Review a requested Git diff for bugs, regressions, integration gaps, and material risks before commit.

Apache-2.0Auto-check passedDevelopment

Install Dev Code Review

skills CLI
$ npx skills add hashgraph-online/awesome-codex-plugins --skill dev-code-review -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install hashgraph-online/awesome-codex-plugins dev-code-review --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/hashgraph-online/awesome-codex-plugins.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/Jason-chen-coder/dev-skills/skills/dev-code-review .claude/skills/dev-code-review && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
dev-code-review
GitHub stars
1.2k
Token cost
~1.7k tokens
SKILL.md length
885 words
Files
5 (incl. references)
Skills in repo
736
Repo updated
First seen
Licence
Apache-2.0

At a glance

Review a requested Git diff for bugs, regressions, integration gaps, and material risks before commit.

  • Review requests and the review phase of requests such as 帮我 commit
  • SKILL.md covers Load baseline, Establish exact scope, Review behavior and integration and Severity and evidence, plus 2 more sections
  • Calls git
  • Tasks that involve Code review

What it does

Dev Code Review is an agent skill from hashgraph-online/awesome-codex-plugins. Review a requested Git diff for bugs, regressions, integration gaps, and material risks before commit. Use for review requests and the review phase of requests such as 帮我 commit. A request for only a commit message belongs to dev-commit-writer. Review is read-only; a broader authorized commit workflow may continue after review.

Its SKILL.md is about 1.7k tokens, which your agent loads only when the skill is triggered. The skill folder holds 5 other files, including reference files (for example `examples.md`, `references/dev-baseline.md` and `references/lang-conventions.md`).

It sits in Development, covering Code review and Commit messages. It works with Git. The repository describes itself as: A curated list of awesome OpenAI Codex / ChatGPT plugins, skills, and resources. The 1 Codex Marketplace. See live plugins at: https://hol.org/plugins/best-codex-plugins. The licence is Apache-2.0.

When your agent uses it

  • Review requests and the review phase of requests such as 帮我 commit
  • Tasks that involve Code review
  • Tasks that involve Commit messages

Example prompts

  • “/dev-code-review”

What it can do on your machine

Read from SKILL.md and the folder at commit 16b4156. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • git

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use git, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Dev Code Review loads about 1.7k tokens when it runs, and up to ~5.1k if it reads all its reference files. Until then it costs about 86 tokens; SKILL.md has 885 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~86
When it runs · the whole SKILL.md, loaded when a task matches
~1.7k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~5.1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from hashgraph-online/awesome-codex-plugins at commit 16b4156, republished under its Apache-2.0 licence (© hashgraph-online). 885 words, ~1,733 tokens.

Download SKILL.mdSave it as .claude/skills/dev-code-review/SKILL.md (or your agent's skills folder). This skill also uses 4 other files; get the full folder from GitHub.
name
dev-code-review
description
Review a requested Git diff for bugs, regressions, integration gaps, and material risks before commit. Use for review requests and the review phase of requests such as 帮我 commit. A request for only a commit message belongs to dev-commit-writer. Review is read-only; a broader authorized commit workflow may continue after review.

Dev Code Review

Evaluate the requested change against its intended behavior and surrounding code. Prioritize actionable defects over stylistic preferences. Review and implementation are separate passes.

Load baseline

Read references/dev-baseline.md before execution. Resolve paths relative to this skill directory.

Establish exact scope

Inspect the actual repository root, branch, working-tree status, and staged/unstaged diffs. Honor named paths, exclusions, commits, and --staged / --cached / --path=<glob> arguments.

For a general working-tree review, review staged and unstaged changes while distinguishing them. For a commit request with no explicit scope, use staged changes when present; otherwise infer the requested change from task context. Never silently include unrelated work. If commit scope cannot be determined, finish the readable review and clarify only the ambiguous staging decision before mutation.

