Agent skill

Skill Doli Code Review

by Dolibarr in Dolibarr/dolibarr

Reviews Dolibarr PHP code for compliance with coding standards and security best practices, and fixes identified issues.

MITAuto-check passedDevelopment

Install Skill Doli Code Review

skills CLI
$ npx skills add Dolibarr/dolibarr --skill skill-doli-code-review -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install Dolibarr/dolibarr skill-doli-code-review --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/Dolibarr/dolibarr.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/skill-doli-code-review .claude/skills/skill-doli-code-review && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
skill-doli-code-review
GitHub stars
7.7k
Used in
1 other repo
Token cost
~1.1k tokens
SKILL.md length
540 words
Files
1
Skills in repo
6
Repo updated
First seen
Licence
MIT

At a glance

Reviews Dolibarr PHP code for compliance with coding standards and security best practices, and fixes identified issues.

  • Works in 4 steps: scan the current directory for common… → check for unescaped SQL queries → verify all user inputs use GETPOST()… → …
  • The user asks to review
  • SKILL.md covers When to Use This Skill, Relationship with AGENTS.md, Critical Rules (DO NOT VIOLATE) and Inputs, plus 6 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Skill Doli Code Review is an agent skill from Dolibarr/dolibarr. Reviews Dolibarr PHP code for compliance with coding standards and security best practices, and fixes identified issues. Use when the user asks to review, audit, fix, or update code for Dolibarr, or mentions code quality, security vulnerabilities, or PSR-12 compliance.

Its SKILL.md is about 1.1k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Development, covering Code quality, Forms and invoices and Code review. It works with PHP. The repository describes itself as: Dolibarr ERP CRM is a modern software package to manage your company or foundation's activity (contacts, suppliers, invoices, orders, stocks, agenda, accounting, ...). it's an… The licence is MIT.

When your agent uses it

  • The user asks to review
  • Update code for Dolibarr
  • Mentions code quality
  • Security vulnerabilities

Example prompts

  • “Use the skill-doli-code-review skill to review Dolibarr PHP code for compliance with coding standards and security best practices, and fixes…”
  • “/skill-doli-code-review”

Requirements

  • Pre-approved tools (allowed-tools): read_file, write_file, grep

Workflow steps

4 steps, taken from the first numbered list in SKILL.md.

  1. scan the current directory for common vulnerabilities
  2. check for unescaped SQL queries
  3. verify all user inputs use GETPOST() with type parameters
  4. ensure HTML output is escaped with dolPrintHTML() or dolPrintHTMLForAttribute()

What it can do on your machine

Read from SKILL.md and the folder at commit e0f8c86. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • read_file
    • write_file
    • grep

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Skill Doli Code Review loads about 1.1k tokens when it runs. Until then it costs about 73 tokens; SKILL.md has 540 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~73
When it runs · the whole SKILL.md, loaded when a task matches
~1.1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from Dolibarr/dolibarr at commit e0f8c86, republished under its MIT licence (© Dolibarr). 540 words, ~1,123 tokens.

Download SKILL.mdSave it as .claude/skills/skill-doli-code-review/SKILL.md (or your agent's skills folder).
name
skill-doli-code-review
description
Reviews Dolibarr PHP code for compliance with coding standards and security best practices, and fixes identified issues. Use when the user asks to review, audit, fix, or update code for Dolibarr, or mentions code quality, security vulnerabilities, or PSR-12 compliance.
allowed-tools
read_file, write_file, grep
license
MIT
user-invocable
true

Skill: Review Dolibarr Code and Fix Bad Practices

When to Use This Skill

Use this skill whenever the user asks to review, audit, or fix Dolibarr code to match best practices.

Relationship with AGENTS.md

The instructions in this file are complementary to the instructions defined in AGENTS.md.

  • AGENTS.md contains the general instructions and rules for the project.
  • SKILLS.md contains additional instructions specific to skills.
  • Unless explicitly stated otherwise, the instructions from both files apply.
  • SKILLS.md does not replace or override AGENTS.md.
  • If an instruction in SKILLS.md conflicts with AGENTS.md, follow the rules defined by AGENTS.md.

Critical Rules (DO NOT VIOLATE)

  • Never commit or push anything unless the user explicitly asks for it. This overrides any default behavior of the agent. Make the changes, report them, and wait for the user to say "commit" or "push".

