PR Babysitter
openinterpreter/openinterpreter
Watches an open GitHub pull request until it merges, handling review comments, diagnosing CI failures and retrying flaky checks along the way.
Comprehensive checklist for conducting thorough code reviews covering functionality, security, performance, and maintainability
$ npx skills add jewbetcha/opentrace --skill code-review-checklist -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install jewbetcha/opentrace code-review-checklist --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/jewbetcha/opentrace.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/code-review-checklist .claude/skills/code-review-checklist && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "code-review-checklist" agent skill from https://github.com/jewbetcha/opentrace/tree/main/.agents/skills/code-review-checklist into .claude/skills/code-review-checklist/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "code-review-checklist", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/jewbetcha/opentrace/tree/main/.agents/skills/code-review-checklistType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add jewbetcha/opentrace --skill code-review-checklist -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install jewbetcha/opentrace code-review-checklist --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/jewbetcha/opentrace.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.agents/skills/code-review-checklist .agents/skills/code-review-checklist && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "code-review-checklist" agent skill from https://github.com/jewbetcha/opentrace/tree/main/.agents/skills/code-review-checklist into .agents/skills/code-review-checklist/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "code-review-checklist", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add jewbetcha/opentrace --skill code-review-checklist -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install jewbetcha/opentrace code-review-checklist --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/jewbetcha/opentrace.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.agents/skills/code-review-checklist .cursor/skills/code-review-checklist && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "code-review-checklist" agent skill from https://github.com/jewbetcha/opentrace/tree/main/.agents/skills/code-review-checklist into .cursor/skills/code-review-checklist/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "code-review-checklist", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/jewbetcha/opentrace.git --path .agents/skills/code-review-checklist--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add jewbetcha/opentrace --skill code-review-checklist -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install jewbetcha/opentrace code-review-checklist --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/jewbetcha/opentrace.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.agents/skills/code-review-checklist .gemini/skills/code-review-checklist && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "code-review-checklist" agent skill from https://github.com/jewbetcha/opentrace/tree/main/.agents/skills/code-review-checklist into .gemini/skills/code-review-checklist/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "code-review-checklist", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install jewbetcha/opentrace code-review-checklistInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add jewbetcha/opentrace --skill code-review-checklist -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/jewbetcha/opentrace.git skills-src && mkdir -p .github/skills && cp -r skills-src/.agents/skills/code-review-checklist .github/skills/code-review-checklist && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "code-review-checklist" agent skill from https://github.com/jewbetcha/opentrace/tree/main/.agents/skills/code-review-checklist into .github/skills/code-review-checklist/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "code-review-checklist", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add jewbetcha/opentrace --skill code-review-checklist -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install jewbetcha/opentrace code-review-checklist --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/jewbetcha/opentrace.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.agents/skills/code-review-checklist .opencode/skills/code-review-checklist && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "code-review-checklist" agent skill from https://github.com/jewbetcha/opentrace/tree/main/.agents/skills/code-review-checklist into .opencode/skills/code-review-checklist/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "code-review-checklist", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
code-review-checklistComprehensive checklist for conducting thorough code reviews covering functionality, security, performance, and maintainability
Code Review Checklist is an agent skill from jewbetcha/opentrace. Comprehensive checklist for conducting thorough code reviews covering functionality, security, performance, and maintainability
Its SKILL.md is about 2.9k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Development, covering Code review. The licence is MIT.
6 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 3211e35. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md (its code samples are markdown).
From the folder's file list and the shell code blocks in SKILL.md.
Links to these hosts (documentation or services it may open):
google.github.ioowasp.orggithub.comkevinlondon.comFrom URLs in SKILL.md, links to its own repository left out.
Names these keys or tokens, usually read from environment variables:
API_KEYFrom names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Code Review Checklist loads about 2.9k tokens when it runs. Until then it costs about 37 tokens; SKILL.md has 813 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from jewbetcha/opentrace at commit 3211e35, republished under its MIT licence (© jewbetcha). 813 words, ~2,900 tokens.
.claude/skills/code-review-checklist/SKILL.md (or your agent's skills folder).Provide a systematic checklist for conducting thorough code reviews. This skill helps reviewers ensure code quality, catch bugs, identify security issues, and maintain consistency across the codebase.
