Agent skill

Piv Review Changes

by coleam00 in coleam00/skills

Performs a technical code review of recently changed files for bugs, security issues, and standards compliance, then writes a report.

MITAuto-check passedDevelopment

Install Piv Review Changes

skills CLI
$ npx skills add coleam00/skills --skill piv-review-changes -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install coleam00/skills piv-review-changes --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/coleam00/skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/piv-review-changes .claude/skills/piv-review-changes && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
piv-review-changes
GitHub stars
676
Token cost
~699 tokens
SKILL.md length
302 words
Files
1
Skills in repo
34
Repo updated
First seen
Licence
MIT

At a glance

Performs a technical code review of recently changed files for bugs, security issues, and standards compliance, then writes a report.

  • Works in 5 steps: Logic Errors → Security Issues → Performance Problems → …
  • Tasks that involve Code review
  • SKILL.md covers Core Principles, What to Review, Verify Issues Are Real and Output Format, plus 1 more section
  • Calls git

What it does

Piv Review Changes is an agent skill from coleam00/skills. Performs a technical code review of recently changed files for bugs, security issues, and standards compliance, then writes a report. Use before committing, as a pre-commit quality gate.

Its SKILL.md is about 700 tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Development, covering Code review and Quality gates. The repository describes itself as: The agent skills I actually use to build software with coding agents. The PIV loop, planning, worktrees, and the meta-skills for building your own AI Layer. The licence is MIT.

When your agent uses it

  • Tasks that involve Code review
  • Tasks that involve Quality gates

Example prompts

  • “Use the piv-review-changes skill to perform a technical code review of recently changed files for bugs, security issues, and standards compliance…”
  • “/piv-review-changes”

Workflow steps

5 steps, taken from the first numbered list in SKILL.md.

  1. Logic Errors
  2. Security Issues
  3. Performance Problems
  4. Code Quality
  5. Adherence to Codebase Standards and Existing Patterns

What it can do on your machine

Read from SKILL.md and the folder at commit 847be08. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • git

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use git, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Piv Review Changes loads about 699 tokens when it runs. Until then it costs about 51 tokens; SKILL.md has 302 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~51
When it runs · the whole SKILL.md, loaded when a task matches
~699

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from coleam00/skills at commit 847be08, republished under its MIT licence (© coleam00). 302 words, ~699 tokens.

Download SKILL.mdSave it as .claude/skills/piv-review-changes/SKILL.md (or your agent's skills folder).
name
piv-review-changes
description
Performs a technical code review of recently changed files for bugs, security issues, and standards compliance, then writes a report. Use before committing, as a pre-commit quality gate.

Code Review

Perform technical code review on recently changed files.

Core Principles

Review Philosophy:

  • Simplicity is the ultimate sophistication - every line should justify its existence
  • Code is read far more often than it's written - optimize for readability
  • The best code is often the code you don't write
  • Elegance emerges from clarity of intent and economy of expression

What to Review

Start by gathering codebase context to understand the codebase standards and patterns.

Start by examining:

  • CLAUDE.md
  • README.md
  • Key files in the core module
  • Documented standards in the docs directory (and any .claude/references/ docs)

After you have a good understanding, run these commands:

bash
git status
git diff HEAD
git diff --stat HEAD

Then check the list of new files:

bash
git ls-files --others --exclude-standard

Read each new file in its entirety. Read each changed file in its entirety (not just the diff) to understand full context.

For each changed file or new file, analyze for:

  1. Logic Errors

    • Off-by-one errors
    • Incorrect conditionals
    • Missing error handling
    • Race conditions
  2. Security Issues

    • SQL injection vulnerabilities
    • XSS vulnerabilities
    • Insecure data handling
    • Exposed secrets or API keys
  3. Performance Problems

    • N+1 queries
    • Inefficient algorithms
    • Memory leaks
    • Unnecessary computations
  4. Code Quality

    • Violations of DRY principle
    • Overly complex functions
    • Poor naming
    • Missing type hints/annotations
  5. Adherence to Codebase Standards and Existing Patterns

    • Adherence to standards documented in the docs directory
    • Linting, typing, and formatting standards
    • Logging standards
    • Testing standards

Verify Issues Are Real

  • Run specific tests for issues found
  • Confirm type errors are legitimate
  • Validate security concerns with context

Output Format

Save a new file to .claude/code-reviews/[appropriate-name].md

Stats:

  • Files Modified: 0
  • Files Added: 0
  • Files Deleted: 0
  • New lines: 0
  • Deleted lines: 0

For each issue found:

severity: critical|high|medium|low
file: path/to/file.py
line: 42
issue: [one-line description]
detail: [explanation of why this is a problem]
suggestion: [how to fix it]

If no issues found: "Code review passed. No technical issues detected."

Important

  • Be specific (line numbers, not vague complaints)
  • Focus on real bugs, not style
  • Suggest fixes, don't just complain
  • Flag security issues as CRITICAL

© coleam00, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .claude/skills/piv-review-changes of coleam00/skills.

Open the folder on GitHubat commit 847be08

Compare with similar skills

Piv Review Changes next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Piv Review Changes compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Piv Review Changes this skillcoleam00/skills676—~699Automated safety check: PassMIT
Requesting Code ReviewHezaoHezao/poirot2495 repos~1.6kAutomated safety check: PassMIT
Compound Engineering Code ReviewEveryInc/compound-engineering-plugin25k—~2kAutomated safety check: PassMIT
Code Reviewmodimihir07/agentic-os195—~222Automated safety check: PassMIT
Code Reviewnth5693/gemini-kit372—~339Automated safety check: PassMIT
PR Deep VerificationQwenLM/qwen-code28k—~23kAutomated safety check: PassApache-2.0

Similar skills

  • Requesting Code Review

    HezaoHezao/poirot

    Pre-commit review: security scan, quality gates, auto-fix. An agent skill from HezaoHezao/poirot.

