Agent skill

Compound Engineering Code Review

by EveryInc in EveryInc/compound-engineering-plugin

Runs a staged pull request or diff review using selected reviewer personas, checking the change against its stated intent and project standards before producing findings.

MITAuto-check passedDevelopment

Install Compound Engineering Code Review

skills CLI
$ npx skills add EveryInc/compound-engineering-plugin --skill ce-code-review -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install EveryInc/compound-engineering-plugin ce-code-review --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/EveryInc/compound-engineering-plugin.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/ce-code-review .claude/skills/ce-code-review && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
ce-code-review
GitHub stars
25k
Token cost
~2k tokens
SKILL.md length
1,119 words
Files
41 (incl. scripts, references)
Skills in repo
37
Repo updated
First seen
Licence
MIT

At a glance

Runs a staged pull request or diff review using selected reviewer personas, checking the change against its stated intent and project standards before producing findings.

  • Works in 7 steps: Read references/modes-and-output.md… → Stage 1. Read references/scope.md and… → Stage 2. Read… → …
  • Reviewing a named pull request or diff before it merges
  • SKILL.md covers Artifact Root, Execution spine and Operating principles
  • Calls git and gh

What it does

The review proceeds through a fixed sequence of stages, each governed by its own reference file read exactly when that stage begins. It first resolves settings and the review depth (a quick, lite-only pass stops the run early), then resolves the diff scope, writes an intent summary every reviewer persona will see, and discovers the plan that a later stage checks requirements against.

Reviewer personas are then selected based on the risks the change poses, drawing from a catalog that includes an adversarial reviewer, an API-contract reviewer, a correctness reviewer, a data-migration reviewer and others, each paired with the project's applicable standards files. Findings are written to an artifact directory whose root is read from the repository's own config file, never a local override, so review output lands in a consistent, repo-relative location.

When your agent uses it

  • Reviewing a named pull request or diff before it merges
  • Running a multi-persona adversarial review on a risky change
  • Producing a review artifact that records findings against project standards
  • Verifying a change against its stated intent rather than a preferred rewrite

Example prompts

  • “Review PR #482 for correctness and API contract issues before I merge it.”
  • “Run a full adversarial review on this data-migration diff.”
  • “Give this diff a quick lite review — just flag anything serious.”

Requirements

  • A repository with a `.compound-engineering/config.yaml` file

Workflow steps

7 steps, taken from the first numbered list in SKILL.md.

  1. Read references/modes-and-output.md first. It settles arguments, conflicts, the quick-review short-circuit, the Review depth gate, and…
  2. Stage 1. Read references/scope.md and resolve the reviewed diff, the scope mode, and the deterministic scope signals. Then apply that…
  3. Stage 2. Read references/intent-and-plan.md, write the intent summary every reviewer receives, and discover the plan Stage 6 verifies…
  4. Stage 3. Read references/persona-catalog.md and references/select-and-route.md, then select the reviewers the change's risks call for…
  5. Stage 3d. When adversarial is selected for a local reviewed tree, start and persist the sanctioned cross-model job that…
  6. Stage 4. Read references/dispatch-reviewers.md. Dispatch the selected local reviewers as one concurrent batch collected in this turn…
  7. Stages 5 and 6. Once every reviewer result is in, write the finish input references/finish-input.md defines and stay in that reference: it…

What it can do on your machine

Read from SKILL.md and the folder at commit cef001f. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/, which the agent can run.

    Shell commands in SKILL.md call:

    • git
    • gh

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use git and gh, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Compound Engineering Code Review loads about 2k tokens when it runs, and up to ~96k if it reads all its reference files. Until then it costs about 71 tokens; SKILL.md has 1,119 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~71
When it runs · the whole SKILL.md, loaded when a task matches
~2k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~96k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from EveryInc/compound-engineering-plugin at commit cef001f, republished under its MIT licence (© EveryInc). 1,119 words, ~1,954 tokens.

Download SKILL.mdSave it as .claude/skills/ce-code-review/SKILL.md (or your agent's skills folder). This skill also uses 40 other files; get the full folder from GitHub.
name
ce-code-review
description
Review a named diff or PR for bugs, regressions, tests, and standards. Use when asked to review code or when a shipping skill needs a review receipt. Use when asked to apply this review's findings locally. Use ce-resolve-pr-feedback for feedback already left on a PR.
argument-hint
[mode:agent] [apply:local] [blank to review current branch, or provide PR link]

Code Review

Help the caller deliver a correct change within the agreed scope. Find defects and improvements whose consequences justify action; judge the code against its intended behavior and project requirements, not a preferred rewrite. Serious defects remain important even when the diff is small. An adequate change needs no findings.