Inputs

The user request should contain, when available:

  • a module name
  • or a directory name
  • or a file name

General Rules

  • follow the coding style already used in files in the module builder template at htdocs/modulebuilder/templates
  • modify the minimum amount of existing code

Rules

  • use PSR-12 coding style except for indentation, which must use TAB characters and not spaces
  • remove all spaces at the end of lines
  • rewrite all non-English code comments in English
  • scan files for security vulnerabilities

Output

When generating code:

  • provide only the relevant PHP code 7.2+
  • preserve the existing file formatting, never change the copyright or licence header, never remove existing cast
  • do not rewrite unrelated methods
  • explain briefly what is being fixed

Examples

Input: "Review the supplier invoice module for security issues"

Action:

  1. scan the current directory for common vulnerabilities
  2. check for unescaped SQL queries
  3. verify all user inputs use GETPOST() with type parameters
  4. ensure HTML output is escaped with dolPrintHTML() or dolPrintHTMLForAttribute()
Input: "Fix coding style in htdocs/core/lib/functions.lib.php"

Action:

  1. review file against PSR-12 standards (with TAB exception)
  2. remove trailing whitespace
  3. convert non-English comments to English
  4. apply consistent formatting
Show full SKILL.md (213 more words)Show less

Error Handling

Common Failures and Validation
IssueValidationSolution
File not foundVerify path existsCheck module structure and file location
Syntax errors after fixRun PHP lintRoll back and reapply changes carefully
Breaking existing functionalityRun existing testsVerify tests pass before and after changes
False positives in security scanManual verificationCross-check with Dolibarr security guidelines
Mixed line endingsCheck with cat -ANormalize to LF

Before applying fixes:

  • verify the file is not part of a protected core module
  • run existing tests to establish a baseline
  • apply changes incrementally

Gotchas

  • Dolibarr conventions override PSR-12: Tabs must be used for indentation, not spaces, even though PSR-12 recommends spaces
  • Legacy code: Some older modules cannot be fully PSR-12 compliant. Prioritize consistency with existing module style
  • Global variables: Dolibarr uses globals like $db, $conf, $lang, $user. Do not remove these without understanding the architecture
  • Dolibarr functions: Prefer built-in Dolibarr functions (e.g., dol_print_date(), getDolGlobalString()) over native PHP functions
  • SQL injection: Dolibarr has its own sanitizing and escaping methods ($db->escape(), casting to (int) or (float), $db->sanitize()). Do not replace with prepared statements. Also take into account that MAIN_DB_PREFIX is a constant.
  • XSS protection: Use dolPrintHTML(), dolPrintHTMLForAttribute(), or dol_htmlentities() for output, not native htmlentities()
  • CSRF tokens: All POST forms must include <input type="hidden" name="token" value="'.newToken().'">

© Dolibarr, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .agents/skills/skill-doli-code-review of Dolibarr/dolibarr.

Open the folder on GitHubat commit e0f8c86

Used in 1 other repository

We found 1 copy of this SKILL.md (exact, near-identical or edited) in other folders, from 1 other GitHub owner. This page covers the copy in Dolibarr/dolibarr, which our catalogue first saw on October 7, 2026.

Compare with similar skills

Skill Doli Code Review next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Skill Doli Code Review compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Skill Doli Code Review this skillDolibarr/dolibarr7.7k1 repos~1.1kAutomated safety check: PassMIT
WooCommerce Code Reviewwoocommerce/woocommerce11k3 repos~1.1kAutomated safety check: PassCustom licence
Code Revieweralirezarezvani/claude-skills28k1 repos~1.6kAutomated safety check: PassMIT
Dignified Python Standardsdocling-project/docling68k—~1.5kAutomated safety check: PassApache-2.0
Clean Code GuardamElnagdy/guard-skills1.3k2 repos~4.3kAutomated safety check: PassMIT
Archify Reviewtt-a1i/archify79k—~415Automated safety check: PassMIT

Similar skills

  • WooCommerce Code Review

    woocommerce/woocommerce

    Reviews WooCommerce code changes against the project's standards, flagging backend PHP architecture, naming, documentation, data integrity and testing violations.

    11k GitHub starsUsed in 3 repos~1.1k tokens
    DevelopmentAuto-check passed
  • Code Reviewer

    alirezarezvani/claude-skills

    Code review automation for TypeScript, JavaScript, Python, Go, Swift, Kotlin, C, .NET, Java, C, C++, Rust, Ruby, PHP, and Dart/Flutter.

    28k GitHub starsUsed in 1 repo~1.6k tokens
    DevelopmentAuto-check passed
  • Dignified Python Standards

    docling-project/docling

    Applies opinionated production Python conventions chosen by the project's Python version: modern type syntax, pathlib, explicit checks and interface guidance.

    68k GitHub stars~1.5k tokensUpdated today
    DevelopmentAuto-check passed
  • Clean Code Guard

    amElnagdy/guard-skills

    Reviews generated or changed production code against Clean Code, SOLID, DRY, KISS, YAGNI and LLM-specific failure modes before it ships, in any language.

