Cwe Code Review
SpecterOps/skills
Perform CWE-grounded security code reviews and precise weakness mapping using a locally derived MITRE CWE corpus, relationship graphs, mapping notes, detection methods, mitigations, and schema…
Record code review findings (GitHub Copilot PR review or a local AI review) that led to a code change in docs/code-review-feedback/ as append-only entries with root-cause analysis.
$ npx skills add haru/redmine_ai_helper --skill record-code-review-feedback -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install haru/redmine_ai_helper record-code-review-feedback --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/haru/redmine_ai_helper.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/record-code-review-feedback .claude/skills/record-code-review-feedback && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "record-code-review-feedback" agent skill from https://github.com/haru/redmine_ai_helper/tree/main/.claude/skills/record-code-review-feedback into .claude/skills/record-code-review-feedback/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "record-code-review-feedback", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/haru/redmine_ai_helper/tree/main/.claude/skills/record-code-review-feedbackType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add haru/redmine_ai_helper --skill record-code-review-feedback -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install haru/redmine_ai_helper record-code-review-feedback --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/haru/redmine_ai_helper.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.claude/skills/record-code-review-feedback .agents/skills/record-code-review-feedback && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "record-code-review-feedback" agent skill from https://github.com/haru/redmine_ai_helper/tree/main/.claude/skills/record-code-review-feedback into .agents/skills/record-code-review-feedback/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "record-code-review-feedback", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add haru/redmine_ai_helper --skill record-code-review-feedback -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install haru/redmine_ai_helper record-code-review-feedback --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/haru/redmine_ai_helper.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.claude/skills/record-code-review-feedback .cursor/skills/record-code-review-feedback && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "record-code-review-feedback" agent skill from https://github.com/haru/redmine_ai_helper/tree/main/.claude/skills/record-code-review-feedback into .cursor/skills/record-code-review-feedback/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "record-code-review-feedback", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/haru/redmine_ai_helper.git --path .claude/skills/record-code-review-feedback--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add haru/redmine_ai_helper --skill record-code-review-feedback -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install haru/redmine_ai_helper record-code-review-feedback --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/haru/redmine_ai_helper.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.claude/skills/record-code-review-feedback .gemini/skills/record-code-review-feedback && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "record-code-review-feedback" agent skill from https://github.com/haru/redmine_ai_helper/tree/main/.claude/skills/record-code-review-feedback into .gemini/skills/record-code-review-feedback/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "record-code-review-feedback", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install haru/redmine_ai_helper record-code-review-feedbackInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add haru/redmine_ai_helper --skill record-code-review-feedback -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/haru/redmine_ai_helper.git skills-src && mkdir -p .github/skills && cp -r skills-src/.claude/skills/record-code-review-feedback .github/skills/record-code-review-feedback && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "record-code-review-feedback" agent skill from https://github.com/haru/redmine_ai_helper/tree/main/.claude/skills/record-code-review-feedback into .github/skills/record-code-review-feedback/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "record-code-review-feedback", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add haru/redmine_ai_helper --skill record-code-review-feedback -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install haru/redmine_ai_helper record-code-review-feedback --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/haru/redmine_ai_helper.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.claude/skills/record-code-review-feedback .opencode/skills/record-code-review-feedback && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "record-code-review-feedback" agent skill from https://github.com/haru/redmine_ai_helper/tree/main/.claude/skills/record-code-review-feedback into .opencode/skills/record-code-review-feedback/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "record-code-review-feedback", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
record-code-review-feedbackRecord code review findings (GitHub Copilot PR review or a local AI review) that led to a code change in docs/code-review-feedback/ as append-only entries with root-cause analysis.
Record Code Review Feedback is an agent skill from haru/redmine_ai_helper. Record code review findings (GitHub Copilot PR review or a local AI review) that led to a code change in docs/code-review-feedback/ as append-only entries with root-cause analysis. Use right after fixing code in response to a review finding (AGENTS.md and the constitution require this), or when the user asks to log review feedback. Skips findings that were not adopted.
