Agent skill

Cc Update Review

by Chachamaru127 in Chachamaru127/claude-code-harness

Quality guardrail for Claude/Codex update integration. An agent skill from Chachamaru127/claude-code-harness.

MITAuto-check: notesAI & LLM Engineering

Install Cc Update Review

skills CLI
$ npx skills add Chachamaru127/claude-code-harness --skill cc-update-review -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install Chachamaru127/claude-code-harness cc-update-review --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/Chachamaru127/claude-code-harness.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/cc-update-review .claude/skills/cc-update-review && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
cc-update-review
GitHub stars
3.2k
Token cost
~1.6k tokens
SKILL.md length
472 words
Files
1
Skills in repo
25
Repo updated
First seen
Licence
MIT

At a glance

Quality guardrail for Claude/Codex update integration. An agent skill from Chachamaru127/claude-code-harness.

  • Works in 2 steps: 呼び出し元の /harness-review が PR diff /… → このスキル自身が read-only Bash で git status…
  • AI & LLM Engineering work in your project
  • SKILL.md covers Quick Reference, 差分入力の取得, 前提チェック and A/B/C/P 分類, plus 3 more sections
  • Calls git and codex

What it does

Cc Update Review is an agent skill from Chachamaru127/claude-code-harness. Quality guardrail for Claude/Codex update integration. Detects doc-only Feature Table additions and requires implementation or explicit planning. Internal use only.

Its SKILL.md is about 1.6k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in AI & LLM Engineering. It works with Git. The repository describes itself as: Claude Code Dedicated Development Harness - Achieving High-Quality Development Through an Autonomous Plan→Work→Review Cycle. The licence is MIT.

When your agent uses it

  • AI & LLM Engineering work in your project

Example prompts

  • “/cc-update-review”

Requirements

  • Pre-approved tools (allowed-tools): Read, Grep, Glob, Bash

Workflow steps

2 steps, taken from the first numbered list in SKILL.md.

  1. 呼び出し元の /harness-review が PR diff / changed files / Feature Table 追加行を渡す
  2. このスキル自身が read-only Bash で git status --short, git diff --name-only, git diff -- docs/CLAUDE-feature-table.md, git show --stat --name-only…

What it can do on your machine

Read from SKILL.md and the folder at commit 2b2b748. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Read
    • Grep
    • Glob
    • Bash

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • git
    • codex

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use git, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Cc Update Review loads about 1.6k tokens when it runs. Until then it costs about 45 tokens; SKILL.md has 472 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~45
When it runs · the whole SKILL.md, loaded when a task matches
~1.6k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NotePre-approves every shell command (allowed-tools: Bash)SKILL.md
    allowed-tools: Read, Grep, Glob, Bash

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from Chachamaru127/claude-code-harness at commit 2b2b748, republished under its MIT licence (© Chachamaru127). 472 words, ~1,644 tokens.

Download SKILL.mdSave it as .claude/skills/cc-update-review/SKILL.md (or your agent's skills folder).
name
cc-update-review
description
Quality guardrail for Claude/Codex update integration. Detects doc-only Feature Table additions and requires implementation or explicit planning. Internal use only.
allowed-tools
Read, Grep, Glob, Bash
description-en
Quality guardrail for Claude/Codex update integration. Detects doc-only Feature Table additions and requires implementation or explicit planning. Internal use…
description-ja
Claude/Codex upstream update 統合の品質ガードレール。Feature Table 追加時に「書いただけ」を検出し、実装または Plans 化を強制する。内部専用。
user-invocable
false
disable-model-invocation
true

Claude/Codex Update Review ガードレール

Claude Code / OpenAI Codex のアップデート統合時に「Feature Table に書いただけ」を防止する品質ガードレール。 Feature Table への追加が実装・検証・明示的な将来タスク化を伴っているかを分類し、不足があれば実装案を強制出力する。

Quick Reference

以下の状況でこのスキルがトリガーされる:

  • Claude Code / Codex upstream update 統合 PR のレビュー時
  • docs/CLAUDE-feature-table.md に新行が追加された diff を検出した時
  • /harness-review が upstream update 統合 PR と判定した場合の内部呼び出し
  • claude-codex-upstream-update スキル更新のレビュー時

トリガーしない状況:

  • 通常の実装作業
  • Feature Table / upstream 追従に関係しない変更
  • セットアップ・初期化作業

差分入力の取得

このスキルは diff-aware review 専用のため、必ず以下のどちらかでレビュー対象差分を確定する。

  1. 呼び出し元の /harness-review が PR diff / changed files / Feature Table 追加行を渡す
  2. このスキル自身が read-only Bash で git status --short, git diff --name-only, git diff -- docs/CLAUDE-feature-table.md, git show --stat --name-only などを実行して確認する

