Code Review Checklist
shareAI-lab/learn-claude-code
Reviews code against a five-part checklist covering security, correctness, performance, maintainability and testing, and reports findings in a fixed format.
Apply safe error-pattern matching rules for agentic engines.
$ npx skills add github/gh-aw --skill error-pattern-safety -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install github/gh-aw error-pattern-safety --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/github/gh-aw.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.github/skills/error-pattern-safety .claude/skills/error-pattern-safety && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "error-pattern-safety" agent skill from https://github.com/github/gh-aw/tree/main/.github/skills/error-pattern-safety into .claude/skills/error-pattern-safety/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "error-pattern-safety", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/github/gh-aw/tree/main/.github/skills/error-pattern-safetyType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add github/gh-aw --skill error-pattern-safety -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install github/gh-aw error-pattern-safety --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/github/gh-aw.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.github/skills/error-pattern-safety .agents/skills/error-pattern-safety && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "error-pattern-safety" agent skill from https://github.com/github/gh-aw/tree/main/.github/skills/error-pattern-safety into .agents/skills/error-pattern-safety/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "error-pattern-safety", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add github/gh-aw --skill error-pattern-safety -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install github/gh-aw error-pattern-safety --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/github/gh-aw.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.github/skills/error-pattern-safety .cursor/skills/error-pattern-safety && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "error-pattern-safety" agent skill from https://github.com/github/gh-aw/tree/main/.github/skills/error-pattern-safety into .cursor/skills/error-pattern-safety/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "error-pattern-safety", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/github/gh-aw.git --path .github/skills/error-pattern-safety--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add github/gh-aw --skill error-pattern-safety -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install github/gh-aw error-pattern-safety --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/github/gh-aw.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.github/skills/error-pattern-safety .gemini/skills/error-pattern-safety && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "error-pattern-safety" agent skill from https://github.com/github/gh-aw/tree/main/.github/skills/error-pattern-safety into .gemini/skills/error-pattern-safety/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "error-pattern-safety", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install github/gh-aw error-pattern-safetyInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add github/gh-aw --skill error-pattern-safety -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/github/gh-aw.git skills-src && mkdir -p .github/skills && cp -r skills-src/.github/skills/error-pattern-safety .github/skills/error-pattern-safety && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "error-pattern-safety" agent skill from https://github.com/github/gh-aw/tree/main/.github/skills/error-pattern-safety into .github/skills/error-pattern-safety/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "error-pattern-safety", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add github/gh-aw --skill error-pattern-safety -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install github/gh-aw error-pattern-safety --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/github/gh-aw.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.github/skills/error-pattern-safety .opencode/skills/error-pattern-safety && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "error-pattern-safety" agent skill from https://github.com/github/gh-aw/tree/main/.github/skills/error-pattern-safety into .opencode/skills/error-pattern-safety/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "error-pattern-safety", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
error-pattern-safetyApply safe error-pattern matching rules for agentic engines.
Error Pattern Safety is an agent skill from github/gh-aw, published by the product's own GitHub organization. Apply safe error-pattern matching rules for agentic engines.
Its SKILL.md is about 1.3k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It works with JavaScript. The repository describes itself as: GitHub Agentic Workflows. The licence is MIT.
3 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit eb63040. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
makeFrom the folder's file list and the shell code blocks in SKILL.md.
Links to these hosts (documentation or services it may open):
pkg.go.devdeveloper.mozilla.orgFrom URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Error Pattern Safety loads about 1.3k tokens when it runs. Until then it costs about 20 tokens; SKILL.md has 415 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from github/gh-aw at commit eb63040, republished under its MIT licence (© github). 415 words, ~1,344 tokens.
.claude/skills/error-pattern-safety/SKILL.md (or your agent's skills folder).Use these regex safety rules in agentic engines to prevent JavaScript infinite loops.
