Agent skill

Code Review

by croffasia in croffasia/itsaplan

A skill your agent uses when reviewing code — a diff, a merge request, a file, a directory, or a feature.

AGPL-3.0Auto-check passedDevelopment

Install Code Review

skills CLI
$ npx skills add croffasia/itsaplan --skill code-review -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install croffasia/itsaplan code-review --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/croffasia/itsaplan.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/code-review .claude/skills/code-review && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
code-review
GitHub stars
895
Token cost
~2k tokens
SKILL.md length
958 words
Files
1
Skills in repo
2
Repo updated
First seen
Licence
AGPL-3.0

At a glance

A skill your agent uses when reviewing code — a diff, a merge request, a file, a directory, or a feature.

  • Works in 3 steps: Reviewer → Filter → Console report
  • Reviewing code — a diff
  • SKILL.md covers Review target, Stage 1 — Reviewer, Stage 2 — Filter and Stage 3 — Console report
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Code Review is an agent skill from croffasia/itsaplan. Use when reviewing code — a diff, a merge request, a file, a directory, or a feature. Produces structured code-review findings, filters out false positives and nitpicks, and prints a concise verdict report. Trigger when the user asks to review a diff, review an MR, or check code for bugs, security issues, or rule violations.

Its SKILL.md is about 2k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Development, covering Code review and Project management. It works with Jira. The repository describes itself as: Open-source, self-hosted alternative to Linear and Plane. Project management and issue tracking where teams and AI agents work side by side to plan and ship products. The licence is AGPL-3.0.

When your agent uses it

  • Reviewing code — a diff
  • A merge request
  • The user asks to review a diff
  • Check code for bugs

Example prompts

  • “/code-review”

Workflow steps

3 steps, taken from the step headings in SKILL.md.

  1. Reviewer
  2. Filter
  3. Console report

What it can do on your machine

Read from SKILL.md and the folder at commit fb9a858. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Code Review loads about 2k tokens when it runs. Until then it costs about 85 tokens; SKILL.md has 958 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~85
When it runs · the whole SKILL.md, loaded when a task matches
~2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from croffasia/itsaplan at commit fb9a858, republished under its AGPL-3.0 licence (© croffasia). 958 words, ~1,969 tokens.

Download SKILL.mdSave it as .claude/skills/code-review/SKILL.md (or your agent's skills folder).
name
code-review
description
Use when reviewing code — a diff, a merge request, a file, a directory, or a feature. Produces structured code-review findings, filters out false positives and nitpicks, and prints a concise verdict report. Trigger when the user asks to review a diff, review an MR, or check code for bugs, security issues, or rule violations.

Code Review

Three-stage method: produce findings, filter them, report verdict.

Stages 1 and 2 are internal reasoning. Never print them. Only the Stage 3 report reaches the user.

Review target

  • User named a target (file, directory, feature, commit range, MR) → review that.
  • No target named → review current diff (uncommitted changes, or the branch diff against the main branch).

Read the code with workspace tools. When code is supplied inline in the prompt, review what is supplied and read further files only for context.

Stage 1 — Reviewer

Review target. Collect findings.

Review algorithm (follow this order)
  1. Read project rules — MANDATORY. Read every instruction file covering the reviewed code: root AGENTS.md plus nested ones in the touched directories, and any docs they point to. Project rules override skill rules on conflict
  2. Load skills — MANDATORY. Load workspace skills matching the reviewed stack and area (framework, language, UI text, testing). Read their rule files via workspace tools, never from memory
  3. Big picture — scan the whole change set for cross-file context
  4. Analyze change — split core change vs plumbing. Core design wrong → focus there
  5. Full-file context — check the change makes sense: imports used, removed items not referenced, control flow correct
  6. API compatibility — check callers match changes
  7. Apply skill rules — check violations from this change only, not pre-existing code
  8. Apply project rules — check violations of AGENTS.md
  9. Deduplicate — skip findings already covered by existing review comments
  10. Verify relevance — each finding must fit actual code context (file type, framework, stack), not generic rule mismatch
  11. Verify against source — re-read the cited lines. Drop findings referencing code, symbols, imports, or behavior that does not exist in the file. Never describe code from memory or assumption
  12. Check the fix — proposed fix must be the smallest change that solves the problem. Drop or rewrite fixes that add abstractions, layers, options, or generalization the problem does not need
  13. Keep — only confidence >= 80, reviewed code only, no linter catches or nitpicks. Fix line says WHAT to fix in 1 sentence, not HOW
Focus on
  • Data loss, security holes (XSS, injection, secrets in code)
  • Runtime crashes, unhandled errors, null/undefined access
  • Broken core logic, wrong conditions, off-by-one errors
  • Race conditions, missing await, wrong async handling
  • API contract violations, wrong types passed between components
  • Functions whose behavior contradicts their name or return type
  • Stub or placeholder implementations merged without TODO/FIXME markers
  • Public functions where invalid but plausible input gives silently wrong results instead of error
  • Unreachable code paths or dead branches caused by change
  • New exports or public API surface not consumed anywhere
  • Obvious performance pitfalls: O(n²) or worse in loops over collections, sync blocking in async paths, missing pagination on unbounded queries, repeated expensive operations that should be cached or batched
  • Hardcoded values that clearly should be configurable or computed (e.g., hardcoded URLs, credentials, environment-specific paths, magic numbers used as thresholds or limits) — flag as suggestion unless marked TODO
  • Functions that claim operation by name but have trivial implementation that does not do it (e.g., isFileExists returning constant without checking filesystem, sendEmail with empty body) — flag unless marked TODO
  • Misused dependencies — components, functions, composables or utilities called with wrong arguments, wrong types, ignored return values, missing required props/options, or invoked in way that violates their contract (when signature visible in provided context)
  • Reinvented shared utilities — new logic that duplicates existing shared helper/component/composable from project (e.g., hand-rolled deep clone, date formatter, query builder, or validator) when equivalent visible in provided context; flag and point to existing one to reuse
Show full SKILL.md (374 more words)Show less
Do NOT check