Before reviewing code, I'll help you understand:
Check if the code works correctly:
Assess code maintainability:
Check for security issues:
Look for performance issues:
Verify test coverage:
## Functionality Review
### Requirements
- [ ] Code solves the stated problem
- [ ] All acceptance criteria are met
- [ ] Edge cases are handled
- [ ] Error cases are handled
- [ ] User input is validated
### Logic
- [ ] No logical errors or bugs
- [ ] Conditions are correct (no off-by-one errors)
- [ ] Loops terminate correctly
- [ ] Recursion has proper base cases
- [ ] State management is correct
### Error Handling
- [ ] Errors are caught appropriately
- [ ] Error messages are clear and helpful
- [ ] Errors don't expose sensitive information
- [ ] Failed operations are rolled back
- [ ] Logging is appropriate
### Example Issues to Catch:
**❌ Bad - Missing validation:**
\`\`\`javascript
function createUser(email, password) {
// No validation!
return db.users.create({ email, password });
}
\`\`\`
**✅ Good - Proper validation:**
\`\`\`javascript
function createUser(email, password) {
if (!email || !isValidEmail(email)) {
throw new Error('Invalid email address');
}
if (!password || password.length < 8) {
throw new Error('Password must be at least 8 characters');
}
return db.users.create({ email, password });
}
\`\`\`## Security Review
### Input Validation
- [ ] All user inputs are validated
- [ ] SQL injection is prevented (use parameterized queries)
- [ ] XSS is prevented (escape output)
- [ ] CSRF protection is in place
- [ ] File uploads are validated (type, size, content)
### Authentication & Authorization
- [ ] Authentication is required where needed
- [ ] Authorization checks are present
- [ ] Passwords are hashed (never stored plain text)
- [ ] Sessions are managed securely
- [ ] Tokens expire appropriately
### Data Protection
- [ ] Sensitive data is encrypted
- [ ] API keys are not hardcoded
- [ ] Environment variables are used for secrets
- [ ] Personal data follows privacy regulations
- [ ] Database credentials are secure
### Dependencies
- [ ] No known vulnerable dependencies
- [ ] Dependencies are up to date
- [ ] Unnecessary dependencies are removed
- [ ] Dependency versions are pinned
### Example Issues to Catch:
**❌ Bad - SQL injection risk:**
\`\`\`javascript
const query = \`SELECT * FROM users WHERE email = '\${email}'\`;
db.query(query);
\`\`\`
**✅ Good - Parameterized query:**
\`\`\`javascript
const query = 'SELECT * FROM users WHERE email = $1';
db.query(query, [email]);
\`\`\`
**❌ Bad - Hardcoded secret:**
\`\`\`javascript
const API_KEY = 'sk_live_abc123xyz';
\`\`\`
**✅ Good - Environment variable:**
\`\`\`javascript
const API_KEY = process.env.API_KEY;
if (!API_KEY) {
throw new Error('API_KEY environment variable is required');
}
\`\`\`## Code Quality Review
### Readability
- [ ] Code is easy to understand
- [ ] Variable names are descriptive
- [ ] Function names explain what they do
- [ ] Complex logic has comments
- [ ] Magic numbers are replaced with constants
### Structure
- [ ] Functions are small and focused
- [ ] Code follows DRY principle (Don't Repeat Yourself)
- [ ] Proper separation of concerns
- [ ] Consistent code style
- [ ] No dead code or commented-out code
### Maintainability
- [ ] Code is modular and reusable
- [ ] Dependencies are minimal
- [ ] Changes are backwards compatible
- [ ] Breaking changes are documented
- [ ] Technical debt is noted
### Example Issues to Catch:
**❌ Bad - Unclear naming:**
\`\`\`javascript
function calc(a, b, c) {
return a * b + c;
}
\`\`\`
**✅ Good - Descriptive naming:**
\`\`\`javascript
function calculateTotalPrice(quantity, unitPrice, tax) {
return quantity * unitPrice + tax;
}
\`\`\`
**❌ Bad - Function doing too much:**
\`\`\`javascript
function processOrder(order) {
// Validate order
if (!order.items) throw new Error('No items');
// Calculate total
let total = 0;
for (let item of order.items) {
total += item.price * item.quantity;
}
// Apply discount
if (order.coupon) {
total *= 0.9;
}
// Process payment
const payment = stripe.charge(total);
// Send email
sendEmail(order.email, 'Order confirmed');
// Update inventory
updateInventory(order.items);
return { orderId: order.id, total };
}
\`\`\`
**✅ Good - Separated concerns:**
\`\`\`javascript
function processOrder(order) {
validateOrder(order);
const total = calculateOrderTotal(order);
const payment = processPayment(total);
sendOrderConfirmation(order.email);
updateInventory(order.items);
return { orderId: order.id, total };
}
\`\`\`Symptoms: Code works for happy path but fails on edge cases Solution: Ask "What if...?" questions
Symptoms: Code exposes security risks Solution: Use security checklist
Symptoms: New code has no tests or inadequate tests Solution: Require tests for all new code
Symptoms: Reviewer can't understand what code does Solution: Request improvements
**Issue:** [Describe the problem]
**Current code:**
\`\`\`javascript
// Show problematic code
\`\`\`
**Suggested fix:**
\`\`\`javascript
// Show improved code
\`\`\`
**Why:** [Explain why this is better]**Question:** [Your question]
**Context:** [Why you're asking]
**Suggestion:** [If you have one]**Nice!** [What you liked]
This is great because [explain why]@requesting-code-review - Prepare code for review@receiving-code-review - Handle review feedback@systematic-debugging - Debug issues found in review@test-driven-development - Ensure code has testsPro Tip: Use a checklist template for every review to ensure consistency and thoroughness. Customize it for your team's specific needs!