With the JavaScript global flag (/pattern/g), zero-width matches can cause infinite loops because:
regex.exec() with the g flag uses lastIndex to track positionlastIndex doesn't advance❌ NEVER USE THESE PATTERNS:
// Pure .* - matches everything including empty string at end
/.*/g
// Single character with * - matches zero or more (including zero)
/a*/g
// Patterns that can match empty string
/(x|y)*/g✅ ALWAYS USE PATTERNS LIKE THESE:
// Required prefix before .*
/error.*/gi
/error.*permission.*denied/gi
// Specific structure with required content
/\[(\d{4}-\d{2}-\d{2})\]\s+(ERROR):\s+(.+)/g
// Required characters throughout
/access denied.*user.*not authorized/giAlways require at least one character match
.+ instead of .* when you need "something"Never use bare .* as the entire pattern
error.*.* or .*?Test patterns against empty string
const regex = /your-pattern/g;
if (regex.test("")) {
throw new Error("Pattern matches empty string - DANGEROUS!");
}Use specific anchors when possible
^error.*.*error$\berror\bAll error patterns must pass the same safety checks used by the repo’s unit suite:
// Test that pattern doesn't match empty string
func TestPatternSafety(t *testing.T) {
pattern := "your-pattern"
regex := regexp.MustCompile(pattern)
if regex.MatchString("") {
t.Error("Pattern matches empty string!")
}
}Run the relevant package tests with make test-unit.
test("should not match empty string", () => {
const regex = new RegExp("your-pattern", "g");
expect(regex.test("")).toBe(false);
});Use the relevant *.test.cjs suite under actions/setup/js/ or pkg/workflow/js/ for the area you changed, or run the repo’s JavaScript checks via make test-js.
The repo’s validation helpers include built-in protections for dangerous regex patterns:
if (regex.lastIndex === lastIndex) {
core.error(`Infinite loop detected! Pattern: ${pattern.pattern}`);
break;
}When adding new error patterns to engines:
Write the pattern with required content
{
Pattern: `(?i)error.*permission.*denied`,
LevelGroup: 0,
MessageGroup: 0,
Description: "Permission denied error",
}Test against empty string
make test-unitTestAllEnginePatternsSafeTest with actual log samples
Document the pattern
Patterns are converted from Go to JavaScript:
// Go pattern (case-insensitive flag)
Pattern: `(?i)error.*permission.*denied`
// Converted to JavaScript
new RegExp("error.*permission.*denied", "gi")The (?i) prefix is removed because JavaScript uses the i flag instead.
// Requires "error" prefix
Pattern: `(?i)error.*permission.*denied`
// Requires specific timestamp format
Pattern: `(\d{4}-\d{2}-\d{2}T\d{2}:\d{2}:\d{2}\.\d{3}Z)\s+\[(ERROR)\]\s+(.+)`
// Requires "access denied" prefix
Pattern: `(?i)access denied.*user.*not authorized`If you find a pattern that matches empty string:
Before (unsafe):
Pattern: `.*error.*` // Can match empty at start/endAfter (safe):
Pattern: `error.*` // Requires "error" at start
// OR
Pattern: `.*error.+` // Requires "error" and at least one char after
// OR
Pattern: `\berror\b.*` // Requires word "error"Before committing pattern changes:
make test-unitmake test-js or the targeted Vitest suitemake test-unit and make test-js© github, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in .github/skills/error-pattern-safety of github/gh-aw.
