Agent skill

Common Review Policy

by HoangNguyen0403 in HoangNguyen0403/agent-skills-standard

Define a repository review policy fixing what each review pass checks, how severities rank, which paths are skipped, the nit cap, and who approves.

MITAuto-check passedDevelopment

Install Common Review Policy

skills CLI
$ npx skills add HoangNguyen0403/agent-skills-standard --skill common-review-policy -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install HoangNguyen0403/agent-skills-standard common-review-policy --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/HoangNguyen0403/agent-skills-standard.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/common/common-review-policy .claude/skills/common-review-policy && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
common-review-policy
GitHub stars
572
Token cost
~1.1k tokens
SKILL.md length
526 words
Files
3 (incl. references)
Skills in repo
211
Repo updated
First seen
Licence
MIT

At a glance

Define a repository review policy fixing what each review pass checks, how severities rank, which paths are skipped, the nit cap, and who approves.

  • Works in 6 steps: The Policy File → Required Passes → Severity Ladder → …
  • Review findings feel inconsistent
  • SKILL.md covers Priority: P1 (HIGH), 1. The Policy File, 2. Required Passes and 3. Severity Ladder, plus 7 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Common Review Policy is an agent skill from HoangNguyen0403/agent-skills-standard. Define a repository review policy fixing what each review pass checks, how severities rank, which paths are skipped, the nit cap, and who approves. Use when review findings feel inconsistent or noisy, or when tuning an automated reviewer.

Its SKILL.md is about 1.1k tokens, which your agent loads only when the skill is triggered. The skill folder holds 4 other files, including reference files (for example `evals/evals.json` and `references/review-policy-template.md`).

It sits in Development, covering Code review. The repository describes itself as: A collection of Agent Skills Standard and Best Practice for Programming Languages, Frameworks that help our AI Agent follow best practies on frameworks and programming laguages. The licence is MIT.

When your agent uses it

  • Review findings feel inconsistent
  • Tuning an automated reviewer

Example prompts

  • “/common-review-policy”

Workflow steps

6 steps, taken from the step headings in SKILL.md.

  1. The Policy File
  2. Required Passes
  3. Severity Ladder
  4. Noise Control
  5. Tuning and Feedback
  6. Separation of Duties

What it can do on your machine

Read from SKILL.md and the folder at commit b529c2d. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Common Review Policy loads about 1.1k tokens when it runs, and up to ~1.4k if it reads all its reference files. Until then it costs about 65 tokens; SKILL.md has 526 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~65
When it runs · the whole SKILL.md, loaded when a task matches
~1.1k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~1.4k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from HoangNguyen0403/agent-skills-standard at commit b529c2d, republished under its MIT licence (© HoangNguyen0403). 526 words, ~1,071 tokens.

Download SKILL.mdSave it as .claude/skills/common-review-policy/SKILL.md (or your agent's skills folder). This skill also uses 2 other files; get the full folder from GitHub.
name
common-review-policy
description
Define a repository review policy fixing what each review pass checks, how severities rank, which paths are skipped, the nit cap, and who approves. Use when review findings feel inconsistent or noisy, or when tuning an automated reviewer.

Review Policy Standard

Priority: P1 (HIGH)

Every pull request gets the same passes in the same order. A review that varies by reviewer or by day is not a control.

1. The Policy File

  • Location: docs/review-policy.md, tracked in the repository and reviewed like code.
  • code-review and review-ticket load it when present; its severity and skip rules override their defaults.
  • Owned by the technical lead. Absent the file, the workflow defaults apply and the review says so.
  • Load references/review-policy-template.md when drafting or auditing the file.

2. Required Passes

Declare the passes and their order. Each pass names what it checks and what it explicitly ignores.

PassChecksOut of scope
Correctnesslogic, edge cases, requirement coveragestyle
Securityinjection, secrets, authorization, trust boundariestheoretical risk with no path
Testsnew logic covered, failure paths assertedcoverage percentage targets
Complianceaudit, data classification, licenceproduct decisions

3. Severity Ladder

  • Blocker: merge causes a defect, breach, or data loss. Concrete path required.
  • Major: real risk or requirement gap the author must resolve or explicitly accept.
  • Nit: everything else, including style, naming, and preference. Minor and Suggestion collapse into Nit.
  • Confidence: a finding without evidence is needs validation, never a silent drop and never a Blocker.
  • One ladder per repository. Workflows that use a longer list map onto these three before publishing.