Code style, naming, missing comments, test coverage, performance micro-optimizations.

Finding fields

Track per finding, in your head, not printed at this stage:

  • file and line
  • title: short, one line
  • problem: what is wrong
  • fix: what to fix, one sentence
  • severity: critical (confidence 90-100) = data loss, security, crash, broken logic. suggestion (confidence 80-89) = everything else
  • source: which rule triggered the finding. One of skill:<skill-name>/<rule-name>, repository-rules (AGENTS.md), general (Focus on section)

Source priority when a finding matches several categories: repository-rules > skill > general. Use the highest-priority source that applies.

Stage 2 — Filter

Act as senior code review editor. Filter findings list. Keep ONLY ones that are:

  1. Real issues — not false positives, not nitpicks, not style preferences
  2. Actionable — developer clearly understands what to fix
  3. High confidence — you agree with finding after review
  4. Critical severity — NEVER drop findings with severity "critical". May adjust description but must keep in output. Believe critical finding is false positive → downgrade severity to "suggestion" instead of removing.

Remove findings that are:

  • Hallucinated — cited line, symbol, or behavior not present in the actual code
  • Overengineered fixes — solution heavier than the problem (new abstraction, config, or layer where a local change is enough)
  • Duplicates or overlapping with other findings
  • Too vague or speculative
  • About pre-existing code patterns (not from this change)
  • Nitpicks disguised as suggestions
  • False positives from incomplete context

For each kept finding, may adjust confidence, severity, or description.

Then pick a verdict: approve, request_changes, or comment.

Verdict rules:

  • approve: no findings kept
  • request_changes: at least one critical finding
  • comment: only suggestions

Stage 3 — Console report

Do NOT edit, write, or fix any code. This skill only reviews and reports.

Print the kept findings as plain text for a human reading a terminal. No preamble, no closing summary, no extra commentary, only the report below.

Format:

Verdict: <verdict> (<N> critical, <M> suggestions)
Reviewed: <what was reviewed>, <K> files

CRITICAL
  <file>:<line>  <title>  [<source>]
    <problem>
    Fix: <fix>

SUGGESTIONS
  <file>:<line>  <title>  [<source>]
    <problem>
    Fix: <fix>

Example:

Verdict: request_changes (1 critical, 1 suggestion)
Reviewed: uncommitted changes, 3 files

CRITICAL
  apps/api/src/planner/issues.ts:118  Transaction never committed
    The early return on a validation error leaves the transaction open, so the connection leaks.
    Fix: commit or roll back before returning.
    [general]

SUGGESTIONS
  apps/web/src/features/board/Column.tsx:64  Board key hardcoded
    "IAP" is written inline instead of coming from props.
    Fix: take the key from the project prop.
    [repository-rules]

Rules:

  • Critical findings first, then suggestions. Omit an empty section.
  • No findings at all: print only Verdict: approve (no issues found) plus the Reviewed: line.
  • One line per field. Problem and fix stay one sentence each. No paragraphs, no tables, no JSON.
  • Source tag in brackets so the reader knows whether it came from project rules, a skill, or built-in checks.
  • Sort findings inside a section by file, then by line.

© croffasia, AGPL-3.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .agents/skills/code-review of croffasia/itsaplan.

