Agent skill

Review Self

by hyodotdev in hyodotdev/openiap

Independently review and simplify the agent's current implementation, working-tree changes, or pull request; enforce KISS and repository SSOT rules, fix actionable in-scope gaps, rerun relevant…

MITAuto-check passedDevelopment

Install Review Self

skills CLI
$ npx skills add hyodotdev/openiap --skill review-self -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install hyodotdev/openiap review-self --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/hyodotdev/openiap.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.codex/skills/review-self .claude/skills/review-self && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
review-self
GitHub stars
154
Token cost
~2.8k tokens
SKILL.md length
1,510 words
Files
2
Skills in repo
19
Repo updated
First seen
Licence
MIT

At a glance

Independently review and simplify the agent's current implementation, working-tree changes, or pull request; enforce KISS and repository SSOT rules, fix actionable in-scope gaps, rerun relevant…

  • Works in 5 steps: Reconstruct the requested outcome and… → Use an explicitly supplied PR, branch,… → For a PR, derive the actual base and… → …
  • The user says review-self
  • SKILL.md covers Preserve Authority And Scope, Establish The Review Target, Run One Review Round and Use Related OpenIAP Workflows, plus 4 more sections
  • Calls git

What it does

Review Self is an agent skill from hyodotdev/openiap. Independently review and simplify the agent's current implementation, working-tree changes, or pull request; enforce KISS and repository SSOT rules, fix actionable in-scope gaps, rerun relevant verification, and recheck at the user-requested interval (five minutes by default) until stable or genuinely blocked. Use when the user says "review-self", asks the agent to review the current changes, requests a self-review loop, or wants current work monitored for new issues after implementation.

Its SKILL.md is about 2.8k tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files (for example `agents/openai.yaml`).

It sits in Development, covering Pull requests. The repository describes itself as: Standardized protocol for in-app purchases across all platforms — backed by Meta & Amazon. The licence is MIT.

When your agent uses it

  • The user says review-self
  • Asks the agent to review the current changes
  • Requests a self-review loop
  • Wants current work monitored for new issues after implementation

Example prompts

  • “review-self”
  • “/review-self”

Workflow steps

5 steps, taken from the first numbered list in SKILL.md.

  1. Reconstruct the requested outcome and its acceptance criteria from the active
  2. Use an explicitly supplied PR, branch, commit range, or path as the target.
  3. For a PR, derive the actual base and head from PR metadata. Without a PR, use
  4. Read the repository's AGENTS.md and every convention or knowledge file that
  5. Stop immediately with a concise report when there is no reviewable diff and no

What it can do on your machine

Read from SKILL.md and the folder at commit 75aa01c. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • git

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use git, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Review Self loads about 2.8k tokens when it runs. Until then it costs about 126 tokens; SKILL.md has 1,510 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~126
When it runs · the whole SKILL.md, loaded when a task matches
~2.8k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from hyodotdev/openiap at commit 75aa01c, republished under its MIT licence (© hyodotdev). 1,510 words, ~2,786 tokens.

Download SKILL.mdSave it as .claude/skills/review-self/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
review-self
description
Independently review and simplify the agent's current implementation, working-tree changes, or pull request; enforce KISS and repository SSOT rules, fix actionable in-scope gaps, rerun relevant verification, and recheck at the user-requested interval (five minutes by default) until stable or genuinely blocked. Use when the user says "review-self", asks the agent to review the current changes, requests a self-review loop, or wants current work monitored for new issues after implementation.

Review Self

Review the current work immediately, fix validated gaps, and use confirmation rounds at the user's requested interval, or five minutes by default, until the result is stable.

Preserve Authority And Scope

  • Treat invocation as authorization to inspect the current work, make local in-scope fixes, and run relevant verification.
  • Preserve the authority of the original request. Do not commit, push, create or edit a PR, post comments, merge, deploy, release, or change live external state unless the user already authorized that action.
  • Keep fixes tied to the original goal. Do not turn self-review into a broad audit, speculative refactor, dependency upgrade, or unrelated cleanup.
  • Preserve pre-existing user changes. Record the initial working-tree state and never sweep-stage or discard files that are outside the current fix batch.
  • Stop and ask for direction when a valid fix requires a material product choice, new authority, an irreversible action, or a meaningful expansion of scope.

Establish The Review Target

  1. Reconstruct the requested outcome and its acceptance criteria from the active conversation and repository evidence.
  2. Use an explicitly supplied PR, branch, commit range, or path as the target. Otherwise, review the current branch plus its staged, unstaged, and untracked changes.
  3. For a PR, derive the actual base and head from PR metadata. Without a PR, use the configured upstream and merge base; do not assume a base branch when it is ambiguous.
  4. Read the repository's AGENTS.md and every convention or knowledge file that applies to the changed paths before editing them.
  5. Stop immediately with a concise report when there is no reviewable diff and no asynchronous PR state to monitor.

