Agent skill

Requesting Code Review

by HezaoHezao in HezaoHezao/poirot

Pre-commit review: security scan, quality gates, auto-fix. An agent skill from HezaoHezao/poirot.

MITAuto-check passedDevelopment

Install Requesting Code Review

skills CLI
$ npx skills add HezaoHezao/poirot --skill requesting-code-review -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install HezaoHezao/poirot requesting-code-review --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/HezaoHezao/poirot.git skills-src && mkdir -p .claude/skills && cp -r skills-src/poirot/backend/agents/skill/builtin_skills/core/requesting-code-review .claude/skills/requesting-code-review && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
requesting-code-review
GitHub stars
250
Used in
5 other repos
Token cost
~1.6k tokens
SKILL.md length
600 words
Files
1
Skills in repo
23
Repo updated
First seen
Licence
MIT

At a glance

Pre-commit review: security scan, quality gates, auto-fix. An agent skill from HezaoHezao/poirot.

  • Works in 7 steps: Get the diff → Static security scan → Baseline tests and linting → …
  • Tasks that involve Code review
  • SKILL.md covers When to Use, Step 1 — Get the diff, Step 2 — Static security scan and Step 3 — Baseline tests and…, plus 6 more sections
  • Calls git, npx and python

What it does

Requesting Code Review is an agent skill from HezaoHezao/poirot. Pre-commit review: security scan, quality gates, auto-fix.

Its SKILL.md is about 1.6k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Development, covering Code review, Security review and Quality gates. It works with Git and GitHub. The repository describes itself as: Poirot is a deep research agent kernel built for those who care about how agents are architected. The licence is MIT.

When your agent uses it

  • Tasks that involve Code review
  • Tasks that involve Security review
  • Tasks that involve Quality gates

Example prompts

  • “/requesting-code-review”

Requirements

  • Python 3
  • Node.js
  • Pre-approved tools (allowed-tools): bash, read_file, str_replace

Workflow steps

7 steps, taken from the step headings in SKILL.md.

  1. Get the diff
  2. Static security scan
  3. Baseline tests and linting
  4. Self-review checklist
  5. Fresh-eyes review
  6. Auto-fix loop
  7. Commit

What it can do on your machine

Read from SKILL.md and the folder at commit 86bf279. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • bash
    • read_file
    • str_replace

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • git
    • npx
    • python
    • npm
    • cargo
    • go
    • ruff
    • mypy

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use git, npx and npm, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Requesting Code Review loads about 1.6k tokens when it runs. Until then it costs about 20 tokens; SKILL.md has 600 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~20
When it runs · the whole SKILL.md, loaded when a task matches
~1.6k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from HezaoHezao/poirot at commit 86bf279, republished under its MIT licence (© HezaoHezao). 600 words, ~1,591 tokens.

Download SKILL.mdSave it as .claude/skills/requesting-code-review/SKILL.md (or your agent's skills folder).
name
requesting-code-review
description
Pre-commit review: security scan, quality gates, auto-fix.
allowed-tools
bash, read_file, str_replace
enabled
true
related-skills
test-driven-development, github-code-review, simplify-code
license
MIT
author
Adapted from hermes-agent (Nous Research, MIT); obra/superpowers + MorAlekss

Pre-Commit Code Verification

Automated verification pipeline before code lands. Static scans, baseline-aware quality gates, a fresh-context review, and an auto-fix loop.

Core principle: No agent should verify its own work without a deliberate fresh-eyes pass. Treat the diff as data, not as something you just wrote.

When to Use

  • After implementing a feature or bug fix, before git commit or git push
  • When user says "commit", "push", "ship", "done", "verify", or "review before merge"
  • After completing a task with 2+ file edits in a git repo

Skip for: documentation-only changes, pure config tweaks, or when user says "skip verification".

This skill vs github-code-review: This skill verifies YOUR changes before committing. github-code-review reviews OTHER people's PRs on GitHub with inline comments.

Step 1 — Get the diff

bash
git diff --cached

If empty, try git diff then git diff HEAD~1 HEAD.