Open the folder on GitHubat commit fb9a858

Compare with similar skills

Code Review next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Code Review compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Code Review this skillcroffasia/itsaplan895—~2kAutomated safety check: PassAGPL-3.0
Code Reviewsortie-ai/sortie196—~2.9kAutomated safety check: PassMIT
Create PRwanteddev/montage-web117—~6.3kAutomated safety check: NotesMIT
Implementopenshift-eng/ai-helpers120—~746Automated safety check: PassApache-2.0
Spec Driven DevLeoYeAI/openclaw-master-skills2.2k—~4.8kAutomated safety check: PassMIT
Jira Natural Language Interfacejjmartres/opencode1333 repos~1.7kAutomated safety check: PassMIT

Similar skills

  • Code Review

    sortie-ai/sortie

    Reviews pull requests in this repository for the defect classes a mechanical checklist misses: documentation that outlived the code it describes, reaction and retry state that leaks or clobbers a…

    196 GitHub stars~2.9k tokensUpdated yesterday
    DevelopmentAuto-check passed
  • Create PR

    wanteddev/montage-web

    Create a GitHub pull request from the current branch. An agent skill from wanteddev/montage-web.

    117 GitHub stars~6.3k tokensUpdated today
    DevelopmentAuto-check: notes
  • Implement

    openshift-eng/ai-helpers

    Implement a scoped Jira requirement or apply local pre-commit review findings.

    120 GitHub stars~746 tokensUpdated yesterday
    DevelopmentAuto-check passed
  • Spec Driven Dev

    LeoYeAI/openclaw-master-skills

    在克隆的 Git 仓库中驱动完整的规格驱动开发生命周期(init→requirements→architecture→processdesign→projectplan→coding→test→bugfix→codereview→release)。阶段门控、产物强制输出、多语言支持,内置 commit message 检查、代码门控与 LOGAF Checklist 评审,支持任意阶段…

    2.2k GitHub stars~4.8k tokensUpdated 2 mo ago
    DevelopmentAuto-check passed
  • Lets an agent view, create, update and transition Jira issues in natural language, automatically choosing between the jira CLI and Atlassian MCP tools.

    133 GitHub starsUsed in 3 repos~1.7k tokens
    Product & Project ManagementAuto-check passed
  • Integration Orchestrator

    rampstackco/claude-skills

    Generate a phased delivery orchestration plan for creative-direction-driven work: which skills run when, what locks at which gate, how handoffs occur, and how the cadence implements in the team's…

    935 GitHub stars~5.3k tokensUpdated today
    Agent WorkflowsAuto-check passed

More from croffasia/itsaplan

  • Tidy

    croffasia/itsaplan

    Simplifies and refines code for clarity, consistency, and maintainability while preserving all functionality.

    895 GitHub stars~2.8k tokensUpdated yesterday
    Auto-check passed

Works with

Questions about Code Review

What does Code Review do?

A skill your agent uses when reviewing code — a diff, a merge request, a file, a directory, or a feature. Code Review is an agent skill from croffasia/itsaplan. Use when reviewing code — a diff, a merge request, a file, a directory, or a feature.

When should I use Code Review?

Code Review fits situations like: reviewing code — a diff; A merge request; the user asks to review a diff; check code for bugs.

How do I install Code Review in Claude Code?

Run `npx skills add croffasia/itsaplan --skill code-review -a claude-code`. Or copy the skill folder (.agents/skills/code-review in croffasia/itsaplan) into .claude/skills/code-review in your project. Claude Code loads it when a task matches its description.

How do I install Code Review in Codex?

Run `npx skills add croffasia/itsaplan --skill code-review -a codex`. Or copy the skill folder (.agents/skills/code-review in croffasia/itsaplan) into .agents/skills/code-review in your project. Codex loads it when a task matches its description.

Can I use Code Review in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add croffasia/itsaplan --skill code-review -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/code-review, .gemini/skills/code-review, .github/skills/code-review and .opencode/skills/code-review in your project.

What does Code Review need to run?

SKILL.md names no scripts, command-line tools or credentials: Code Review is instructions for the agent only.

Does Code Review access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Code Review safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Code Review use?

Code Review is published under the AGPL-3.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Code Review use?

About 2k tokens (SKILL.md is roughly 7.9k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Code Review?

Skills that share tags, products or a category with Code Review: Code Review (sortie-ai/sortie, 196 stars), Create PR (wanteddev/montage-web, 117 stars), Implement (openshift-eng/ai-helpers, 120 stars) and Spec Driven Dev (LeoYeAI/openclaw-master-skills, 2.2k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Code Review?

croffasia (a GitHub user) maintains it in croffasia/itsaplan, which has 895 GitHub stars. The repository holds 2 skills in this directory. The repository was last updated on October 6, 2026.

Source: croffasia/itsaplan on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.