Bash は read-only git inspection のみに使う。テスト実行、format、生成、network access、ファイル変更を伴うコマンドは実行しない。 diff が取得できない場合は B: 書いただけ 0 件 と推定せず、「差分未提供のため分類不能」としてレビューを止める。

前提チェック

レビュー冒頭で必ず確認する:

  • diff source が呼び出し元提供または read-only git inspection のどちらかで確定しているか
  • skills/ や hooks/ を編集した PR の場合、直後に /reload-plugins を実行して runtime cache を更新したか({skills,hooks}/** ガイドライン準拠)
  • upstream のバージョン別分解表があるか
  • Claude Code の一次情報 URL が anthropics/claude-code または公式 docs になっているか
  • Codex の一次情報 URL が openai/codex/releases または OpenAI 公式記事になっているか
  • B: 書いただけ が残っていないか
  • skill mirror を触る場合、skills/, codex/.codex/skills/, .agents/skills/ の差分が意図通りか

禁止する古い参照:

  • 旧 TypeScript guardrail path
  • 旧 TypeScript implementation glob
  • 旧 Codex feature-table path
  • 旧 Codex plugin directory
  • 旧 Codex state directory を現行正本として扱う記述
  • 存在しない Anthropic 側 Codex repo URL

A/B/C/P 分類

Feature Table に追加された各項目を、以下の A/B/C/P のいずれかに分類する。

(A) 実装あり

定義: Feature Table の追加に対応する hooks / settings / Go / scripts / agents / skills / tests の変更が同じ PR に含まれている。

判定条件:

  • Feature Table の行で言及されている機能に関連するファイルが変更されている
  • hooks/hooks.json, .claude-plugin/hooks.json, .claude-plugin/settings.json, go/internal/guardrail/, go/internal/hookhandler/, scripts/, agents/, skills/, tests/ のいずれかに実体差分がある
  • 対象テストまたは検証スクリプトで固定されている

例:

Feature Table 追加対応する実装変更判定
AskUserQuestion updatedInputGo handler + hooks wiring + upstream integration testA
sandbox.network.deniedDomains.claude-plugin/settings.json + jq testA
find -delete hardeninggo/internal/guardrail/ + unit testA

結果: OK。追加のアクション不要。


(B) 書いただけ

定義: Feature Table にのみ行が追加され、Harness 側の実装変更も Plans 化もない。かつ upstream 自動継承にも該当しない。

判定条件:

  • Feature Table に新行がある
  • 同じ PR 内で関連する実装 / test / skill / Plans の変更がない
  • Harness が独自の付加価値を提供すべき機能である

例:

Feature Table 追加対応する実装変更判定
PreCompact hookなしB
permission hardeningsettings / guardrail / tests の確認なしB
Codex marketplacePlans への切り出しなしB

結果: NG。PR をブロックし、実装案または Plans 化を要求する。


Show full SKILL.md (182 more words)Show less
(C) upstream 自動継承

定義: Claude Code / Codex 本体のパフォーマンス改善・バグ修正・内部最適化等で、Harness 側の変更が不要な項目。

判定条件:

  • upstream 本体の修正であり、Harness がラップ・拡張する余地がない
  • Harness の settings / hooks / guardrail / workflow / tests に影響しない
  • Feature Table に「upstream 自動継承」または「CC 自動継承 / Codex 側自動継承」と明記されている

注意:

  • permission / sandbox / security / Bash allowlist / MCP trust boundary は安易に C にしない
  • その項目が Harness の独自 guardrail や settings に影響しないことを確認してから C にする
  • Claude Code 2.1.113 の hardening は、sandbox.network.deniedDomains, wrapper Bash deny, find -exec/-delete, macOS dangerous rm paths を確認するまで C 判定しない

例:

Feature Table 追加理由判定
Agent Teams permission dialog crash fixCC 本体の crash fix。Harness 側変更不要C
Codex Guardian timeout wordingCodex 側 UX 修正。Harness surface なしC

結果: OK。ただし理由を明記する。


(P) Plans 化

定義: 今回は直接実装しないが、Harness に取り込む価値があるため Plans.md に明示タスクとして残す項目。

判定条件:

  • Feature Table の付加価値列が A: 将来タスク化 または P: Plans 化 として読める
  • Plans.md に対応タスクがあり、setup / guardrails / memory / Codex workflow など実装面が明記されている
  • alpha release や大規模設計変更など、即実装しない理由が書かれている

例:

Feature Table 追加Plans への切り出し判定
Codex marketplace / MCP AppsCodex workflow 比較軸タスクP
Codex 0.122.0-alphastable 化後の compare 調査タスクP

結果: OK。次回 cycle で拾える。

Upstream update PR チェックリスト

markdown
## Claude/Codex update 統合チェックリスト

### 1. 一次情報と分解表
- [ ] diff source が呼び出し元提供または read-only git inspection のどちらかで確定している
- [ ] Claude / Codex の公式 URL を確認した
- [ ] Version / Upstream item / Category / Harness surface / Action の表がある
- [ ] alpha / stable / docs-only の区別がある