Done when: required review and validation are complete, retained findings are supported by the source, and the caller has a clear result with any remaining coverage limits. Apply only when the invocation authorizes it, under the rules below.

Artifact Root

<!-- ce-docs-root:start -->

Resolve the CE artifact root <root> before composing any artifact path.

  • Read docs_root from <repo-root>/.compound-engineering/config.yaml only (<repo-root> = git rev-parse --show-toplevel). Do not read it from config.local.yaml. Unset -> <root> is docs, exactly as before.
  • Validate a set value: a repo-relative directory whose real, symlink-resolved path stays inside the repo and is neither the repo root nor under .git/. Otherwise stop with an error naming docs_root and the value -- never fall back to docs.
  • Use <root> as the sole artifact location: create it if absent, compose each path as <root>/<subdir> with this skill's own subdirectory, and never also read docs.
<!-- ce-docs-root:end -->

Execution spine

Follow these steps in order; the references supply the detail but never change the order. Read each reference when you enter the step whose own work it governs; a read made before that step does not satisfy it, and a reference you only hand to a leaf is not one you read.

  1. Read references/modes-and-output.md first. It settles arguments, conflicts, the quick-review short-circuit, the Review depth gate, and what this invocation returns.
  2. Stage 1. Read references/scope.md and resolve the reviewed diff, the scope mode, and the deterministic scope signals. Then apply that Review depth gate before Stage 2. Lite ends the run without the later spine references; lite and focused each run from this context by references/depth-paths.md.
  3. Stage 2. Read references/intent-and-plan.md, write the intent summary every reviewer receives, and discover the plan Stage 6 verifies requirements against.
  4. Stage 3. Read references/persona-catalog.md and references/select-and-route.md, then select the reviewers the change's risks call for, find the applicable standards files, and decide how the adversarial review will run.
  5. Stage 3d. When adversarial is selected for a local reviewed tree, start and persist the sanctioned cross-model job that references/cross-model-review.md defines, before any local persona dispatch. Invoking this skill is itself the authorization for its configured or allowlisted peer route, once you have made the required disclosure of the recipient and of the code that leaves the machine. Do not ask the user to confirm a second time, and do not skip the peer because the user did not repeat that authorization. An explicit user prohibition on external review overrides it, as does a checkout that sets cross_model_review_mode: off with no live opt-in; both are resolved before you bind a route. A started peer replaces the local adversarial persona at this stage, and only a real failure to scope, allowlist, reach, authenticate, or start it leaves the local fallback in the roster; a later stage may still restore the local reviewer under the conditions that reference states.
  6. Stage 4. Read references/dispatch-reviewers.md. Dispatch the selected local reviewers as one concurrent batch collected in this turn, sized to the host's active-agent cap. Every successful launch is collected only when its terminal outcome is in hand: a valid compact return is consumed, a tool error or malformed output is recorded as a failed reviewer, and a launch acknowledgement alone is not a result. Use the host's blocking collection capability for asynchronous receipts within the bound that reference states, after which an uncollected reviewer is a failed reviewer; a terminal outcome may arrive as the call's return, a blocking wait's return, or a host-delivered terminal message that names the launch and carries its payload; a progress update is not one. If launched work cannot be collected reliably, stop it, and for any persisted peer (the cross-model job) run the cleanup its reference describes before returning the failure result, and never end the turn on progress to await it. Detaching local review into a polled background job is forbidden. The cross-model peer is the only detached work, and it may overlap this batch.
  7. Stages 5 and 6. Once every reviewer result is in, write the finish input references/finish-input.md defines and stay in that reference: it owns the validator launch and the run-artifact list. Dispatch in sequence the two leaf subagents it names, each seeded with references/finish-review.md, which the leaves read from disk and you do not open: a merge leaf that folds in the peer's findings once and merges from the run dir, then, after you launch and collect the validator it selected, a report leaf that renders the report. Neither leaf launches a subagent; you launch every one. Emit the report leaf's return verbatim as this skill's response. Never synthesize directly from raw reviewer artifacts, and never merge or render in the dispatch context. In the multi-agent path, emit only this skill's report: do not also invoke a harness-native findings or reporting tool, which belongs to the quick-review short-circuit alone.
Show full SKILL.md (271 more words)Show less

