an agent skill from biomejs/biome, published by the product's own GitHub organization. Use only for reviewing completed Biome PRs, branches, commit ranges, diffs, or working trees against business logic and requirements. Excludes broad code-quality and process audits, triage, reproduction, and implementation.

Its SKILL.md is about 2.8k tokens, which your agent loads only when the skill is triggered. The skill folder holds 5 other files, including reference files (for example `references/documentation-and-process.md`, `references/repository-and-subsystems.md` and `references/rust-safety-and-syntax.md`). Compatibility notes: Designed for read-only review of the Biome codebase (github.com/biomejs/biome).

It sits in Development, covering Linting and formatting, Code review and Code quality. The repository describes itself as: A toolchain for web projects, aimed to provide functionalities to maintain them. Biome offers formatter and linter, usable via CLI and LSP. The licence is Apache-2.0.

When your agent uses it

  • Tasks that involve Linting and formatting
  • Tasks that involve Code review
  • Tasks that involve Code quality

Example prompts

  • “/biome-code-review”

Requirements

  • Compatibility (from SKILL.md): Designed for read-only review of the Biome codebase (github.com/biomejs/biome).

Workflow steps

5 steps, taken from the first numbered list in SKILL.md.

  1. Read branch, upstream, and every untracked path with git status --short --branch --untracked-files=all.
  2. Use the supplied base when present. Otherwise, use the tracking branch when it is origin/main or origin/next, or compare merge bases…
  3. Fetch the selected base once.
  4. Diff the merge base through the working tree so committed, staged, and unstaged changes are included.
  5. Read every reported untracked file; untracked tests and changesets are part of the review.

What it can do on your machine

Read from SKILL.md and the folder at commit c870caa. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • gh
    • git

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use gh and git, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

  • Compatibility

    Designed for read-only review of the Biome codebase (github.com/biomejs/biome).

    From compatibility in the SKILL.md frontmatter.

Context cost

Biome Code Review loads about 2.8k tokens when it runs, and up to ~6.2k if it reads all its reference files. Until then it costs about 60 tokens; SKILL.md has 1,197 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~60
When it runs · the whole SKILL.md, loaded when a task matches
~2.8k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~6.2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from biomejs/biome at commit c870caa, republished under its Apache-2.0 licence (© biomejs). 1,197 words, ~2,832 tokens.

Download SKILL.mdSave it as .claude/skills/biome-code-review/SKILL.md (or your agent's skills folder). This skill also uses 4 other files; get the full folder from GitHub.
name
biome-code-review
description
Use only for reviewing completed Biome PRs, branches, commit ranges, diffs, or working trees against business logic and requirements. Excludes broad code-quality and process audits, triage, reproduction, and implementation.
compatibility
Designed for read-only review of the Biome codebase (github.com/biomejs/biome).
metadata.repository
biomejs/biome
metadata.mode
read-only

Biome Code Review

Review changes read-only against business requirements and applicable behavioral, architectural, and subsystem constraints.

Invocation

Delegate completed reviews to a fresh subagent when available. Supply only:

  • the review scope;
  • the intended business requirements, including constraints the repository cannot establish.

To avoid bias, omit implementation details, suspected defects, priority files, prior findings, and expected review outcomes.

Review subagents must not delegate again. Without subagents, review the complete scope directly.

Treat delegated findings as candidates; the parent must validate them before confirming or acting.

Safety Boundary

Reviewers and validating parents must preserve the worktree. Authorized implementation follows validation, outside this skill.

  • Do not create, edit, move, or delete files.
  • Do not run project code, builds, tests, formatters, linters, codegen, benchmarks, package managers, LSPs, or daemons.
  • Do not run mutating Git or GitHub commands except the single base-branch fetch allowed below.
  • Do not use shell pipelines, scripts, sed, or awk to inspect source. Use file reads, globs, and text search.

Shell is limited to these review commands:

text
git fetch origin <main|next>
git status --short --branch --untracked-files=all
git branch --show-current
git rev-parse ...
git merge-base ...
git --no-pager diff --no-ext-diff --no-textconv ...
git --no-pager show --no-ext-diff --no-textconv ...
git --no-pager log ...
git ls-files ...
gh pr view <number> [--json ...]
gh pr diff <number>
gh issue view <number> [--json ...]

One fetch of the resolved base is allowed. If it fails, continue with the local remote-tracking branch and disclose that it may be stale. Documentation lookups are allowed only when checked-out source cannot settle an external language or API contract.

Establish Scope

Use the supplied PR, range, diff, files, or base; exclude unrelated worktree changes.

For a PR number, read its title, body, base, and files with gh pr view, then read gh pr diff. Do not check it out.