Untracked files are absent from git diff; inspect them when they belong to the requested scope. For a staged review, read index versions and evaluate the staged snapshot, including caller relationships. A working-tree test run does not prove a staged snapshot with different contents passes. Use an isolated snapshot when necessary or state that verification limit.

Read changed logic and enough callers, definitions, tests, and configuration to assess behavior. Expand context where a question requires it; do not read entire large files by default. Inspect generated code, dependency resolution, or data changes when they can alter behavior. Binary or generated files may need source or artifact checks, not an unconditional skip.

Review behavior and integration

Use the current request and relevant SDD spec/plan/fix artifacts as the contract. Existing artifacts may live in .claude/artifacts/{designs,plans,fixes}/. Select by actual relevance; a lone artifact is not automatically related. The latest user correction overrides stale text.

Trace changed behavior from its entry point through important transitions and effects. For a new route, component, configuration key, event, or public symbol, verify its registration, consumer, or intended external entry point. Use structural tools or repository search as appropriate, and inspect matches: a textual hit is not proof of a working call path; zero hits is not proof of a defect. Account for framework discovery, reflection, generated registration, and exported library APIs.

Prioritize:

  • Incorrect outputs, error handling, state recovery, and reachable edge cases.
  • Broken registrations, save/restore paths, request transformations, or cross-module contracts.
  • Security boundaries, sensitive data exposure, integrity, concurrency, and resource usage relevant to the diff.
  • Missing tests for consequential behavior, and tests that cannot detect the claimed defect.
  • Unrelated changes that violate the requested commit scope, newly obsolete code, or misleading comments with concrete consequences.

Read references/risk-checklist.md when the diff touches trust boundaries, persistence, concurrency, dependencies, or performance-sensitive paths. Read only relevant language sections of references/lang-conventions.md when convention guidance is needed; project configuration and local conventions govern. Style, line count, debug-like logging, or absent callers alone do not establish severity.

Severity and evidence

  • P0: An immediate, critical defect such as broadly exploitable compromise, severe data loss, or an unconditional release-wide failure. Establish impact and reachability.
  • P1: A high-impact defect in supported use that should be fixed before delivery.
  • P2: A concrete, lower-impact defect or meaningful maintenance/test gap worth fixing.
  • P3: Optional polish, only when useful or requested.

Base priority on consequences and likelihood, not the category of code or a grep count. Mark uncertainty and required conditions. Pre-existing defects are findings only when this change introduces, worsens, or exposes them; identify unrelated observations separately.

Each finding needs a verified location, trigger, consequence, and actionable correction. Do not invent line numbers or claim a vulnerability without a supported path. Avoid reproducing secret values in the report.

Show full SKILL.md (306 more words)Show less

Report and continuation

Lead with findings ordered by severity, followed by open questions, verification gaps, and a brief scope/result. When no actionable issue is found, say so and state material untested areas. Keep the report proportional to the diff; omit empty checklist sections.

Preserve the existing verdict names: BLOCK for critical issues, FIX P1 for high-priority defects that should be fixed before delivery, and READY when review finds no blockers. Use INCOMPLETE when missing evidence prevents a verdict. READY is limited to the reviewed scope and is not a blanket test or production guarantee. Do not emit an unqualified READY while a material review gap remains.

A review-only request does not authorize editing, staging, stashing, or committing. If the user already requested fixes or the full commit flow, report the review result, then let the authorized implementation/delivery lane continue in the same task; do not demand a new user turn solely because review finished. After edits, review the changed result again in a separate pass.

Generate a commit message only when requested by the user or as part of an authorized commit flow and the intended commit is ready. Follow repository history and actual diff intent. Add artifact Refs: only when the association is supported and compatible with repository convention; omit uncertain associations. dev-commit-writer, when installed, may help with formatting but is not required.

Multi-Agent Profile

Recommended agent_type: worker

When independent review is required and delegation is available and permitted, use a reviewer who did not author the implementation. Provide raw scope and requirements rather than the author's preferred conclusion. Keep the reviewer read-only; the main agent owns integration, staging, and authorized delivery. If no independent reviewer is available, disclose that limitation rather than labeling self-review independent.

