Agent skill

Code Review

by fossasia in fossasia/eventyay

How to review code and Pull Requests in the Eventyay repository against canonical instructions.

Apache-2.0Auto-check passedDevelopment

Install Code Review

skills CLI
$ npx skills add fossasia/eventyay --skill code-review -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install fossasia/eventyay code-review --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/fossasia/eventyay.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.github/skills/code-review .claude/skills/code-review && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
code-review
GitHub stars
1.7k
Token cost
~949 tokens
SKILL.md length
418 words
Files
1
Skills in repo
21
Repo updated
First seen
Licence
Apache-2.0

At a glance

How to review code and Pull Requests in the Eventyay repository against canonical instructions.

  • Works in 4 steps: Initial Triage & Architecture Checks → File-Scoped Standard Enforcement → Security, Validation & State → …
  • Tasks that involve Code review
  • SKILL.md covers 1. Initial Triage &…, 2. File-Scoped Standard…, 3. Security, Validation & State and 4. Providing Actionable Feedback
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Code Review is an agent skill from fossasia/eventyay. How to review code and Pull Requests in the Eventyay repository against canonical instructions.

Its SKILL.md is about 950 tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Development, covering Code review and Pull requests. It works with Vue.js, Python, Django and GitHub. The repository describes itself as: Open Source Event Management, Ticketing and Checkins, Talks and Schedules, Video and Interpretations, Badges, Exhibitions and more https://eventyay.com. The licence is Apache-2.0.

When your agent uses it

  • Tasks that involve Code review
  • Tasks that involve Pull requests

Example prompts

  • “/code-review”

Requirements

  • Python 3

Workflow steps

4 steps, taken from the step headings in SKILL.md.

  1. Initial Triage & Architecture Checks
  2. File-Scoped Standard Enforcement
  3. Security, Validation & State
  4. Providing Actionable Feedback

What it can do on your machine

Read from SKILL.md and the folder at commit d7b6e86. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Code Review loads about 949 tokens when it runs. Until then it costs about 27 tokens; SKILL.md has 418 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~27
When it runs · the whole SKILL.md, loaded when a task matches
~949

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from fossasia/eventyay at commit d7b6e86, republished under its Apache-2.0 licence (© fossasia). 418 words, ~949 tokens.

Download SKILL.mdSave it as .claude/skills/code-review/SKILL.md (or your agent's skills folder).
name
code-review
description
How to review code and Pull Requests in the Eventyay repository against canonical instructions.

Code Review Protocol

This skill provides the standard operating procedure for AI agents (like GitHub Copilot, Claude, etc.) performing code reviews on the Eventyay repository.

1. Initial Triage & Architecture Checks

Before reviewing specific business logic, strictly enforce these Non-Negotiable Architecture Rules (from AGENTS.md):

  • Location Verification: New product code must reside under app/eventyay/. Tests must reside under app/tests/. Ensure legacy directories (talk/, video/, src/) are not being actively modified unless requested.
  • Legacy Namespaces: Reject any new imports or logic using pretix.*, pretalx.*, or venueless.*. All new code must use the eventyay.* namespace.
  • Multi-tenancy (Crucial): Any ORM query accessing event-specific data MUST be wrapped securely with django_scopes.scope(event=event). Flag missing scopes immediately.
  • ORM Efficiency: Check for N+1 query vulnerabilities. Ensure select_related and prefetch_related are used appropriately.
  • Error Handling: Reject the use of generic Exception blocks. Code must catch specific exception types.
  • Imports Structure: Imports must be at the top of the file. Local imports inside functions/methods are strictly for resolving circular dependencies.
  • Frontend Hard Rules: No jQuery. No inline scripts in templates. JavaScript must use external ES modules.