Operating principles

  • Report-only by default; never push. A bare ce-code-review invocation produces findings and does not apply them. Entering the apply stage requires apply:local, or an explicit user request in the invoking prompt to apply or fix this review's findings; a deprecated mode:autofix token is neither. mode:agent never mutates the tree, even when nested inside a workflow that later applies findings. Never push, open PRs, or file tickets in any mode.
  • No blocking prompts. Never use AskUserQuestion, request_user_input, ask_user, or other blocking question tools. Infer intent, plan, and scope from explicit tokens, git state, PR metadata, and conversation. Note uncertainty in Coverage or the verdict — do not stop to ask.
  • Explicit mutations only. Never run gh pr checkout, git checkout, git switch, or similar branch-switch commands. Passing a PR number, URL, or branch name selects review scope, not permission to mutate the working tree. Uncommitted work can only be reviewed from the checkout that holds it, so to review it on a feature branch, stay on that branch (or check it out yourself) and pass base: or no target.
  • Report outcomes, not machinery. What you show the user is about the review: what is being examined, which coverage is included and the one-line reason for each conditional lens, the independent cross-model pass, and the findings. Name what the user would recognize, such as a PR number, a reviewer's concern, or a peer model. This skill's internal labels, dispatch bookkeeping, and setup narration stay out of user-facing text. Never claim more about the peer than its receipt attests. This governs what you surface and suppress, not the wording; use your own voice.

© EveryInc, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 40 other files (scripts, references) in skills/ce-code-review of EveryInc/compound-engineering-plugin.

  • SKILL.md
  • references/action-class-rubric.md
  • references/cross-model-recovery.md
  • references/cross-model-review.md
  • references/depth-paths.md
  • references/diff-scope.md
  • references/dispatch-reviewers.md
  • references/findings-schema.json
  • references/finish-input.md
  • references/finish-review.md
  • references/intent-and-plan.md
  • references/modes-and-output.md
  • references/persona-catalog.md
  • references/personas/adversarial-reviewer.md
  • references/personas/agent-native-reviewer.md
  • references/personas/api-contract-reviewer.md
  • references/personas/correctness-reviewer.md
  • references/personas/data-migration-reviewer.md
  • references/personas/deployment-verification-agent.md
  • … and 22 more

Open the folder on GitHubat commit cef001f

Compare with similar skills

Compound Engineering Code Review next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Compound Engineering Code Review compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Compound Engineering Code Review this skillEveryInc/compound-engineering-plugin25k—~2kAutomated safety check: PassMIT
PR Deep VerificationQwenLM/qwen-code28k—~18kAutomated safety check: PassApache-2.0
Dsh Code ReviewZhou-Yujing114514/deepseek-harness-linux116—~2.1kAutomated safety check: PassMIT
Alego Code Reviewsingula-ai/alego109—~2.4kAutomated safety check: PassMIT
Pre-PR Reviewyuga-hashimoto/and-code123—~710Automated safety check: PassMIT
GitHub Swarm Code Reviewruvnet/agentic-flow8166 repos~6.5kAutomated safety check: PassNone

Similar skills

  • PR Deep Verification

    QwenLM/qwen-code

    Runs a sandboxed, evidence-based check of one qwen-code pull request, proving its main change against the base build and writing a report with a machine-readable verdict.

    28k GitHub stars~18k tokensUpdated today
    DevelopmentAuto-check passed
  • Dsh Code Review

    Zhou-Yujing114514/deepseek-harness-linux

    A skill your agent uses when reviewing a pull request in the deepseek-harness repo — orients the reviewer to this codebase's standards (AGENTS.md conventions, defensive patterns, ADRs, quality…

    116 GitHub stars~2.1k tokensUpdated yesterday
    DevelopmentAuto-check passed
  • Alego Code Review

    singula-ai/alego

    A skill your agent uses when reviewing a pull request in the alego repo — orients the reviewer to this codebase's standards (AGENTS.md conventions, defensive patterns, ADRs, quality gates) and the…

    109 GitHub stars~2.4k tokensUpdated 8 days ago
    DevelopmentAuto-check passed
  • Pre-PR Review

    yuga-hashimoto/and-code

    Runs local checks and a repo-reviewer subagent over the whole branch diff before a pull request is opened, then records the approval in the PR description.

    123 GitHub stars~710 tokensUpdated today
    DevelopmentAuto-check passed
  • GitHub Swarm Code Review

    ruvnet/agentic-flow

    Reviews GitHub pull requests with a swarm of specialized agents covering security, performance, architecture, style and accessibility, driven by the gh CLI and ruv-swarm.

    816 GitHub starsUsed in 6 repos~6.5k tokens
    DevelopmentAuto-check passed
  • PR Babysitter

    openinterpreter/openinterpreter

    Watches an open GitHub pull request until it merges, handling review comments, diagnosing CI failures and retrying flaky checks along the way.