When no explicit PR, range, diff, or file scope is supplied, review the current branch and working tree:

  1. Read branch, upstream, and every untracked path with git status --short --branch --untracked-files=all.
  2. Use the supplied base when present. Otherwise, use the tracking branch when it is origin/main or origin/next, or compare merge bases against both branches and choose the actual ancestor. Ask only when the result is genuinely ambiguous.
  3. Fetch the selected base once.
  4. Diff the merge base through the working tree so committed, staged, and unstaged changes are included.
  5. Read every reported untracked file; untracked tests and changesets are part of the review.

Never fall back to HEAD as the base without saying so. That would omit committed branch changes.

Infer intent from the brief, PR/commit text, linked issue, tests, and code; explicit requirements take precedence. A steered brief still requires reviewing the entire supplied scope; disclose the steer.

Behavioral Boundary

Before tracing beyond the diff, record intended behavior, requirements, and applicable behavioral, architectural, and subsystem constraints with sources. Report violations or concrete avoidable costs/failures introduced, worsened, or newly exposed by the change.

Read surrounding code only to verify changed behavior and constraints; full-file reads do not expand scope. Stop tracing once the question is settled.

Apply guidance only to changed or directly affected code; preferences are not violations, and requirements must not be invented. Exclude unrelated cleanup, defects, process checks, and speculative optimization, even from optional suggestions or questions.

Gather Context

  • Read every changed file in full.
  • Inspect affected callers, registrations, generated counterparts, neighbors, and tests only to verify scoped behavior and constraints.
  • Read root AGENTS.md and only the relevant sections of CONTRIBUTING.md or crate guides.
  • Load relevant skills and references for contracts, not additional objectives or permission to execute workflows.
  • Prefer checked-out source over documentation or memory.

Use this routing table instead of loading every reference:

In-scope question concernsLoad
Grammar, lint, parser, formatter, diagnostics, types, tests, generated filesrepository-and-subsystems.md and the matching implementation skill
biome_service, workspace DB, CLI/LSP execution, cancellationworkspace-access.md
Rust production totality, failure paths, recursion, syntax text, ranges, allocation, or API shaperust-safety-and-syntax.md
Documentation describing required behavior or affected contractsdocumentation-and-process.md

Review Method

Perform two passes:

  1. Behavior: trace requirements, control and data flow, and relevant ownership and execution contracts.
  2. Implementation: inspect every human-written changed line and relevant test against those requirements and affected behavior.

Try to falsify claimed requirements such as zero-copy, unchanged behavior, faster execution, or no new dependencies. Rate counterexamples by impact.

Check required paths, callers, variants, and failure behavior before supporting artifacts. Behavioral failures require reachability; constraint violations, including production totality, require evidence of an unmet constraint, not a runtime counterexample.

Show full SKILL.md (505 more words)Show less

Cross-Cutting Checks

  • Verify a bug fix's regression test reaches the changed behavior and fails without the fix.
  • Read snapshot changes as expected behavior. A snapshot can faithfully record an incorrect range, message, or output.
  • A safe fix must preserve semantics for every reachable case and stop the rule from reporting after application.
  • Check required registration and generated artifacts against affected sources and AGENTS.md; honor CI Autofix exceptions.
  • Consolidate repeated symptoms under their root cause.

Finding Threshold

Report only actionable, in-scope issues supported by inspected code.

  • Cite the unmet requirement, violated contract, or concrete avoidable cost and its connection to the diff.
  • For behavioral failures, give the trigger, expected versus actual behavior, and impact. For test gaps, name the required scenario and defect to catch.
  • Check guards, types, caller invariants, and tests for counter-evidence.
  • Cite the smallest relevant changed range.
  • Give minimal remediation, not a patch.

Put unresolved in-scope requirements or correctness assumptions under questions, not findings.

Production Totality

Report production unwrap, expect, indexing, slicing, panic macros, integer division/remainder, and other partial operations unless release-mode control flow, types, or API contracts establish totality. No concrete failing input is required.

Limit this to added or modified operations, or existing operations whose preconditions or reachability the diff affects. Check relevant guards and callers; proofs need not be local.

Cite the unmet precondition and inspected evidence without claiming a demonstrated panic. See operation-specific checks.

Parent Validation

Validate every candidate independently; confidence is not evidence.