4. Noise Control

  • Skip list: generated code, vendored dependencies, lockfiles, and snapshots. Name them as globs.
  • Nit cap: a fixed maximum per review. Over the cap, keep the highest-signal nits and drop the rest.
  • Lead with risk: Blocker and Major first, nits last, praise never.
  • Deduplicate by root cause: one finding per cause, listing the affected locations.

5. Tuning and Feedback

  • Review the policy monthly: rate a sample of findings as useful or noise, then adjust cap, skip list, and pass scope.
  • Recurring Blockers mean a missing standard. Route them to retro-learn so the preventing skill and its evals absorb the rule.
  • Record each tuning change in the policy file so severity drift is visible.
Show full SKILL.md (193 more words)Show less

6. Separation of Duties

  • The agent reviews and proposes; a human approves. The agent never approves its own change.
  • Approval is enforced by branch protection, not by the reviewing agent's verdict.
  • Publishing findings to a ticket or pull request needs operator approval, and never happens from untrusted review context.

Anti-Patterns

  • No per-reviewer severity: One ladder, defined in the policy file.
  • No unbounded nits: Cap them and keep the highest signal.
  • No reviewing generated code: Put it in the skip list.
  • No Blocker without a path: Downgrade to needs validation.
  • No agent self-approval: A human approves through branch protection.
  • No silent policy drift: Record every tuning change in the file.

Red Flags

  • Stop if the review opens with praise: Lead with Blocker and Major findings.
  • Stop if the same Blocker recurs across reviews: Route it to retro-learn instead of re-reporting it.
  • Stop if severity is chosen to force attention: Rank by consequence, not by urgency.

References

Canonical response anchors

When this skill applies, preserve the following domain terminology or equivalent concrete examples in the answer when relevant:

  • docs/review-policy.md
  • Blocker, Major, Nit
  • skip list
  • nit cap
  • needs validation
  • monthly tuning
  • branch protection

© HoangNguyen0403, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 2 other files (references) in skills/common/common-review-policy of HoangNguyen0403/agent-skills-standard.

  • SKILL.md
  • evals/evals.json
  • references/review-policy-template.md

Open the folder on GitHubat commit b529c2d

Compare with similar skills

Common Review Policy next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Common Review Policy compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Common Review Policy this skillHoangNguyen0403/agent-skills-standard572—~1.1kAutomated safety check: PassMIT
PR Babysitteropeninterpreter/openinterpreter69k3 repos~4.2kAutomated safety check: PassApache-2.0
Code Review ChecklistshareAI-lab/learn-claude-code78k4 repos~1.1kAutomated safety check: PassMIT
Backend Code Reviewlangflow-ai/langflow155k—~3.5kAutomated safety check: NotesMIT
Mole Bug Patternstw93/Mole70k—~2kAutomated safety check: PassGPL-3.0
Backend Code Reviewlanggenius/dify158k—~676Automated safety check: PassCustom licence

Similar skills

  • PR Babysitter

    openinterpreter/openinterpreter

    Watches an open GitHub pull request until it merges, handling review comments, diagnosing CI failures and retrying flaky checks along the way.

    69k GitHub starsUsed in 3 repos~4.2k tokens
    DevelopmentAuto-check passed
  • Code Review Checklist

    shareAI-lab/learn-claude-code

    Reviews code against a five-part checklist covering security, correctness, performance, maintainability and testing, and reports findings in a fixed format.

    78k GitHub starsUsed in 4 repos~1.1k tokens
    DevelopmentAuto-check passed
  • Backend Code Review

    langflow-ai/langflow

    Review backend code for quality, security, maintainability, and best practices based on established checklist rules.

    155k GitHub stars~3.5k tokensUpdated yesterday
    DevelopmentAuto-check: notes
  • A catalog of recurring bug shapes in the Mole Mac cleaner, used to review safety-sensitive diffs for deletion safety, unbounded commands, shell traps and weak tests.

    70k GitHub stars~2k tokensUpdated today
    DevelopmentAuto-check passed
  • Backend Code Review

    langgenius/dify

    Reviews backend code under api/ for concrete, reproducible defects, routes to rule packs for architecture, schema, repositories and SQLAlchemy, and ranks findings from P0 to P3.

    158k GitHub stars~676 tokensUpdated today
    DevelopmentAuto-check passed
  • WooCommerce Code Review

    woocommerce/woocommerce

    Reviews WooCommerce code changes against the project's standards, flagging backend PHP architecture, naming, documentation, data integrity and testing violations.