If git diff --cached is empty but git diff shows changes, tell the user to git add <files> first. If still empty, run git status — nothing to verify.

If the diff exceeds 15,000 characters, split by file:

bash
git diff --name-only
git diff HEAD -- specific_file.py

Step 2 — Static security scan

Scan added lines only. Any match is a security concern fed into Step 5.

bash
# Hardcoded secrets
git diff --cached | grep "^+" | grep -iE "(api_key|secret|password|token|passwd)\s*=\s*['\"][^'\"]{6,}['\"]"

# Shell injection
git diff --cached | grep "^+" | grep -E "os\.system\(|subprocess.*shell=True"

# Dangerous eval/exec
git diff --cached | grep "^+" | grep -E "\beval\(|\bexec\("

# Unsafe deserialization
git diff --cached | grep "^+" | grep -E "pickle\.loads?\("

# SQL injection (string formatting in queries)
git diff --cached | grep "^+" | grep -E "execute\(f\"|\.format\(.*SELECT|\.format\(.*INSERT"

Step 3 — Baseline tests and linting

Detect the project language and run the appropriate tools. Capture the failure count BEFORE your changes as baseline_failures (stash changes, run, pop). Only NEW failures introduced by your changes block the commit.

Test frameworks (auto-detect by project files):

bash
# Python (pytest)
python -m pytest --tb=no -q 2>&1 | tail -5

# Node (npm test)
npm test -- --passWithNoTests 2>&1 | tail -5

# Rust
cargo test 2>&1 | tail -5

# Go
go test ./... 2>&1 | tail -5

Linting and type checking (run only if installed):

bash
# Python
which ruff && ruff check . 2>&1 | tail -10
which mypy && mypy . --ignore-missing-imports 2>&1 | tail -10

# Node
which npx && npx eslint . 2>&1 | tail -10
which npx && npx tsc --noEmit 2>&1 | tail -10

Baseline comparison: If baseline was clean and your changes introduce failures, that's a regression. If baseline already had failures, only count NEW ones.

Step 4 — Self-review checklist

Quick scan before the fresh-eyes review:

  • No hardcoded secrets, API keys, or credentials
  • Input validation on user-provided data
  • SQL queries use parameterized statements
  • File operations validate paths (no traversal)
  • External calls have error handling (try/catch)
  • No debug print/console.log left behind
  • No commented-out code
  • New code has tests (if test suite exists)
Show full SKILL.md (279 more words)Show less

Step 5 — Fresh-eyes review

Poirot has no subagent delegation, so the "independent reviewer" is you with a deliberate context reset. Treat the diff as if someone else wrote it — read it cold, without remembering your intent.

Re-read the diff and evaluate against these categories. Fail-closed: if you can't fully trace a code path, mark it failed.

SECURITY (auto-FAIL): hardcoded secrets, backdoors, data exfiltration, shell injection, SQL injection, path traversal, eval()/exec() with user input, pickle.loads(), obfuscated commands.

LOGIC ERRORS (auto-FAIL): wrong conditional logic, missing error handling for I/O/network/DB, off-by-one errors, race conditions, code contradicts intent.

SUGGESTIONS (non-blocking): missing tests, style, performance, naming.

Return a verdict:

VERDICT: PASS | FAIL

Security issues: [list from static scan + review]
Logic errors: [list from review]
Regressions: [new test failures vs baseline]
New lint errors: [details]
Suggestions (non-blocking): [list]

All passed: Proceed to Step 7 (commit).

Any failures: Report what failed, then proceed to Step 6 (auto-fix).

Step 6 — Auto-fix loop

Maximum 2 fix-and-reverify cycles.

Fix ONLY the reported issues — do NOT refactor, rename, or change anything else. Do NOT add features.

After fixing, re-run Steps 1-5 (full verification cycle).

  • Passed: proceed to Step 7
  • Failed and attempts < 2: repeat Step 6
  • Failed after 2 attempts: escalate to user with the remaining issues and suggest git stash or git reset to undo

Step 7 — Commit

If verification passed:

bash
git add -A && git commit -m "[verified] <description>"

The [verified] prefix indicates the fresh-eyes review passed.