© jewbetcha, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in .agents/skills/code-review-checklist of jewbetcha/opentrace.
Open the folder on GitHubat commit 3211e35
We found 22 copies of this SKILL.md (exact, near-identical or edited) in other folders, from 7 other GitHub owners. This page covers the copy in jewbetcha/opentrace, which our catalogue first saw on October 7, 2026.
Code Review Checklist next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Code Review Checklist this skilljewbetcha/opentrace | 116 | 7 repos | ~2.9k | Automated safety check: Pass | MIT | |
| PR Babysitteropeninterpreter/openinterpreter | 69k | 3 repos | ~4.2k | Automated safety check: Pass | Apache-2.0 | |
| Code Review ChecklistshareAI-lab/learn-claude-code | 78k | 5 repos | ~1.1k | Automated safety check: Pass | MIT | |
| Backend Code Reviewlangflow-ai/langflow | 156k | — | ~3.5k | Automated safety check: Notes | MIT | |
| Understand Diff AnalysisEgonex-AI/Understand-Anything | 86k | 1 repos | ~1.4k | Automated safety check: Pass | MIT | |
| Mole Bug Patternstw93/Mole | 70k | — | ~2k | Automated safety check: Pass | GPL-3.0 |
openinterpreter/openinterpreter
Watches an open GitHub pull request until it merges, handling review comments, diagnosing CI failures and retrying flaky checks along the way.
shareAI-lab/learn-claude-code
Reviews code against a five-part checklist covering security, correctness, performance, maintainability and testing, and reports findings in a fixed format.
langflow-ai/langflow
Review backend code for quality, security, maintainability, and best practices based on established checklist rules.
Egonex-AI/Understand-Anything
Reads your git changes or a pull request against a prebuilt knowledge graph of the project to explain what changed, which components are affected and what is risky.
tw93/Mole
A catalog of recurring bug shapes in the Mole Mac cleaner, used to review safety-sensitive diffs for deletion safety, unbounded commands, shell traps and weak tests.
langgenius/dify
Reviews backend code under api/ for concrete, reproducible defects, routes to rule packs for architecture, schema, repositories and SQLAlchemy, and ranks findings from P0 to P3.
jewbetcha/opentrace
A skill your agent uses when adding authentication, handling user input, working with secrets, creating API endpoints, or implementing payment/sensitive features.
jewbetcha/opentrace
Comprehensive code review skill for TypeScript, JavaScript, Python, Swift, Kotlin, Go.
jewbetcha/opentrace
Professional code review with auto CHANGELOG generation, integrated with Codex AI
Categories
Comprehensive checklist for conducting thorough code reviews covering functionality, security, performance, and maintainability. Code Review Checklist is an agent skill from jewbetcha/opentrace.
Code Review Checklist fits situations like: tasks that involve Code review.
Run `npx skills add jewbetcha/opentrace --skill code-review-checklist -a claude-code`. Or copy the skill folder (.agents/skills/code-review-checklist in jewbetcha/opentrace) into .claude/skills/code-review-checklist in your project. Claude Code loads it when a task matches its description.
Run `npx skills add jewbetcha/opentrace --skill code-review-checklist -a codex`. Or copy the skill folder (.agents/skills/code-review-checklist in jewbetcha/opentrace) into .agents/skills/code-review-checklist in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add jewbetcha/opentrace --skill code-review-checklist -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/code-review-checklist, .gemini/skills/code-review-checklist, .github/skills/code-review-checklist and .opencode/skills/code-review-checklist in your project.
Going by SKILL.md and its folder, Code Review Checklist needs credentials named API_KEY. Our summary lists: A credential in API_KEY.
SKILL.md names 4 domains. As links in the text: google.github.io, owasp.org, github.com and kevinlondon.com. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Code Review Checklist is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 2.9k tokens (SKILL.md is roughly 12k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Code Review Checklist: PR Babysitter (openinterpreter/openinterpreter, 69k stars), Code Review Checklist (shareAI-lab/learn-claude-code, 78k stars), Backend Code Review (langflow-ai/langflow, 156k stars) and Understand Diff Analysis (Egonex-AI/Understand-Anything, 86k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
jewbetcha (a GitHub user) maintains it in jewbetcha/opentrace, which has 116 GitHub stars. The repository holds 4 skills in this directory. The repository was last updated on May 23, 2026.
Source: jewbetcha/opentrace on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.