2. File-Scoped Standard Enforcement

During the review, you MUST apply the canonical scoped rules based on the files modified in the pull request:

File TypeInstruction File to EnforceKey Review Focus
Python (.py).github/instructions/python.instructions.mdPython 3.12 compatibility, correct typing, proper Django 5.2+ usage, Celery task definitions.
JavaScript/Vue (.js, .vue).github/instructions/js.instructions.mdVue 3 composition API standards, ES modules, strict absence of jQuery.
Django Templates (.html).github/instructions/django-template.instructions.mdStructural integrity, template tag correctness, absence of inline JavaScript.
Jinja Templates (.html, .j2).github/instructions/jinja.instructions.mdSyntax correctness, context safety and proper escaping.
Dockerfile.github/instructions/dockerfile.instructions.mdSecurity, multi-stage build best practices, minimal layer size.
TOML (.toml).github/instructions/toml.instructions.mdSyntax validity, uv dependency alignment (app/pyproject.toml).
Git Commits.github/instructions/git-commit.instructions.mdConventional commit formatting, descriptive bodies.
Show full SKILL.md (129 more words)Show less

3. Security, Validation & State

  • Permissions: Verify that new endpoints or views enforce appropriate Django/DRF permissions and scopes.
  • Validation: Ensure all incoming data is validated via Django forms or DRF serializers.
  • Runtime Context: Keep in mind the stack runs on PostgreSQL, Redis, Channels, and Celery. Review background tasks for idempotency and transaction safety.

4. Providing Actionable Feedback

When leaving review comments:

  1. Be Explicit: Do not just say "fix imports". Say "Use eventyay.* for this import instead of pretalx.*".
  2. Provide Code Snippets: If an ORM query is missing a scope, provide the correct wrapped django_scopes.scope(...) snippet.
  3. Cite Sources: Reference AGENTS.md or the specific file in .github/instructions/ to reinforce the source of truth.
  4. Prioritize Severity: Call out missing Django Scopes, N+1 queries, and generic exceptions as block-level issues.

© fossasia, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .github/skills/code-review of fossasia/eventyay.

Open the folder on GitHubat commit d7b6e86

Compare with similar skills

Code Review next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Code Review compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Code Review this skillfossasia/eventyay1.7k—~949Automated safety check: PassApache-2.0
Code Review Skillawesome-skills/code-review-skill2.1k—~2.8kAutomated safety check: NotesMIT
Code Review SkillRain-kl/OpenFlare288—~2.3kAutomated safety check: NotesMIT
Code Review Excellenceandrew-yangy/gru-ai155—~1.7kAutomated safety check: NotesMIT
PR Review Comments Fetcherwarpdotdev/warp65k1 repos~1.1kAutomated safety check: PassAGPL-3.0
GitHub Pull Request Reviewergoogle/adk-recipes10k—~8.4kAutomated safety check: PassApache-2.0

Similar skills

  • Code Review Skill

    awesome-skills/code-review-skill

    Provides comprehensive code review guidance for React 19, Vue 3, Angular 17+, Svelte 5, Rust, TypeScript, Java, Java 8, PHP, Ruby, Rails, Python, Django, FastAPI, Go, C/.NET, Kotlin, Swift, Dart…

    2.1k GitHub stars~2.8k tokensUpdated 29 days ago
    DevelopmentAuto-check: notes
  • Code Review Skill

    Rain-kl/OpenFlare

    Provides comprehensive code review guidance for React 19, Vue 3, Angular 17+, Svelte 5, Rust, TypeScript, Java, PHP, Python, Django, Go, C/.NET, Kotlin, Swift, NestJS, C/C++, and more.

    288 GitHub stars~2.3k tokensUpdated today
    DevelopmentAuto-check: notes
  • Code Review Excellence

    andrew-yangy/gru-ai

    Provides comprehensive code review guidance for React 19, Vue 3, Rust, TypeScript, Java, Python, and C/C++.

    155 GitHub stars~1.7k tokensUpdated 7 mo ago
    DevelopmentAuto-check: notes
  • Pulls every review comment from the current branch's GitHub pull request into Warp's code review panel, then waits for your direction.

    65k GitHub starsUsed in 1 repo~1.1k tokens
    DevelopmentAuto-check passed
  • Official

    Reviews a GitHub pull request and drafts a small set of inline comments in a human reviewing voice, each checkable from the line it points at, then posts them after approval.