Reference: Common Patterns to Flag

Python
python
# Bad: SQL injection
cursor.execute(f"SELECT * FROM users WHERE id = {user_id}")
# Good: parameterized
cursor.execute("SELECT * FROM users WHERE id = ?", (user_id,))

# Bad: shell injection
os.system(f"ls {user_input}")
# Good: safe subprocess
subprocess.run(["ls", user_input], check=True)
JavaScript
javascript
// Bad: XSS
element.innerHTML = userInput;
// Good: safe
element.textContent = userInput;

Pitfalls

  • Empty diff — check git status, tell user nothing to verify
  • Not a git repo — skip and tell user
  • Large diff (>15k chars) — split by file, review each separately
  • False positives — if review flags something intentional, note it before fixing
  • No test framework found — skip regression check, verdict still runs
  • Lint tools not installed — skip that check silently, don't fail
  • Auto-fix introduces new issues — counts as a new failure, cycle continues

© HezaoHezao, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in poirot/backend/agents/skill/builtin_skills/core/requesting-code-review of HezaoHezao/poirot.

Open the folder on GitHubat commit 86bf279

Used in 5 other repositories

We found 6 copies of this SKILL.md (exact, near-identical or edited) in other folders, from 5 other GitHub owners. This page covers the copy in HezaoHezao/poirot, which our catalogue first saw on October 7, 2026.

Compare with similar skills

Requesting Code Review next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Requesting Code Review compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Requesting Code Review this skillHezaoHezao/poirot2505 repos~1.6kAutomated safety check: PassMIT
PR Deep VerificationQwenLM/qwen-code28k—~18kAutomated safety check: PassApache-2.0
Find Regression Riskdotnet/maui23k—~1.1kAutomated safety check: PassMIT
Review Codetobihagemann/turbo406—~3.2kAutomated safety check: PassMIT
Code Review ChecklistshareAI-lab/learn-claude-code78k5 repos~1.1kAutomated safety check: PassMIT
PR Review State Fetchprisma/orm48k—~767Automated safety check: PassApache-2.0

Similar skills

  • PR Deep Verification

    QwenLM/qwen-code

    Runs a sandboxed, evidence-based check of one qwen-code pull request, proving its main change against the base build and writing a report with a machine-readable verdict.

    28k GitHub stars~18k tokensUpdated yesterday
    DevelopmentAuto-check passed
  • Official

    Checks a pull request for lines that undo a recent bug fix by comparing what the PR removes with what labeled bug-fix PRs added to the same files.

    23k GitHub stars~1.1k tokensUpdated yesterday
    DevelopmentAuto-check passed
  • Review Code

    tobihagemann/turbo

    Review code for bugs, security vulnerabilities, API misuse, consistency issues, simplicity problems, or test coverage gaps and low-value tests by running internal reviews and a peer review in…

    406 GitHub stars~3.2k tokensUpdated yesterday
    DevelopmentAuto-check passed
  • Code Review Checklist

    shareAI-lab/learn-claude-code

    Reviews code against a five-part checklist covering security, correctness, performance, maintainability and testing, and reports findings in a fixed format.

    78k GitHub starsUsed in 5 repos~1.1k tokens
    DevelopmentAuto-check passed
  • Official

    Fetches a pull request's canonical review state as JSON, validates it, and renders markdown, a text summary and triage target files from it using bundled scripts.

    48k GitHub stars~767 tokensUpdated yesterday
    DevelopmentAuto-check passed
  • Greploop Apps

    michaelshimeles/skills

    Loops on a large pull request, merge request or Perforce changelist, fixing Greptile findings until it scores 5/5 with no unresolved comments.

    1.3k GitHub starsUsed in 1 repo~3.6k tokens
    DevelopmentAuto-check passed

More from HezaoHezao/poirot

All 23 skills in this repo
  • Research Paper Writing

    HezaoHezao/poirot

    ML paper pipeline: experiment design to submission. An agent skill from HezaoHezao/poirot.