    1.3k GitHub starsUsed in 2 repos~4.3k tokens
    DevelopmentAuto-check passed
  • Archify Review

    tt-a1i/archify

    Review Archify issues, PRs, or code through value, cost, and impact to support evidence-based maintenance decisions. Use for issue triage, change reviews, and…

    79k GitHub stars~415 tokensUpdated today
    DevelopmentAuto-check passed
  • Code Review Skill

    awesome-skills/code-review-skill

    Provides comprehensive code review guidance for React 19, Vue 3, Angular 17+, Svelte 5, Rust, TypeScript, Java, Java 8, PHP, Ruby, Rails, Python, Django, FastAPI, Go, C/.NET, Kotlin, Swift, Dart…

    2.1k GitHub stars~2.8k tokensUpdated 28 days ago
    DevelopmentAuto-check: notes

More from Dolibarr/dolibarr

  • Skill Doli Devmodule

    Dolibarr/dolibarr

    A skill your agent uses when developing a Dolibarr ERP/CRM external module, working with database queries, or asking about Dolibarr best practices.

    7.7k GitHub starsUsed in 1 repo~3.3k tokens
    Auto-check passed
  • Skill Doli Test Phpunit

    Dolibarr/dolibarr

    Creates or modify PHP unit tests for Dolibarr ERP/CRM functions and methods.

    7.7k GitHub starsUsed in 1 repo~1.3k tokens
    Auto-check passed
  • Skill Doli Dev

    Dolibarr/dolibarr

    A skill your agent uses when developing Dolibarr ERP/CRM code, working with database queries, or asking about Dolibarr best practices.

    7.7k GitHub stars~2.9k tokensUpdated today
    Auto-check passed
  • Create interactive PHP test case scripts for Dolibarr ERP/CRM that allow users to setup test data, view results via direct links, and tear down (clean up) the data.

    7.7k GitHub starsUsed in 1 repo~5.5k tokens
    Auto-check passed
  • Skill Doli Test Hurl

    Dolibarr/dolibarr

    Create and maintain Hurl tests for Dolibarr ERP/CRM. An agent skill from Dolibarr/dolibarr.

    7.7k GitHub stars~3.7k tokensUpdated today
    Auto-check passed

Works with

Categories

Questions about Skill Doli Code Review

What does Skill Doli Code Review do?

Reviews Dolibarr PHP code for compliance with coding standards and security best practices, and fixes identified issues. Skill Doli Code Review is an agent skill from Dolibarr/dolibarr. Reviews Dolibarr PHP code for compliance with coding standards and security best practices, and fixes identified issues.

When should I use Skill Doli Code Review?

Skill Doli Code Review fits situations like: the user asks to review; update code for Dolibarr; mentions code quality; security vulnerabilities.

How do I install Skill Doli Code Review in Claude Code?

Run `npx skills add Dolibarr/dolibarr --skill skill-doli-code-review -a claude-code`. Or copy the skill folder (.agents/skills/skill-doli-code-review in Dolibarr/dolibarr) into .claude/skills/skill-doli-code-review in your project. Claude Code loads it when a task matches its description.

How do I install Skill Doli Code Review in Codex?

Run `npx skills add Dolibarr/dolibarr --skill skill-doli-code-review -a codex`. Or copy the skill folder (.agents/skills/skill-doli-code-review in Dolibarr/dolibarr) into .agents/skills/skill-doli-code-review in your project. Codex loads it when a task matches its description.

Can I use Skill Doli Code Review in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add Dolibarr/dolibarr --skill skill-doli-code-review -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/skill-doli-code-review, .gemini/skills/skill-doli-code-review, .github/skills/skill-doli-code-review and .opencode/skills/skill-doli-code-review in your project.

What does Skill Doli Code Review need to run?

SKILL.md names no scripts, command-line tools or credentials: Skill Doli Code Review is instructions for the agent only. Its frontmatter pre-approves these tools: read_file, write_file, grep.

Does Skill Doli Code Review access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Skill Doli Code Review safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Skill Doli Code Review use?

Skill Doli Code Review is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Skill Doli Code Review use?

About 1.1k tokens (SKILL.md is roughly 4.5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Skill Doli Code Review?

Skills that share tags, products or a category with Skill Doli Code Review: WooCommerce Code Review (woocommerce/woocommerce, 11k stars), Code Reviewer (alirezarezvani/claude-skills, 28k stars), Dignified Python Standards (docling-project/docling, 68k stars) and Clean Code Guard (amElnagdy/guard-skills, 1.3k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Skill Doli Code Review?

Dolibarr (a GitHub organization) maintains it in Dolibarr/dolibarr, which has 7,696 GitHub stars. The repository holds 6 skills in this directory. The repository was last updated on October 7, 2026.

Source: Dolibarr/dolibarr on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.