Use docs/multi-agent-policy.md for repository coordination conventions when available. Standalone installations follow the same separation, scope, and evidence rules above.

© hashgraph-online, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 4 other files (references) in plugins/Jason-chen-coder/dev-skills/skills/dev-code-review of hashgraph-online/awesome-codex-plugins.

  • SKILL.md
  • examples.md
  • references/dev-baseline.md
  • references/lang-conventions.md
  • references/risk-checklist.md

Open the folder on GitHubat commit 16b4156

Compare with similar skills

Dev Code Review next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Dev Code Review compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Dev Code Review this skillhashgraph-online/awesome-codex-plugins1.2k—~1.7kAutomated safety check: PassApache-2.0
GitHub Workflowtransilienceai/communitytools559—~812Automated safety check: NotesMIT
CommitZhangShenao/harness9141—~327Automated safety check: NotesMIT
Ship Thisplanetabhi/riseofmachine111—~2.9kAutomated safety check: PassCustom licence
Aube Bumpnubjs/nub4.4k—~4.3kAutomated safety check: WarnMIT
Cr Commit CheckLeoYeAI/openclaw-master-skills2.2k—~943Automated safety check: PassMIT

Similar skills

  • GitHub Workflow

    transilienceai/communitytools

    GitHub workflow automation — branching, committing, pushing, pull requests, issues, and code review.

    559 GitHub stars~812 tokensUpdated 2 mo ago
    DevelopmentAuto-check: notes
  • Commit

    ZhangShenao/harness9

    A skill your agent uses when the user invokes /commit or asks to commit changes, after a code review has been completed and the changes are confirmed ready to stage and commit to git.

    141 GitHub stars~327 tokensUpdated today
    DevelopmentAuto-check: notes
  • Ship This

    planetabhi/riseofmachine

    Load this skill before shipping a UI change, to statically review the diff for design-craft regressions (accessibility, motion, responsive, and visual or UX drift), correctness and security issues…

    111 GitHub stars~2.9k tokensUpdated 2 days ago
    DevelopmentAuto-check passed
  • Aube Bump

    nubjs/nub

    Bump nub's vendored aube engine to a newer jdx/aube upstream.

    4.4k GitHub stars~4.3k tokensUpdated today
    DevelopmentAuto-check: warnings
  • Cr Commit Check

    LeoYeAI/openclaw-master-skills

    【Code Review 子 Agent · 门控一】校验本迭代所有 commit 是否符合 Conventional Commits 规范及项目可追溯性格式。输入 git log 片段和项目元数据,输出结构化校验报告并以 STATUS=OK|FAIL 结尾。由 spec-driven-dev 的 codereview 阶段自动调用,不建议单独触发。

    2.2k GitHub stars~943 tokensUpdated 2 mo ago
    DevelopmentAuto-check passed
  • Spec Driven Dev

    LeoYeAI/openclaw-master-skills

    在克隆的 Git 仓库中驱动完整的规格驱动开发生命周期(init→requirements→architecture→processdesign→projectplan→coding→test→bugfix→codereview→release)。阶段门控、产物强制输出、多语言支持,内置 commit message 检查、代码门控与 LOGAF Checklist 评审,支持任意阶段…

    2.2k GitHub stars~4.8k tokensUpdated 2 mo ago
    DevelopmentAuto-check passed

More from hashgraph-online/awesome-codex-plugins

All 736 skills in this repo
  • Anime Reaction Gif

    hashgraph-online/awesome-codex-plugins

    Create original anime-style reaction stickers as looping GIFs and MP4 previews, using generated character pose sheets and timed key poses.

    1.2k GitHub stars~922 tokensUpdated yesterday
    Auto-check passed
  • Calibredb

    hashgraph-online/awesome-codex-plugins

    Manage and query Calibre libraries with the calibredb CLI (local paths or Calibre Content server URLs).