    10k GitHub stars~8.4k tokensUpdated yesterday
    DevelopmentAuto-check passed
  • Smart PR Review

    LeoYeAI/openclaw-master-skills

    Opinionated AI code reviewer — not a yes-machine. An agent skill from LeoYeAI/openclaw-master-skills.

    2.2k GitHub stars~2.7k tokensUpdated 2 mo ago
    DevelopmentAuto-check: notes

More from fossasia/eventyay

All 21 skills in this repo
  • Stripe Projects

    fossasia/eventyay

    A skill your agent uses when the user wants to provision infrastructure or third-party services using Stripe Projects.

    1.7k GitHub starsUsed in 5 repos~2k tokens
    Auto-check: notes
  • Stripe Apps

    fossasia/eventyay

    A skill your agent uses when building, modifying, or reviewing a Stripe App — or when the user describes something that implies one (e.g.

    1.7k GitHub starsUsed in 1 repo~3.6k tokens
    Auto-check passed
  • Connect Recommend

    fossasia/eventyay

    A skill your agent uses when the user asks about Stripe Connect configuration, charge patterns, Dashboard access, or how to get started with Connect, is building a marketplace, platform…

    1.7k GitHub starsUsed in 1 repo~5.9k tokens
    Auto-check: warnings
  • Django Run Locally

    fossasia/eventyay

    Steps for initiating the Django development server without Docker

    1.7k GitHub stars~411 tokensUpdated today
    Auto-check passed
  • Docker Deployment

    fossasia/eventyay

    Docker Compose, container services, deployment. An agent skill from fossasia/eventyay.

    1.7k GitHub stars~574 tokensUpdated today
    Auto-check: notes
  • Stripe Best Practices

    fossasia/eventyay

    Guides Stripe integration decisions across development and test environment planning (separate sandboxes vs the shared test mode sandbox), API selection (Checkout Sessions vs PaymentIntents)…

    1.7k GitHub starsUsed in 1 repo~1.7k tokens
    Auto-check passed

Categories

Questions about Code Review

What does Code Review do?

How to review code and Pull Requests in the Eventyay repository against canonical instructions. Code Review is an agent skill from fossasia/eventyay. How to review code and Pull Requests in the Eventyay repository against canonical instructions.

When should I use Code Review?

Code Review fits situations like: tasks that involve Code review; tasks that involve Pull requests.

How do I install Code Review in Claude Code?

Run `npx skills add fossasia/eventyay --skill code-review -a claude-code`. Or copy the skill folder (.github/skills/code-review in fossasia/eventyay) into .claude/skills/code-review in your project. Claude Code loads it when a task matches its description.

How do I install Code Review in Codex?

Run `npx skills add fossasia/eventyay --skill code-review -a codex`. Or copy the skill folder (.github/skills/code-review in fossasia/eventyay) into .agents/skills/code-review in your project. Codex loads it when a task matches its description.

Can I use Code Review in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add fossasia/eventyay --skill code-review -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/code-review, .gemini/skills/code-review, .github/skills/code-review and .opencode/skills/code-review in your project.

What does Code Review need to run?

SKILL.md names no scripts, command-line tools or credentials: Code Review is instructions for the agent only. Our summary lists: Python 3.

Does Code Review access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Code Review safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Code Review use?

Code Review is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Code Review use?

About 949 tokens (SKILL.md is roughly 3.8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Code Review?

Skills that share tags, products or a category with Code Review: Code Review Skill (awesome-skills/code-review-skill, 2.1k stars), Code Review Skill (Rain-kl/OpenFlare, 288 stars), Code Review Excellence (andrew-yangy/gru-ai, 155 stars) and PR Review Comments Fetcher (warpdotdev/warp, 65k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Code Review?

fossasia (a GitHub organization) maintains it in fossasia/eventyay, which has 1,700 GitHub stars. The repository holds 21 skills in this directory. The repository was last updated on October 7, 2026.

Source: fossasia/eventyay on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.