  1. Read the cited diff, source, callers or tests, and claimed requirement, constraint, or cost; the summary is not evidence.
  2. Try to disprove claims using guards, types, call order, tests, and pre-change behavior. Behavioral failures require reachability; totality findings require checking release-mode control flow, types, and API contracts, not a failing input.
  3. Apply the same scope and finding threshold; verify applicable constraints, avoidable costs, and proportional remediation. Reject out-of-scope claims even if correct; never invent requirements.
  4. Mark each validated, rejected, or unresolved, citing supporting or specific missing evidence. Seek targeted clarification when needed.
  5. Only validated findings qualify for confirmation or authorized remediation outside review. Note rejected/unresolved candidates in validation status; unresolved requirements belong under questions and never justify fixes.

Report Format

Return only raw Markdown in one fenced block, findings first by severity.

Every finding starts with exactly one <severity>/<area> token.

SeverityMeaning
highMaterial regression, corruption or data loss, exploitable security/privacy failure, availability failure, broad false positive, incorrect safe fix, user-reachable panic, or a change that defeats its core requirement
mediumCredible edge-case failure, missing required variant or registration, demonstrated performance regression, material test gap for required behavior, or unjustified in-scope production partial operation
lowLocalized correctness, maintainability, documentation, or implementation-constraint issue that meets the finding threshold

Areas: design, correctness, security, privacy, availability, performance, completeness, error-handling, tests, maintainability, documentation, changeset, process.

Areas classify eligible findings; they do not expand scope.

Use exactly this format:

md
```
## Findings

- `high/correctness` `path/to/file.rs:42` - Short title. Cite the requirement, trigger, expected/actual behavior, impact, and minimal remediation.
- `medium/error-handling` `path/to/file.rs:57` - Missing totality guarantee. Cite the affected operation, unmet precondition, inspected evidence, and minimal remediation; do not claim a demonstrated panic.

## Questions

- Include only unresolved assumptions that affect correctness. Omit this section when there are none.

## Review Status

Scope: `<supplied diff or base-sha through head or working tree>`, `<n>` files, plus listed in-scope untracked files.
Requirements: `<intended behavior, applicable constraints, and sources>`.
Brief: independent | steered toward `<area>`; full supplied scope reviewed.
Validation: Static review only; no project code was run.
Parent validation: not delegated | pending: parent must independently check source and requirements before confirming or acting | completed: `<evidence-backed candidate dispositions>`.
Fetch: updated `origin/<base>` | failed, local `origin/<base>` used | not needed.
```

Use No findings. under ## Findings when empty. Severity reflects impact, not confidence. Subagents mark parent validation pending; only the parent may mark it completed after validation.

© biomejs, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 4 other files (references) in .agents/skills/biome-code-review of biomejs/biome.

  • SKILL.md
  • references/documentation-and-process.md
  • references/repository-and-subsystems.md
  • references/rust-safety-and-syntax.md
  • references/workspace-access.md

Open the folder on GitHubat commit c870caa

Compare with similar skills

Biome Code Review next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Biome Code Review compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Biome Code Review this skillbiomejs/biome26k—~2.8kAutomated safety check: PassApache-2.0
Uncle Bob Craftsickn33/agentic-awesome-skills47k2 repos~2.6kAutomated safety check: PassMIT
Code Qualitywaybarrios/opencode-power-pack533—~1.8kAutomated safety check: PassMIT
Install Anti-Slop Oxlint Rulesdmmulroy/anti-slop5.3k1 repos~2.2kAutomated safety check: PassMIT
WooCommerce Code Reviewwoocommerce/woocommerce11k3 repos~1.1kAutomated safety check: PassCustom licence
Skill Doli Code ReviewDolibarr/dolibarr7.7k1 repos~1.1kAutomated safety check: PassMIT

Similar skills

  • Uncle Bob Craft

    sickn33/agentic-awesome-skills

    A skill your agent uses when performing code review, writing or refactoring code, or discussing architecture; complements clean-code and does not replace project linter/formatter.

    47k GitHub starsUsed in 2 repos~2.6k tokens
    DevelopmentAuto-check passed
  • Code Quality

    waybarrios/opencode-power-pack

    Agents should invoke this skill for code reviews, linting/formatting setup, maintainability checks, complexity concerns, warning cleanup, coding standards, or quality gates in Rust, TypeScript…

    533 GitHub stars~1.8k tokensUpdated 2 days ago
    DevelopmentAuto-check passed
  • Installs, updates or migrates the vendored anti-slop Oxlint plugin in a repository, keeping local rule changes and the plugin's license and provenance files.

    5.3k GitHub starsUsed in 1 repo~2.2k tokens
    DevelopmentAuto-check passed
  • WooCommerce Code Review

    woocommerce/woocommerce

    Reviews WooCommerce code changes against the project's standards, flagging backend PHP architecture, naming, documentation, data integrity and testing violations.

    11k GitHub starsUsed in 3 repos~1.1k tokens
    DevelopmentAuto-check passed
  • Skill Doli Code Review

    Dolibarr/dolibarr

    Reviews Dolibarr PHP code for compliance with coding standards and security best practices, and fixes identified issues.