Its SKILL.md is about 1.1k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Development, covering Code review, Root cause analysis and Pull requests. The repository describes itself as: A Redmine plugin that adds AI agents, MCP Server, smart completion, and vector search. The licence is MIT.
8 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 54cee42. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
ghgitFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use gh and git, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Record Code Review Feedback loads about 1.1k tokens when it runs. Until then it costs about 100 tokens; SKILL.md has 586 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from haru/redmine_ai_helper at commit 54cee42, republished under its MIT licence (© haru). 586 words, ~1,131 tokens.
.claude/skills/record-code-review-feedback/SKILL.md (or your agent's skills folder).Record review findings on AI-generated code that resulted in a fix, analyze why the AI wrote the original code, and derive a rule that prevents the same mistake next time.
$ARGUMENTSConsider any context from the user input (PR number, which findings, the review source) before proceeding.
Read docs/code-review-feedback/README.md. It defines what to record, the root-cause categories, the template, and the index. Follow it; this skill only describes the workflow.
Identify the review source:
GitHub Copilot PR review: determine the PR from the user input or gh pr view --json number -q .number on the current branch, then fetch Copilot's review comments:
gh api repos/{owner}/{repo}/pulls/<PR>/comments --paginate \
--jq '.[] | select(.user.login == "Copilot") | {id, path, line, html_url, body}'Local AI review (/code-review, speckit-review-*, etc.): use the findings reported earlier in the conversation. If they are no longer available (e.g. after /clear or in a new session), ask the user for them instead of reconstructing them.
For each finding, check whether it led to a code change (git diff, git log -p on the affected files, or the conversation). Keep only adopted findings. Skip typo-only and formatting-only fixes.
If nothing remains, stop and tell the user there is nothing to record.
Group the remaining findings by root cause: one entry per root cause.
Scan the index in the README and open entries with the same category or touching the same files/area. If an existing entry describes the same pattern, list it under Related.
Answer concretely:
Pick the category from the README table. Use other only with an explanation.
Write a rule that is concrete and checkable at code-generation time (e.g. "Tools that take a project ID must return the same error for missing and invisible projects" — not "check permissions carefully"). Set Promoted to to Not yet unless the rule is actually added to a durable place.
docs/code-review-feedback/ and add one (start at 001).docs/code-review-feedback/NNN-short-title.md from the template, in English, with today's date. Include the review comment URL and the fix commit hash when available.| [CRF-NNN](./NNN-short-title.md) | Title | category | source | Not yet |.Never edit or delete existing entries, except for updating the Promoted to field in Step 7.
If the new entry has one or more Related entries (the pattern has occurred at least twice), propose to the user where the prevention rule should be promoted (AGENTS.md, the constitution, an ADR, a skill) and show the proposed text. Do not change those files without the user's approval. After the approved rule is added, update the entry's Promoted to field and the matching index cell to name the destination.
Tell the user the created files, categories, prevention rules, and any promotion proposal. Do not commit.
gh fails (not authenticated, API error), report the error to the user instead of guessing the review content.© haru, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in .claude/skills/record-code-review-feedback of haru/redmine_ai_helper.
Open the folder on GitHubat commit 54cee42
Record Code Review Feedback next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Record Code Review Feedback this skillharu/redmine_ai_helper | 106 | — | ~1.1k | Automated safety check: Pass | MIT | |
| Cwe Code ReviewSpecterOps/skills | 706 | — | ~2.4k | Automated safety check: Pass | Apache-2.0 | |
| Code Overviewtestdouble/han | 281 | — | ~8.5k | Automated safety check: Pass | MIT | |
| PR Babysitteropeninterpreter/openinterpreter | 69k | 3 repos | ~4.2k | Automated safety check: Pass | Apache-2.0 | |
| WooCommerce Code Reviewwoocommerce/woocommerce | 11k | 3 repos | ~1.1k | Automated safety check: Pass | Custom licence | |
| Open Code Review CLIalibaba/open-code-review | 46k | — | ~3.1k | Automated safety check: Pass | Apache-2.0 |
SpecterOps/skills
Perform CWE-grounded security code reviews and precise weakness mapping using a locally derived MITRE CWE corpus, relationship graphs, mapping notes, detection methods, mitigations, and schema…
testdouble/han
Produces a human-readable, progressive-disclosure overview of unfamiliar code or a pull request's changes — why it exists (the real problem it solves or goal it serves for the business or a user)…
openinterpreter/openinterpreter
Watches an open GitHub pull request until it merges, handling review comments, diagnosing CI failures and retrying flaky checks along the way.
