PR Deep Verification
QwenLM/qwen-code
Runs a sandboxed, evidence-based check of one qwen-code pull request, proving its main change against the base build and writing a report with a machine-readable verdict.
Pre-commit review: security scan, quality gates, auto-fix. An agent skill from HezaoHezao/poirot.
$ npx skills add HezaoHezao/poirot --skill requesting-code-review -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install HezaoHezao/poirot requesting-code-review --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/HezaoHezao/poirot.git skills-src && mkdir -p .claude/skills && cp -r skills-src/poirot/backend/agents/skill/builtin_skills/core/requesting-code-review .claude/skills/requesting-code-review && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "requesting-code-review" agent skill from https://github.com/HezaoHezao/poirot/tree/master/poirot/backend/agents/skill/builtin_skills/core/requesting-code-review into .claude/skills/requesting-code-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "requesting-code-review", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/HezaoHezao/poirot/tree/master/poirot/backend/agents/skill/builtin_skills/core/requesting-code-reviewType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add HezaoHezao/poirot --skill requesting-code-review -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install HezaoHezao/poirot requesting-code-review --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/HezaoHezao/poirot.git skills-src && mkdir -p .agents/skills && cp -r skills-src/poirot/backend/agents/skill/builtin_skills/core/requesting-code-review .agents/skills/requesting-code-review && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "requesting-code-review" agent skill from https://github.com/HezaoHezao/poirot/tree/master/poirot/backend/agents/skill/builtin_skills/core/requesting-code-review into .agents/skills/requesting-code-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "requesting-code-review", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add HezaoHezao/poirot --skill requesting-code-review -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install HezaoHezao/poirot requesting-code-review --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/HezaoHezao/poirot.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/poirot/backend/agents/skill/builtin_skills/core/requesting-code-review .cursor/skills/requesting-code-review && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "requesting-code-review" agent skill from https://github.com/HezaoHezao/poirot/tree/master/poirot/backend/agents/skill/builtin_skills/core/requesting-code-review into .cursor/skills/requesting-code-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "requesting-code-review", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/HezaoHezao/poirot.git --path poirot/backend/agents/skill/builtin_skills/core/requesting-code-review--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add HezaoHezao/poirot --skill requesting-code-review -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install HezaoHezao/poirot requesting-code-review --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/HezaoHezao/poirot.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/poirot/backend/agents/skill/builtin_skills/core/requesting-code-review .gemini/skills/requesting-code-review && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "requesting-code-review" agent skill from https://github.com/HezaoHezao/poirot/tree/master/poirot/backend/agents/skill/builtin_skills/core/requesting-code-review into .gemini/skills/requesting-code-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "requesting-code-review", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install HezaoHezao/poirot requesting-code-reviewInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add HezaoHezao/poirot --skill requesting-code-review -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/HezaoHezao/poirot.git skills-src && mkdir -p .github/skills && cp -r skills-src/poirot/backend/agents/skill/builtin_skills/core/requesting-code-review .github/skills/requesting-code-review && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "requesting-code-review" agent skill from https://github.com/HezaoHezao/poirot/tree/master/poirot/backend/agents/skill/builtin_skills/core/requesting-code-review into .github/skills/requesting-code-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "requesting-code-review", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add HezaoHezao/poirot --skill requesting-code-review -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install HezaoHezao/poirot requesting-code-review --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/HezaoHezao/poirot.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/poirot/backend/agents/skill/builtin_skills/core/requesting-code-review .opencode/skills/requesting-code-review && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "requesting-code-review" agent skill from https://github.com/HezaoHezao/poirot/tree/master/poirot/backend/agents/skill/builtin_skills/core/requesting-code-review into .opencode/skills/requesting-code-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "requesting-code-review", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
requesting-code-reviewPre-commit review: security scan, quality gates, auto-fix. An agent skill from HezaoHezao/poirot.
Requesting Code Review is an agent skill from HezaoHezao/poirot. Pre-commit review: security scan, quality gates, auto-fix.
Its SKILL.md is about 1.6k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Development, covering Code review, Security review and Quality gates. It works with Git and GitHub. The repository describes itself as: Poirot is a deep research agent kernel built for those who care about how agents are architected. The licence is MIT.
7 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 86bf279. It shows what the files ask for, not the result of running them.
Pre-approves these tools, so the agent can use them without asking each time:
bashread_filestr_replaceFrom allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
gitnpxpythonnpmcargogoruffmypyFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use git, npx and npm, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Requesting Code Review loads about 1.6k tokens when it runs. Until then it costs about 20 tokens; SKILL.md has 600 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from HezaoHezao/poirot at commit 86bf279, republished under its MIT licence (© HezaoHezao). 600 words, ~1,591 tokens.