    69k GitHub starsUsed in 3 repos~4.2k tokens
    DevelopmentAuto-check passed

More from EveryInc/compound-engineering-plugin

All 37 skills in this repo
  • Compound Learning Writer

    EveryInc/compound-engineering-plugin

    Records one solved and verified problem as a durable learning in the repository, but only when the reasoning is not already clear from the final code, tests or docs.

    25k GitHub stars~2k tokensUpdated today
    Auto-check passed
  • Compound Learnings Refresh

    EveryInc/compound-engineering-plugin

    Audits a repo's stored learnings against the current codebase, fixes stale, overlapping or superseded docs and reports on every document.

    25k GitHub stars~2k tokensUpdated today
    Auto-check passed
  • Compound Engineering Prototype

    EveryInc/compound-engineering-plugin

    Builds a throwaway prototype at just the fidelity needed to settle a specific how-it-should-work-or-feel question, before committing to an approach other work will treat as fixed.

    25k GitHub stars~1.9k tokensUpdated today
    Auto-check passed
  • Compound Engineering Setup

    EveryInc/compound-engineering-plugin

    Checks Compound Engineering plugin health and repo-local config, or scaffolds a Compound Pack when you ask for one by id.

    25k GitHub stars~1.9k tokensUpdated today
    Auto-check passed
  • PR Babysitter

    EveryInc/compound-engineering-plugin

    Watches an open GitHub pull request over time, routing review comments and CI failures to other skills until the PR is ready to merge.

    25k GitHub stars~2k tokensUpdated today
    Auto-check passed
  • CE Brainstorm

    EveryInc/compound-engineering-plugin

    Turns a vague or ambitious feature idea into a requirements-only plan through dialogue with you, sized to the work, before any code is written.

    25k GitHub stars~1.9k tokensUpdated today
    Auto-check passed

Questions about Compound Engineering Code Review

What does Compound Engineering Code Review do?

Runs a staged pull request or diff review using selected reviewer personas, checking the change against its stated intent and project standards before producing findings. The review proceeds through a fixed sequence of stages, each governed by its own reference file read exactly when that stage begins. It first resolves settings and the review depth (a quick, lite-only pass stops the run early), then resolves the diff scope, writes an intent summary every reviewer persona will see, and discovers the plan that a later stage checks requirements against.

When should I use Compound Engineering Code Review?

Compound Engineering Code Review fits situations like: reviewing a named pull request or diff before it merges; running a multi-persona adversarial review on a risky change; producing a review artifact that records findings against project standards; verifying a change against its stated intent rather than a preferred rewrite.

How do I install Compound Engineering Code Review in Claude Code?

Run `npx skills add EveryInc/compound-engineering-plugin --skill ce-code-review -a claude-code`. Or copy the skill folder (skills/ce-code-review in EveryInc/compound-engineering-plugin) into .claude/skills/ce-code-review in your project. Claude Code loads it when a task matches its description.

How do I install Compound Engineering Code Review in Codex?

Run `npx skills add EveryInc/compound-engineering-plugin --skill ce-code-review -a codex`. Or copy the skill folder (skills/ce-code-review in EveryInc/compound-engineering-plugin) into .agents/skills/ce-code-review in your project. Codex loads it when a task matches its description.

Can I use Compound Engineering Code Review in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add EveryInc/compound-engineering-plugin --skill ce-code-review -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/ce-code-review, .gemini/skills/ce-code-review, .github/skills/ce-code-review and .opencode/skills/ce-code-review in your project.

What does Compound Engineering Code Review need to run?

Going by SKILL.md and its folder, Compound Engineering Code Review needs the command-line tools its instructions call (git and gh). Our summary lists: A repository with a `.compound-engineering/config.yaml` file.

Does Compound Engineering Code Review access the network?

SKILL.md contains no URLs. Its commands use git and gh, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Compound Engineering Code Review safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Compound Engineering Code Review use?

Compound Engineering Code Review is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Compound Engineering Code Review use?

About 2k tokens (SKILL.md is roughly 7.8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 94k tokens, read only when the agent opens those files.

What are the alternatives to Compound Engineering Code Review?

Skills that share tags, products or a category with Compound Engineering Code Review: PR Deep Verification (QwenLM/qwen-code, 28k stars), Dsh Code Review (Zhou-Yujing114514/deepseek-harness-linux, 116 stars), Alego Code Review (singula-ai/alego, 109 stars) and Pre-PR Review (yuga-hashimoto/and-code, 123 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Compound Engineering Code Review?

EveryInc (a GitHub organization) maintains it in EveryInc/compound-engineering-plugin, which has 25,412 GitHub stars. The repository holds 37 skills in this directory. The repository was last updated on October 7, 2026.

Source: EveryInc/compound-engineering-plugin on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.