    249 GitHub starsUsed in 5 repos~1.6k tokens
    DevelopmentAuto-check passed
  • Compound Engineering Code Review

    EveryInc/compound-engineering-plugin

    Runs a staged pull request or diff review using selected reviewer personas, checking the change against its stated intent and project standards before producing findings.

    25k GitHub stars~2k tokensUpdated 2 days ago
    DevelopmentAuto-check passed
  • Code Review

    modimihir07/agentic-os

    Automated code review with checklist and quality gates. An agent skill from modimihir07/agentic-os.

    195 GitHub stars~222 tokensUpdated 2 mo ago
    DevelopmentAuto-check passed
  • Code Review

    nth5693/gemini-kit

    Systematic multi-perspective code review with consistent quality gates.

    372 GitHub stars~339 tokensUpdated 7 mo ago
    DevelopmentAuto-check passed
  • PR Deep Verification

    QwenLM/qwen-code

    Runs a sandboxed, evidence-based check of one qwen-code pull request, proving its main change against the base build and writing a report with a machine-readable verdict.

    28k GitHub stars~23k tokensUpdated today
    DevelopmentAuto-check passed
  • Gsd Ns Review

    open-gsd/gsd-core

    quality gates | code review debug audit security eval ui. An agent skill from open-gsd/gsd-core.

    10k GitHub starsUsed in 1 repo~304 tokens
    DevelopmentAuto-check passed

More from coleam00/skills

All 34 skills in this repo
  • Ablate AI Layer

    coleam00/skills

    Measure whether a repository's AI instructions still earn their place, by running the same real task many times with the layer intact and with it stripped, then grading every rule against what…

    676 GitHub stars~1.9k tokensUpdated 3 days ago
    Auto-check passed
  • Build Dark Factory

    coleam00/skills

    Take a PRD and build a dark factory around it - a repository that takes work in as an issue and ships validated code out with nobody at the keyboard - one component at a time, into the user's actual…

    676 GitHub stars~12k tokensUpdated 3 days ago
    Auto-check passed
  • Drive Screen

    coleam00/skills

    Take real control of the desktop - list and focus windows, type, paste, click, scroll, and screenshot - on Windows, macOS or Linux, and drive other coding-agent sessions running in terminals.

    676 GitHub stars~5.4k tokensUpdated 3 days ago
    Auto-check passed
  • Second Brain Audit

    coleam00/skills

    Audit any second brain, notes folder, or agent memory for facts that have quietly stopped being true, then fix the worst one so it stops recurring.

    676 GitHub stars~4.6k tokensUpdated 3 days ago
    Auto-check passed
  • Build Signal Engine

    coleam00/skills

    Build a personal signal engine from scratch - a system that reads every source someone cares about each day (changelogs and release notes, communities, feeds, videos, papers), makes a quick decision…

    676 GitHub stars~2.9k tokensUpdated 3 days ago
    Auto-check passed
  • Worktree Create

    coleam00/skills

    Create one or more git worktrees for parallel development, each on its own branch with gitignored config copied in, dependencies installed, and a health check, by fanning out a setup subagent per…

    676 GitHub stars~958 tokensUpdated 3 days ago
    Auto-check passed

Questions about Piv Review Changes

What does Piv Review Changes do?

Performs a technical code review of recently changed files for bugs, security issues, and standards compliance, then writes a report. Piv Review Changes is an agent skill from coleam00/skills. Performs a technical code review of recently changed files for bugs, security issues, and standards compliance, then writes a report.

When should I use Piv Review Changes?

Piv Review Changes fits situations like: tasks that involve Code review; tasks that involve Quality gates.

How do I install Piv Review Changes in Claude Code?

Run `npx skills add coleam00/skills --skill piv-review-changes -a claude-code`. Or copy the skill folder (.claude/skills/piv-review-changes in coleam00/skills) into .claude/skills/piv-review-changes in your project. Claude Code loads it when a task matches its description.

How do I install Piv Review Changes in Codex?

Run `npx skills add coleam00/skills --skill piv-review-changes -a codex`. Or copy the skill folder (.claude/skills/piv-review-changes in coleam00/skills) into .agents/skills/piv-review-changes in your project. Codex loads it when a task matches its description.

Can I use Piv Review Changes in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add coleam00/skills --skill piv-review-changes -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/piv-review-changes, .gemini/skills/piv-review-changes, .github/skills/piv-review-changes and .opencode/skills/piv-review-changes in your project.

What does Piv Review Changes need to run?

Going by SKILL.md and its folder, Piv Review Changes needs the command-line tools its instructions call (git).

Does Piv Review Changes access the network?

SKILL.md contains no URLs. Its commands use git, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Piv Review Changes safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Piv Review Changes use?

Piv Review Changes is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Piv Review Changes use?

About 699 tokens (SKILL.md is roughly 2.8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Piv Review Changes?

Skills that share tags, products or a category with Piv Review Changes: Requesting Code Review (HezaoHezao/poirot, 249 stars), Compound Engineering Code Review (EveryInc/compound-engineering-plugin, 25k stars), Code Review (modimihir07/agentic-os, 195 stars) and Code Review (nth5693/gemini-kit, 372 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Piv Review Changes?

coleam00 (a GitHub user) maintains it in coleam00/skills, which has 676 GitHub stars. The repository holds 34 skills in this directory. The repository was last updated on October 7, 2026.

Source: coleam00/skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.