.claude/skills/requesting-code-review/SKILL.md (or your agent's skills folder).Automated verification pipeline before code lands. Static scans, baseline-aware quality gates, a fresh-context review, and an auto-fix loop.
Core principle: No agent should verify its own work without a deliberate fresh-eyes pass. Treat the diff as data, not as something you just wrote.
git commit or git pushSkip for: documentation-only changes, pure config tweaks, or when user says "skip verification".
This skill vs github-code-review: This skill verifies YOUR changes before
committing. github-code-review reviews OTHER people's PRs on GitHub with
inline comments.
git diff --cachedIf empty, try git diff then git diff HEAD~1 HEAD.
If git diff --cached is empty but git diff shows changes, tell the user to
git add <files> first. If still empty, run git status — nothing to verify.
If the diff exceeds 15,000 characters, split by file:
git diff --name-only
git diff HEAD -- specific_file.pyScan added lines only. Any match is a security concern fed into Step 5.
# Hardcoded secrets
git diff --cached | grep "^+" | grep -iE "(api_key|secret|password|token|passwd)\s*=\s*['\"][^'\"]{6,}['\"]"
# Shell injection
git diff --cached | grep "^+" | grep -E "os\.system\(|subprocess.*shell=True"
# Dangerous eval/exec
git diff --cached | grep "^+" | grep -E "\beval\(|\bexec\("
# Unsafe deserialization
git diff --cached | grep "^+" | grep -E "pickle\.loads?\("
# SQL injection (string formatting in queries)
git diff --cached | grep "^+" | grep -E "execute\(f\"|\.format\(.*SELECT|\.format\(.*INSERT"Detect the project language and run the appropriate tools. Capture the failure count BEFORE your changes as baseline_failures (stash changes, run, pop). Only NEW failures introduced by your changes block the commit.
Test frameworks (auto-detect by project files):
# Python (pytest)
python -m pytest --tb=no -q 2>&1 | tail -5
# Node (npm test)
npm test -- --passWithNoTests 2>&1 | tail -5
# Rust
cargo test 2>&1 | tail -5
# Go
go test ./... 2>&1 | tail -5Linting and type checking (run only if installed):
# Python
which ruff && ruff check . 2>&1 | tail -10
which mypy && mypy . --ignore-missing-imports 2>&1 | tail -10
# Node
which npx && npx eslint . 2>&1 | tail -10
which npx && npx tsc --noEmit 2>&1 | tail -10Baseline comparison: If baseline was clean and your changes introduce failures, that's a regression. If baseline already had failures, only count NEW ones.
Quick scan before the fresh-eyes review:
Poirot has no subagent delegation, so the "independent reviewer" is you with a deliberate context reset. Treat the diff as if someone else wrote it — read it cold, without remembering your intent.
Re-read the diff and evaluate against these categories. Fail-closed: if you can't fully trace a code path, mark it failed.
SECURITY (auto-FAIL): hardcoded secrets, backdoors, data exfiltration, shell injection, SQL injection, path traversal, eval()/exec() with user input, pickle.loads(), obfuscated commands.
LOGIC ERRORS (auto-FAIL): wrong conditional logic, missing error handling for I/O/network/DB, off-by-one errors, race conditions, code contradicts intent.
SUGGESTIONS (non-blocking): missing tests, style, performance, naming.
Return a verdict:
VERDICT: PASS | FAIL
Security issues: [list from static scan + review]
Logic errors: [list from review]
Regressions: [new test failures vs baseline]
New lint errors: [details]
Suggestions (non-blocking): [list]All passed: Proceed to Step 7 (commit).
Any failures: Report what failed, then proceed to Step 6 (auto-fix).
Maximum 2 fix-and-reverify cycles.
Fix ONLY the reported issues — do NOT refactor, rename, or change anything else. Do NOT add features.
After fixing, re-run Steps 1-5 (full verification cycle).
git stash or git reset to undoIf verification passed:
git add -A && git commit -m "[verified] <description>"The [verified] prefix indicates the fresh-eyes review passed.
# Bad: SQL injection
cursor.execute(f"SELECT * FROM users WHERE id = {user_id}")
# Good: parameterized
cursor.execute("SELECT * FROM users WHERE id = ?", (user_id,))
# Bad: shell injection
os.system(f"ls {user_input}")
# Good: safe subprocess
subprocess.run(["ls", user_input], check=True)// Bad: XSS
element.innerHTML = userInput;
// Good: safe
element.textContent = userInput;git status, tell user nothing to verify© HezaoHezao, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in poirot/backend/agents/skill/builtin_skills/core/requesting-code-review of HezaoHezao/poirot.