### 2. Feature Table 差分
- [ ] `docs/CLAUDE-feature-table.md` の追加行を列挙した
- [ ] 各行に A / C / P のいずれかが付いている
- [ ] B が 0 件である

### 3. カテゴリ別の確認
- [ ] (A) 実装あり: 対応する実装ファイルとテストがある
- [ ] (B) 書いただけ: 0 件。残る場合は PR ブロック
- [ ] (C) 自動継承: permission / sandbox / security / workflow 影響を確認済み
- [ ] (P) Plans 化: `Plans.md` に将来タスクがある

### 4. Mirror と stale path
- [ ] `skills/` と `codex/.codex/skills/` の意図しない drift がない
- [ ] `.agents/skills/` が存在する場合、Claude/Codex 表記が壊れていない
- [ ] 旧 TypeScript guardrail path、旧 Codex plugin directory、旧 Codex feature-table path などの旧参照がない

### 5. CHANGELOG / tests
- [ ] CHANGELOG に「今まで / 今後」または相当する user-facing 説明がある
- [ ] upstream integration test または対象 unit test が追加 / 更新されている

カテゴリ B 検出時の出力フォーマット

カテゴリ B が 1 件以上検出された場合、以下のフォーマットで実装案を出力する。 このフォーマットの出力は必須であり、省略は許可されない。

markdown
## カテゴリ B 検出: 実装案

### B-{番号}. {Feature Table の項目名}

**現状**: Feature Table に記載のみ。Harness 側の実装 / 検証 / Plans 化なし。

**Harness ならではの付加価値**:
{この機能を Harness がどう活用すべきかの具体的な説明}

**実装案**:

| 対象ファイル | 変更内容 |
|------------|---------|
| `{ファイルパス}` | {具体的な変更内容} |
| `{ファイルパス}` | {具体的な変更内容} |

**ユーザー体験の改善**:
- 今まで: {現在のユーザー体験}
- 今後: {実装後のユーザー体験}

**実装の優先度**: {高 / 中 / 低}
**推定工数**: {小 / 中 / 大}

関連スキル

  • claude-codex-upstream-update - upstream 差分調査と実装 cycle
  • harness-review - コードレビュー
  • harness-work - カテゴリ B / P の実装
  • memory - 分類基準の SSOT 化

© Chachamaru127, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/cc-update-review of Chachamaru127/claude-code-harness.

Open the folder on GitHubat commit 2b2b748

Compare with similar skills

Cc Update Review next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Cc Update Review compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Cc Update Review this skillChachamaru127/claude-code-harness3.2k—~1.6kAutomated safety check: NotesMIT
Opt Trace Miningalibaba/atrex-kernel-agent168—~4.4kAutomated safety check: PassApache-2.0
Ownmem Dashboardgrpcer/ownmem423—~563Automated safety check: PassApache-2.0
Agent Evalaffaan-m/ECC277k3 repos~1.1kAutomated safety check: PassMIT
Use Shared Credentialyc-software/qm15k—~1.3kAutomated safety check: PassMIT
Gltf Asset Optimizationelodin-sys/elodin547—~1kAutomated safety check: PassApache-2.0

Similar skills

  • Opt Trace Mining

    alibaba/atrex-kernel-agent

    Mine a per-kernel optimization trace — a git repository capturing successive versions of one kernel being optimized — into structured, gate-validated optimization-experience records for the GPU…

    168 GitHub stars~4.4k tokensUpdated yesterday
    AI & LLM EngineeringAuto-check passed
  • Ownmem Dashboard

    grpcer/ownmem

    Open OwnMem Console, the local dashboard for this repository's memory.

    423 GitHub stars~563 tokensUpdated 5 days ago
    AI & LLM EngineeringAuto-check passed
  • Agent Eval

    affaan-m/ECC

    Head-to-head comparison of coding agents (Claude Code, Aider, Codex, etc.) on custom tasks with pass rate, cost, time, and consistency metrics.

    277k GitHub starsUsed in 3 repos~1.1k tokens
    AI & LLM EngineeringAuto-check passed
  • Use Shared Credential

    yc-software/qm

    When you need to call a service the org has a SHARED credential for (a SERP/search key, a paid-API key, a data-vendor feed, a Git remote) — and the platform has told you that credential is available…

    15k GitHub stars~1.3k tokensUpdated today
    AI & LLM EngineeringAuto-check passed
  • Gltf Asset Optimization

    elodin-sys/elodin

    Reduce the size of glTF/GLB 3D assets to cut Git LFS bandwidth/storage while keeping them loadable by the editor's Bevy 0.18 glTF loader.