    11k GitHub starsUsed in 3 repos~1.1k tokens
    DevelopmentAuto-check passed

More from HoangNguyen0403/agent-skills-standard

All 211 skills in this repo
  • Subagent-Driven Development

    HoangNguyen0403/agent-skills-standard

    Runs a multi-task implementation plan by sending each task to a fresh implementer subagent, reviewing it independently, then reviewing the whole branch.

    572 GitHub stars~1.3k tokensUpdated yesterday
    Auto-check passed
  • draw.io Architecture Diagramming

    HoangNguyen0403/agent-skills-standard

    Draws architecture diagrams as editable draw.io files from a JSON spec, with a fixed house style, one C4 level per diagram and evidence-tagged shapes.

    572 GitHub stars~1.3k tokensUpdated yesterday
    Auto-check passed
  • Android Navigation 3 Guide

    HoangNguyen0403/agent-skills-standard

    Implements and migrates to Jetpack Navigation 3 in Compose: NavDisplay, typed route objects, a state-list back stack, deep links, multiple back stacks and dialog scenes.

    572 GitHub stars~687 tokensUpdated yesterday
    Auto-check passed
  • Angular HttpClient Standards

    HoangNguyen0403/agent-skills-standard

    Sets rules for Angular HTTP code: functional interceptors, typed requests, services that own every call, and httpResource for reactive data loading in Angular 17+.

    572 GitHub stars~652 tokensUpdated yesterday
    Auto-check passed
  • Angular Tooling

    HoangNguyen0403/agent-skills-standard

    Angular CLI usage, code generation, build configuration, and bundle optimization.

    572 GitHub stars~743 tokensUpdated yesterday
    Auto-check passed
  • Common Code Review

    HoangNguyen0403/agent-skills-standard

    Conduct high-quality, persona-driven code reviews. An agent skill from HoangNguyen0403/agent-skills-standard.

    572 GitHub stars~772 tokensUpdated yesterday
    Auto-check passed

Categories

Questions about Common Review Policy

What does Common Review Policy do?

Define a repository review policy fixing what each review pass checks, how severities rank, which paths are skipped, the nit cap, and who approves. Common Review Policy is an agent skill from HoangNguyen0403/agent-skills-standard. Define a repository review policy fixing what each review pass checks, how severities rank, which paths are skipped, the nit cap, and who approves.

When should I use Common Review Policy?

Common Review Policy fits situations like: review findings feel inconsistent; tuning an automated reviewer.

How do I install Common Review Policy in Claude Code?

Run `npx skills add HoangNguyen0403/agent-skills-standard --skill common-review-policy -a claude-code`. Or copy the skill folder (skills/common/common-review-policy in HoangNguyen0403/agent-skills-standard) into .claude/skills/common-review-policy in your project. Claude Code loads it when a task matches its description.

How do I install Common Review Policy in Codex?

Run `npx skills add HoangNguyen0403/agent-skills-standard --skill common-review-policy -a codex`. Or copy the skill folder (skills/common/common-review-policy in HoangNguyen0403/agent-skills-standard) into .agents/skills/common-review-policy in your project. Codex loads it when a task matches its description.

Can I use Common Review Policy in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add HoangNguyen0403/agent-skills-standard --skill common-review-policy -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/common-review-policy, .gemini/skills/common-review-policy, .github/skills/common-review-policy and .opencode/skills/common-review-policy in your project.

What does Common Review Policy need to run?

SKILL.md names no scripts, command-line tools or credentials: Common Review Policy is instructions for the agent only.

Does Common Review Policy access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Common Review Policy safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Common Review Policy use?

Common Review Policy is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Common Review Policy use?

About 1.1k tokens (SKILL.md is roughly 4.3k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 329 tokens, read only when the agent opens those files.

What are the alternatives to Common Review Policy?

Skills that share tags, products or a category with Common Review Policy: PR Babysitter (openinterpreter/openinterpreter, 69k stars), Code Review Checklist (shareAI-lab/learn-claude-code, 78k stars), Backend Code Review (langflow-ai/langflow, 155k stars) and Mole Bug Patterns (tw93/Mole, 70k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Common Review Policy?

HoangNguyen0403 (a GitHub user) maintains it in HoangNguyen0403/agent-skills-standard, which has 572 GitHub stars. The repository holds 211 skills in this directory. The repository was last updated on October 9, 2026.

Source: HoangNguyen0403/agent-skills-standard on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.