Open the folder on GitHubat commit 86bf279
We found 6 copies of this SKILL.md (exact, near-identical or edited) in other folders, from 5 other GitHub owners. This page covers the copy in HezaoHezao/poirot, which our catalogue first saw on October 7, 2026.
Requesting Code Review next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Requesting Code Review this skillHezaoHezao/poirot | 250 | 5 repos | ~1.6k | Automated safety check: Pass | MIT | |
| PR Deep VerificationQwenLM/qwen-code | 28k | — | ~18k | Automated safety check: Pass | Apache-2.0 | |
| Find Regression Riskdotnet/maui | 23k | — | ~1.1k | Automated safety check: Pass | MIT | |
| Review Codetobihagemann/turbo | 406 | — | ~3.2k | Automated safety check: Pass | MIT | |
| Code Review ChecklistshareAI-lab/learn-claude-code | 78k | 5 repos | ~1.1k | Automated safety check: Pass | MIT | |
| PR Review State Fetchprisma/orm | 48k | — | ~767 | Automated safety check: Pass | Apache-2.0 |
QwenLM/qwen-code
Runs a sandboxed, evidence-based check of one qwen-code pull request, proving its main change against the base build and writing a report with a machine-readable verdict.
dotnet/maui
Checks a pull request for lines that undo a recent bug fix by comparing what the PR removes with what labeled bug-fix PRs added to the same files.
tobihagemann/turbo
Review code for bugs, security vulnerabilities, API misuse, consistency issues, simplicity problems, or test coverage gaps and low-value tests by running internal reviews and a peer review in…
shareAI-lab/learn-claude-code
Reviews code against a five-part checklist covering security, correctness, performance, maintainability and testing, and reports findings in a fixed format.
prisma/orm
Fetches a pull request's canonical review state as JSON, validates it, and renders markdown, a text summary and triage target files from it using bundled scripts.
michaelshimeles/skills
Loops on a large pull request, merge request or Perforce changelist, fixing Greptile findings until it scores 5/5 with no unresolved comments.
HezaoHezao/poirot
ML paper pipeline: experiment design to submission. An agent skill from HezaoHezao/poirot.
HezaoHezao/poirot
Structured peer-review of academic papers. An agent skill from HezaoHezao/poirot.
HezaoHezao/poirot
Monitor blogs and RSS/Atom feeds via blogwatcher-cli. An agent skill from HezaoHezao/poirot.
HezaoHezao/poirot
Onboarding conversation to generate a user profile. An agent skill from HezaoHezao/poirot.
HezaoHezao/poirot
Generate charts: select type, extract data, render image. An agent skill from HezaoHezao/poirot.
HezaoHezao/poirot
Generate docs: README, API reference, architecture, guides. An agent skill from HezaoHezao/poirot.
Categories
Pre-commit review: security scan, quality gates, auto-fix. An agent skill from HezaoHezao/poirot. Requesting Code Review is an agent skill from HezaoHezao/poirot. Pre-commit review: security scan, quality gates, auto-fix.
Requesting Code Review fits situations like: tasks that involve Code review; tasks that involve Security review; tasks that involve Quality gates.
Run `npx skills add HezaoHezao/poirot --skill requesting-code-review -a claude-code`. Or copy the skill folder (poirot/backend/agents/skill/builtin_skills/core/requesting-code-review in HezaoHezao/poirot) into .claude/skills/requesting-code-review in your project. Claude Code loads it when a task matches its description.
Run `npx skills add HezaoHezao/poirot --skill requesting-code-review -a codex`. Or copy the skill folder (poirot/backend/agents/skill/builtin_skills/core/requesting-code-review in HezaoHezao/poirot) into .agents/skills/requesting-code-review in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add HezaoHezao/poirot --skill requesting-code-review -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/requesting-code-review, .gemini/skills/requesting-code-review, .github/skills/requesting-code-review and .opencode/skills/requesting-code-review in your project.
Going by SKILL.md and its folder, Requesting Code Review needs the command-line tools its instructions call (git, npx, python, npm, cargo and go). Our summary lists: Python 3; Node.js. Its frontmatter pre-approves these tools: bash, read_file, str_replace.
SKILL.md contains no URLs. Its commands use git, npx and npm, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Requesting Code Review is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.
About 1.6k tokens (SKILL.md is roughly 6.4k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Requesting Code Review: PR Deep Verification (QwenLM/qwen-code, 28k stars), Find Regression Risk (dotnet/maui, 23k stars), Review Code (tobihagemann/turbo, 406 stars) and Code Review Checklist (shareAI-lab/learn-claude-code, 78k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
HezaoHezao (a GitHub user) maintains it in HezaoHezao/poirot, which has 250 GitHub stars. The repository holds 23 skills in this directory. The repository was last updated on July 28, 2026.
Source: HezaoHezao/poirot on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.