    547 GitHub stars~1k tokensUpdated yesterday
    AI & LLM EngineeringAuto-check passed
  • Reliability Concurrency

    ChatbotXIO/ChatbotX

    A skill your agent uses when writing code that runs concurrently in ChatbotX — BullMQ worker consumers, sharded DB migrations, embedding replace-writes, or any multi-step operation that could be…

    885 GitHub stars~735 tokensUpdated 2 days ago
    AI & LLM EngineeringAuto-check passed

More from Chachamaru127/claude-code-harness

All 25 skills in this repo
  • CI Failure Triage and Repair

    Chachamaru127/claude-code-harness

    Diagnoses failing CI pipelines and tests, deciding first whether the test or the implementation is at fault, and hands hard cases to a dedicated fixer subagent.

    3.2k GitHub starsUsed in 1 repo~1.1k tokens
    Auto-check: notes
  • Cursor Composer Task Delegate

    Chachamaru127/claude-code-harness

    Hands one implementation task to Cursor Composer in an isolated git worktree, then reviews its diff and cherry-picks the result into the main branch.

    3.2k GitHub stars~4.4k tokensUpdated 6 days ago
    Auto-check: notes
  • Acceptance Demo Generator

    Chachamaru127/claude-code-harness

    Renders a single HTML page showing each acceptance criterion as verified or not, with a ship, wait, or reject recommendation for non-engineers.

    3.2k GitHub stars~3.4k tokensUpdated 6 days ago
    Auto-check: notes
  • Harness Long-Running Task Loop

    Chachamaru127/claude-code-harness

    Repeats a long task as a series of scheduled wake-ups, each re-entering with fresh context and calling harness-work for one task per cycle.

    3.2k GitHub stars~2.3k tokensUpdated 6 days ago
    Auto-check: notes
  • Harness Plan

    Chachamaru127/claude-code-harness

    Creates and maintains Plans.md task plans with a spec delta, updates task markers and syncs plan progress with the implementation.

    3.2k GitHub stars~3.7k tokensUpdated 6 days ago
    Auto-check: notes
  • Harness Release

    Chachamaru127/claude-code-harness

    Runs a release for any project that keeps a Keep a Changelog file on GitHub, from version bump to merge, tag and GitHub Release after a single approval.

    3.2k GitHub stars~4.4k tokensUpdated 6 days ago
    Auto-check: notes

Works with

Questions about Cc Update Review

What does Cc Update Review do?

Quality guardrail for Claude/Codex update integration. An agent skill from Chachamaru127/claude-code-harness. Cc Update Review is an agent skill from Chachamaru127/claude-code-harness. Quality guardrail for Claude/Codex update integration.

When should I use Cc Update Review?

Cc Update Review fits situations like: AI & LLM Engineering work in your project.

How do I install Cc Update Review in Claude Code?

Run `npx skills add Chachamaru127/claude-code-harness --skill cc-update-review -a claude-code`. Or copy the skill folder (skills/cc-update-review in Chachamaru127/claude-code-harness) into .claude/skills/cc-update-review in your project. Claude Code loads it when a task matches its description.

How do I install Cc Update Review in Codex?

Run `npx skills add Chachamaru127/claude-code-harness --skill cc-update-review -a codex`. Or copy the skill folder (skills/cc-update-review in Chachamaru127/claude-code-harness) into .agents/skills/cc-update-review in your project. Codex loads it when a task matches its description.

Can I use Cc Update Review in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add Chachamaru127/claude-code-harness --skill cc-update-review -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/cc-update-review, .gemini/skills/cc-update-review, .github/skills/cc-update-review and .opencode/skills/cc-update-review in your project.

What does Cc Update Review need to run?

Going by SKILL.md and its folder, Cc Update Review needs the command-line tools its instructions call (git and codex). Its frontmatter pre-approves these tools: Read, Grep, Glob, Bash.

Does Cc Update Review access the network?

SKILL.md contains no URLs. Its commands use git, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Cc Update Review safe to install?

Our automated static check of SKILL.md found notes only (pre-approves every shell command (allowed-tools: bash)), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Cc Update Review use?

Cc Update Review is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Cc Update Review use?

About 1.6k tokens (SKILL.md is roughly 6.6k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Cc Update Review?

Skills that share tags, products or a category with Cc Update Review: Opt Trace Mining (alibaba/atrex-kernel-agent, 168 stars), Ownmem Dashboard (grpcer/ownmem, 423 stars), Agent Eval (affaan-m/ECC, 277k stars) and Use Shared Credential (yc-software/qm, 15k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Cc Update Review?

Chachamaru127 (a GitHub user) maintains it in Chachamaru127/claude-code-harness, which has 3,156 GitHub stars. The repository holds 25 skills in this directory. The repository was last updated on October 5, 2026.

Source: Chachamaru127/claude-code-harness on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.