woocommerce/woocommerce
Reviews WooCommerce code changes against the project's standards, flagging backend PHP architecture, naming, documentation, data integrity and testing violations.
alibaba/open-code-review
Runs the ocr command-line tool to review Git changes, a commit or a branch comparison with an AI model, returning line-level comments and optionally applying fixes.
prisma/orm
Runs a loop on a GitHub pull request: fetch review state, triage comments into actions, implement them and resolve threads, repeating until nothing actionable is left.
haru/redmine_ai_helper
Stage the current changes and create a git commit with a properly formatted English message.
haru/redmine_ai_helper
Create a pull request from the current branch. An agent skill from haru/redmine_ai_helper.
haru/redmine_ai_helper
Create a release branch for a given version. An agent skill from haru/redmine_ai_helper.
haru/redmine_ai_helper
Record a user's correction of an AI-written specification in docs/spec-feedback/ as an append-only entry with root-cause analysis.
haru/redmine_ai_helper
Code quality checks, formatting, and metrics via qlty CLI. An agent skill from haru/redmine_ai_helper.
haru/redmine_ai_helper
Connect to the running Redmine instance and log in via the Playwright MCP browser, using REDMINEPLAYRIGHTURL/REDMINEPLAYRIGHTUSER/REDMINEPLAYRIGHTPASSWORD environment variables.
Categories
Record code review findings (GitHub Copilot PR review or a local AI review) that led to a code change in docs/code-review-feedback/ as append-only entries with root-cause analysis. Record Code Review Feedback is an agent skill from haru/redmine_ai_helper. Record code review findings (GitHub Copilot PR review or a local AI review) that led to a code change in docs/code-review-feedback/ as append-only entries with root-cause analysis.
Record Code Review Feedback fits situations like: asks to log review feedback; tasks that involve Code review; tasks that involve Root cause analysis.
Run `npx skills add haru/redmine_ai_helper --skill record-code-review-feedback -a claude-code`. Or copy the skill folder (.claude/skills/record-code-review-feedback in haru/redmine_ai_helper) into .claude/skills/record-code-review-feedback in your project. Claude Code loads it when a task matches its description.
Run `npx skills add haru/redmine_ai_helper --skill record-code-review-feedback -a codex`. Or copy the skill folder (.claude/skills/record-code-review-feedback in haru/redmine_ai_helper) into .agents/skills/record-code-review-feedback in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add haru/redmine_ai_helper --skill record-code-review-feedback -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/record-code-review-feedback, .gemini/skills/record-code-review-feedback, .github/skills/record-code-review-feedback and .opencode/skills/record-code-review-feedback in your project.
Going by SKILL.md and its folder, Record Code Review Feedback needs the command-line tools its instructions call (gh and git).
SKILL.md contains no URLs. Its commands use gh and git, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Record Code Review Feedback is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 1.1k tokens (SKILL.md is roughly 4.5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Record Code Review Feedback: Cwe Code Review (SpecterOps/skills, 706 stars), Code Overview (testdouble/han, 281 stars), PR Babysitter (openinterpreter/openinterpreter, 69k stars) and WooCommerce Code Review (woocommerce/woocommerce, 11k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
haru (a GitHub user) maintains it in haru/redmine_ai_helper, which has 106 GitHub stars. The repository holds 21 skills in this directory. The repository was last updated on October 11, 2026.
Source: haru/redmine_ai_helper on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.