    1.2k GitHub stars~1k tokensUpdated yesterday
    Auto-check passed
  • Rust API Test Harness

    hashgraph-online/awesome-codex-plugins

    A skill your agent uses when adding, changing, testing, or debugging Rust HTTP APIs and services, especially when Codex needs black-box integration tests, random-port app startup, real database test…

    1.2k GitHub stars~1.7k tokensUpdated yesterday
    Auto-check passed
  • Art

    hashgraph-online/awesome-codex-plugins

    Make a studio's game look like something at build time — a cover from a real frame of the game (free), painted covers, backdrops, textures and character plates from image models through the…

    1.2k GitHub stars~2.4k tokensUpdated yesterday
    Auto-check passed
  • Calle

    hashgraph-online/awesome-codex-plugins

    Use CALL-E from Codex through the calle CLI. An agent skill from hashgraph-online/awesome-codex-plugins.

    1.2k GitHub stars~2.9k tokensUpdated yesterday
    Auto-check passed
  • Game Balance Economy

    hashgraph-online/awesome-codex-plugins

    Balance game difficulty, resources, rewards, probability, progression, economies, and dominant strategies.

    1.2k GitHub stars~618 tokensUpdated yesterday
    Auto-check passed

Works with

Categories

Questions about Dev Code Review

What does Dev Code Review do?

Review a requested Git diff for bugs, regressions, integration gaps, and material risks before commit. Dev Code Review is an agent skill from hashgraph-online/awesome-codex-plugins. Review a requested Git diff for bugs, regressions, integration gaps, and material risks before commit.

When should I use Dev Code Review?

Dev Code Review fits situations like: review requests and the review phase of requests such as 帮我 commit; tasks that involve Code review; tasks that involve Commit messages.

How do I install Dev Code Review in Claude Code?

Run `npx skills add hashgraph-online/awesome-codex-plugins --skill dev-code-review -a claude-code`. Or copy the skill folder (plugins/Jason-chen-coder/dev-skills/skills/dev-code-review in hashgraph-online/awesome-codex-plugins) into .claude/skills/dev-code-review in your project. Claude Code loads it when a task matches its description.

How do I install Dev Code Review in Codex?

Run `npx skills add hashgraph-online/awesome-codex-plugins --skill dev-code-review -a codex`. Or copy the skill folder (plugins/Jason-chen-coder/dev-skills/skills/dev-code-review in hashgraph-online/awesome-codex-plugins) into .agents/skills/dev-code-review in your project. Codex loads it when a task matches its description.

Can I use Dev Code Review in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add hashgraph-online/awesome-codex-plugins --skill dev-code-review -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/dev-code-review, .gemini/skills/dev-code-review, .github/skills/dev-code-review and .opencode/skills/dev-code-review in your project.

What does Dev Code Review need to run?

Going by SKILL.md and its folder, Dev Code Review needs the command-line tools its instructions call (git).

Does Dev Code Review access the network?

SKILL.md contains no URLs. Its commands use git, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Dev Code Review safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Dev Code Review use?

Dev Code Review is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Dev Code Review use?

About 1.7k tokens (SKILL.md is roughly 6.9k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 3.4k tokens, read only when the agent opens those files.

What are the alternatives to Dev Code Review?

Skills that share tags, products or a category with Dev Code Review: GitHub Workflow (transilienceai/communitytools, 559 stars), Commit (ZhangShenao/harness9, 141 stars), Ship This (planetabhi/riseofmachine, 111 stars) and Aube Bump (nubjs/nub, 4.4k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Dev Code Review?

hashgraph-online (a GitHub organization) maintains it in hashgraph-online/awesome-codex-plugins, which has 1,232 GitHub stars. The repository holds 736 skills in this directory. The repository was last updated on October 6, 2026.

Source: hashgraph-online/awesome-codex-plugins on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.