Open the folder on GitHubat commit eb63040
Error Pattern Safety next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Error Pattern Safety this skillgithub/gh-aw | 5.3k | — | ~1.3k | Automated safety check: Pass | MIT | |
| Code Review ChecklistshareAI-lab/learn-claude-code | 78k | 5 repos | ~1.1k | Automated safety check: Pass | MIT | |
| Tailwindcss Developmentanonaddy/anonaddy | 4.9k | 10 repos | ~865 | Automated safety check: Pass | MIT | |
| Figma use_figma Plugin API Ruleswarpdotdev/warp | 65k | 4 repos | ~4.4k | Automated safety check: Pass | AGPL-3.0 | |
| GSAP Core Animationgreensock/gsap-skills | 16k | 4 repos | ~3.7k | Automated safety check: Pass | MIT | |
| JavaScript Concept Fact Checkerleonardomso/33-js-concepts | 67k | 1 repos | ~5k | Automated safety check: Pass | MIT |
shareAI-lab/learn-claude-code
Reviews code against a five-part checklist covering security, correctness, performance, maintainability and testing, and reports findings in a fixed format.
anonaddy/anonaddy
Always invoke when the user's message includes 'tailwind' in any form.
warpdotdev/warp
Required groundwork before any use_figma call: the rules and reference files for running JavaScript in a Figma file through the Plugin API without common failures.
greensock/gsap-skills
Covers the GSAP core API for tweens, easing, staggers, defaults and matchMedia, and when to choose GSAP over CSS animations or other JavaScript animation libraries.
leonardomso/33-js-concepts
Verifies the technical accuracy of JavaScript concept pages by checking code examples, MDN and ECMAScript claims and external links through a five-phase method.
oso95/scroll-world
Builds a scroll-driven landing page where a pre-rendered camera flies through connected AI-generated scenes, using Higgsfield for stills and video clips.
github/gh-aw
Drives a real browser from the command line with playwright-cli to open pages, interact, mock requests, save state and work with Playwright tests.
github/gh-aw
Designs and verifies a deterministic grader that measures whether a GitHub Agentic Workflow run reached its real-world or repository outcome.
github/gh-aw
Scaffolds, edits, reloads and debugs a canvas extension that the GitHub Copilot CLI can open in its side panel.
github/gh-aw
Drives an open pull request to merge-ready from inside a GitHub Copilot cloud agent, resolving review threads and local checks concurrently, without merging or retriggering CI.
github/gh-aw
Bumps gh-aw's pinned gh-aw-firewall version, rebuilds generated artifacts, and flags upstream spec or schema changes that need follow-up work.
github/gh-aw
Guide to the console struct tag system in gh-aw: headers, titles, number and cost formats, omitempty, and how structs, slices and maps render in the terminal.
Works with
Apply safe error-pattern matching rules for agentic engines. Error Pattern Safety is an agent skill from github/gh-aw, published by the product's own GitHub organization. Apply safe error-pattern matching rules for agentic engines.
Run `npx skills add github/gh-aw --skill error-pattern-safety -a claude-code`. Or copy the skill folder (.github/skills/error-pattern-safety in github/gh-aw) into .claude/skills/error-pattern-safety in your project. Claude Code loads it when a task matches its description.
Run `npx skills add github/gh-aw --skill error-pattern-safety -a codex`. Or copy the skill folder (.github/skills/error-pattern-safety in github/gh-aw) into .agents/skills/error-pattern-safety in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add github/gh-aw --skill error-pattern-safety -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/error-pattern-safety, .gemini/skills/error-pattern-safety, .github/skills/error-pattern-safety and .opencode/skills/error-pattern-safety in your project.
Going by SKILL.md and its folder, Error Pattern Safety needs the command-line tools its instructions call (make).
SKILL.md names 2 domains. As links in the text: pkg.go.dev and developer.mozilla.org. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Error Pattern Safety is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 1.3k tokens (SKILL.md is roughly 5.4k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Error Pattern Safety: Code Review Checklist (shareAI-lab/learn-claude-code, 78k stars), Tailwindcss Development (anonaddy/anonaddy, 4.9k stars), Figma use_figma Plugin API Rules (warpdotdev/warp, 65k stars) and GSAP Core Animation (greensock/gsap-skills, 16k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
github (a GitHub organization, an official publisher) maintains it in github/gh-aw, which has 5,350 GitHub stars. The repository holds 52 skills in this directory. The repository was last updated on October 7, 2026.
Source: github/gh-aw on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.