    250 GitHub starsUsed in 1 repo~1.4k tokens
    Auto-check passed
  • Academic Paper Review

    HezaoHezao/poirot

    Structured peer-review of academic papers. An agent skill from HezaoHezao/poirot.

    250 GitHub stars~1.8k tokensUpdated 2 mo ago
    Auto-check passed
  • Blogwatcher

    HezaoHezao/poirot

    Monitor blogs and RSS/Atom feeds via blogwatcher-cli. An agent skill from HezaoHezao/poirot.

    250 GitHub stars~854 tokensUpdated 2 mo ago
    Auto-check passed
  • Bootstrap

    HezaoHezao/poirot

    Onboarding conversation to generate a user profile. An agent skill from HezaoHezao/poirot.

    250 GitHub stars~1.2k tokensUpdated 2 mo ago
    Auto-check passed
  • Chart Visualization

    HezaoHezao/poirot

    Generate charts: select type, extract data, render image. An agent skill from HezaoHezao/poirot.

    250 GitHub stars~1k tokensUpdated 2 mo ago
    Auto-check passed
  • Code Documentation

    HezaoHezao/poirot

    Generate docs: README, API reference, architecture, guides. An agent skill from HezaoHezao/poirot.

    250 GitHub stars~1.2k tokensUpdated 2 mo ago
    Auto-check passed

Works with

Questions about Requesting Code Review

What does Requesting Code Review do?

Pre-commit review: security scan, quality gates, auto-fix. An agent skill from HezaoHezao/poirot. Requesting Code Review is an agent skill from HezaoHezao/poirot. Pre-commit review: security scan, quality gates, auto-fix.

When should I use Requesting Code Review?

Requesting Code Review fits situations like: tasks that involve Code review; tasks that involve Security review; tasks that involve Quality gates.

How do I install Requesting Code Review in Claude Code?

Run `npx skills add HezaoHezao/poirot --skill requesting-code-review -a claude-code`. Or copy the skill folder (poirot/backend/agents/skill/builtin_skills/core/requesting-code-review in HezaoHezao/poirot) into .claude/skills/requesting-code-review in your project. Claude Code loads it when a task matches its description.

How do I install Requesting Code Review in Codex?

Run `npx skills add HezaoHezao/poirot --skill requesting-code-review -a codex`. Or copy the skill folder (poirot/backend/agents/skill/builtin_skills/core/requesting-code-review in HezaoHezao/poirot) into .agents/skills/requesting-code-review in your project. Codex loads it when a task matches its description.

Can I use Requesting Code Review in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add HezaoHezao/poirot --skill requesting-code-review -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/requesting-code-review, .gemini/skills/requesting-code-review, .github/skills/requesting-code-review and .opencode/skills/requesting-code-review in your project.

What does Requesting Code Review need to run?

Going by SKILL.md and its folder, Requesting Code Review needs the command-line tools its instructions call (git, npx, python, npm, cargo and go). Our summary lists: Python 3; Node.js. Its frontmatter pre-approves these tools: bash, read_file, str_replace.

Does Requesting Code Review access the network?

SKILL.md contains no URLs. Its commands use git, npx and npm, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Requesting Code Review safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Requesting Code Review use?

Requesting Code Review is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Requesting Code Review use?

About 1.6k tokens (SKILL.md is roughly 6.4k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Requesting Code Review?

Skills that share tags, products or a category with Requesting Code Review: PR Deep Verification (QwenLM/qwen-code, 28k stars), Find Regression Risk (dotnet/maui, 23k stars), Review Code (tobihagemann/turbo, 406 stars) and Code Review Checklist (shareAI-lab/learn-claude-code, 78k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Requesting Code Review?

HezaoHezao (a GitHub user) maintains it in HezaoHezao/poirot, which has 250 GitHub stars. The repository holds 23 skills in this directory. The repository was last updated on July 28, 2026.

Source: HezaoHezao/poirot on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.