    7.7k GitHub starsUsed in 1 repo~1.1k tokens
    DevelopmentAuto-check passed
  • Dignified Python Standards

    docling-project/docling

    Applies opinionated production Python conventions chosen by the project's Python version: modern type syntax, pathlib, explicit checks and interface guidance.

    69k GitHub stars~1.5k tokensUpdated today
    DevelopmentAuto-check passed

More from biomejs/biome

All 12 skills in this repo
  • Changeset

    biomejs/biome

    Official

    A skill your agent uses when a Biome change may affect users and you must decide whether it needs a changeset, choose the release level, or create and edit .changeset/.md release-note text.

    26k GitHub stars~839 tokensUpdated today
    Auto-check passed
  • Doc Comments

    biomejs/biome

    Official

    A skill your agent uses whenever writing or editing Rust //, ///, or //!

    26k GitHub stars~3k tokensUpdated today
    Auto-check passed
  • Official

    A skill your agent uses when biome migrate eslint must preserve configurable ESLint rule options through source-option models, Biome conversions, typed rule variants, and migration fixtures.

    26k GitHub stars~1.4k tokensUpdated today
    Auto-check passed
  • Official

    A skill your agent uses whenever implementing or debugging Biome formatter behavior, IR composition, node rules, layout selection, source-comment handling, verbatim formatting, idempotency, internal…

    26k GitHub stars~2.1k tokensUpdated today
    Auto-check passed
  • Official

    A skill your agent uses when creating or modifying Biome lint rules or assists, including analyzer queries, semantic bindings, rule state, code actions, fix safety, options, registration, and…

    26k GitHub stars~1.6k tokensUpdated today
    Auto-check passed
  • Parser Development

    biomejs/biome

    Official

    A skill your agent uses when implementing or modifying Biome parser behavior, including .ungram grammars, lexers, token sources, parse rules, separated lists, error recovery, and parser fixtures.

    26k GitHub stars~1.2k tokensUpdated today
    Auto-check passed

Categories

Questions about Biome Code Review

What does Biome Code Review do?

Use only for reviewing completed Biome PRs, branches, commit ranges, diffs, or working trees against business logic and requirements. Biome Code Review is an agent skill from biomejs/biome, published by the product's own GitHub organization. Use only for reviewing completed Biome PRs, branches, commit ranges, diffs, or working trees against business logic and requirements.

When should I use Biome Code Review?

Biome Code Review fits situations like: tasks that involve Linting and formatting; tasks that involve Code review; tasks that involve Code quality.

How do I install Biome Code Review in Claude Code?

Run `npx skills add biomejs/biome --skill biome-code-review -a claude-code`. Or copy the skill folder (.agents/skills/biome-code-review in biomejs/biome) into .claude/skills/biome-code-review in your project. Claude Code loads it when a task matches its description.

How do I install Biome Code Review in Codex?

Run `npx skills add biomejs/biome --skill biome-code-review -a codex`. Or copy the skill folder (.agents/skills/biome-code-review in biomejs/biome) into .agents/skills/biome-code-review in your project. Codex loads it when a task matches its description.

Can I use Biome Code Review in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add biomejs/biome --skill biome-code-review -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/biome-code-review, .gemini/skills/biome-code-review, .github/skills/biome-code-review and .opencode/skills/biome-code-review in your project.

What does Biome Code Review need to run?

Going by SKILL.md and its folder, Biome Code Review needs the command-line tools its instructions call (gh and git). Compatibility (from SKILL.md): Designed for read-only review of the Biome codebase (github.com/biomejs/biome)..

Does Biome Code Review access the network?

SKILL.md contains no URLs. Its commands use gh and git, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Biome Code Review safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Biome Code Review use?

Biome Code Review is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Biome Code Review use?

About 2.8k tokens (SKILL.md is roughly 11k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 3.4k tokens, read only when the agent opens those files.

What are the alternatives to Biome Code Review?

Skills that share tags, products or a category with Biome Code Review: Uncle Bob Craft (sickn33/agentic-awesome-skills, 47k stars), Code Quality (waybarrios/opencode-power-pack, 533 stars), Install Anti-Slop Oxlint Rules (dmmulroy/anti-slop, 5.3k stars) and WooCommerce Code Review (woocommerce/woocommerce, 11k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Biome Code Review?

biomejs (a GitHub organization, an official publisher) maintains it in biomejs/biome, which has 25,910 GitHub stars. The repository holds 12 skills in this directory. The repository was last updated on October 8, 2026.

Source: biomejs/biome on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.