Run One Review Round

  1. Resnapshot the target from disk. Include the full base-to-head diff, staged and unstaged overlays, and the contents of untracked files. Do not review only the latest commit or trust a snapshot from a previous round.
  2. Read surrounding implementation, tests, documentation, issue/PR requirements, and current CI or review feedback needed to understand the change.
  3. Review for evidence-backed, actionable gaps:
    • requirement completeness and end-to-end wiring;
    • correctness, error paths, edge cases, state transitions, concurrency, idempotency, data safety, and security;
    • public contracts, naming, compatibility, generated-file rules, and cross-package or SDK parity;
    • missing or weak tests, documentation, examples, migrations, and operational safeguards required by the change, including, for a published package, the guides it affects and its release card for the next version, checked with knowledge/internal/05-docs-patterns.md#release-note-completeness-gate;
    • the canonical KISS/SSOT release rules in knowledge/internal/03-coding-style.md;
    • code smells in the diff, the code it touches, and any code read during the round, including any as any, per "Clean Up Once It Works" in the same file. These are in scope and fixed without being asked.
  4. Use independent read-only subagents for separate review lenses when the diff is large or cross-cutting. Give them the raw target and request, not suspected findings or an expected answer.
  5. Validate every finding against the current code and applicable instructions. Reject pure taste, cosmetic churn, duplicate findings, and unrelated feature work. A code smell is not taste: fix it even outside the change's scope.
  6. Fix all validated in-scope findings in one coherent batch under those canonical KISS/SSOT rules. Regenerate generated files only through their documented generator and preserve unrelated edits.
  7. Re-read the resulting diff, then run the path-specific lint, typecheck, tests, builds, audits, and git diff --check required by the repository. Do not rerun an expensive unchanged check fingerprint unless new state can affect it.
  8. If the target has a PR, inspect new failed checks and unresolved feedback as additional evidence. Reuse the repository's review-pr rules for a single thread-handling pass when GitHub writes are authorized. Do not invoke or schedule its polling section; keep review-self as the only polling-loop owner and never retrigger review bots on a no-op poll.
  9. Commit or push only when already authorized. Stage only files owned by the current round, follow repository commit ordering, and publish one verified fix batch rather than one commit per finding.

Load only the workflow needed by the current finding; do not run every command by default. Use $openiap-workflows as the router for .claude/commands/:

  • Read review-pr.md for one pass of external review-thread handling. Skip its polling section so review-self remains the only loop owner.
  • Read verify-all.md for an explicitly requested full health check or a risky cross-package change; otherwise run the touched-path checks.
  • Read audit-code.md only for an explicitly requested broad knowledge/API audit.
  • Read compile-knowledge.md after changing knowledge sources or compiled agent context.
  • Read e2e-tests.md when purchase behavior, native wiring, examples, or device-backed flows change.
  • Read resolve-issue.md when the target is a GitHub issue, while preserving its external-write authorization gates.
  • Read commit.md for an authorized commit, push, or PR, and release.md only for an explicitly authorized release on the correct branch.

Use the more specific local skill when its domain matches: $generate-doc for OpenIAP docs and release notes, $iapkit-e2e-petgu for Petgu product-sync E2E, $iapkit-e2e-martie for Martie local-receipt E2E, and $opencollective-steward for OpenCollective work.

Act As A Review-PR Fallback

When review-pr invokes this skill because an external reviewer cannot review the current PR head:

  • Run exactly one complete review round against the supplied base, head SHA, requirements, and acceptance criteria. Preserve the commit/push and external write authority supplied by the calling workflow.
  • Do not re-enter review-pr, request external reviewers, handle its trigger comments, invoke this fallback again, or schedule this skill's recurring loop. review-pr remains the sole thread-handling and polling owner.
  • Return the reviewed head and working-tree fingerprints, validated findings and fixes, checks run, and a clean or blocked result. The caller may cache a clean result only for that exact head and invalidate it after any head change.

This single-round override prevents nested polling loops while still replacing the missing external review coverage with the full self-review procedure.

Show full SKILL.md (548 more words)Show less

Recheck At The Requested Interval

  • Run the first round immediately; never wait before the initial review.
  • If the user explicitly requests one pass, finish after that round and do not schedule a confirmation.
  • Use the product's real recurring-monitor or wake-up mechanism to schedule the next round after the user's explicit interval, or 300 seconds by default. Make the scheduled prompt explicitly invoke $review-self; re-enter this skill rather than trying to perform semantic review inside a shell loop.
  • Keep at most one outstanding wake-up for the same target. Cancel or supersede stale duplicate wake-ups when the mechanism supports it.
  • Carry a compact state capsule in the scheduled prompt or monitor state. Include the original goal and acceptance criteria, target and base, head/tree and working-tree fingerprints, seen feedback and check IDs, poll count, clean count, start time, the requested interval, the active interval, the current pending-state fingerprint and first-seen time, finding fingerprints with fix attempts, and the existing commit/push authority.
  • Keep loop state out of tracked repository files. Revalidate it against disk and remote state on every wake-up.
  • Validate the requested and active intervals on every wake-up. Preserve an explicit user interval unless the user changes it; otherwise use the default.
  • Increment the clean count only after a complete round has no actionable findings, all requested verification passes, required checks are terminal and successful or explicitly allowed to skip, no actionable feedback remains, and the final diff has been reread. Reset it when any material state or finding changes, then allow the fully clean post-change result to start a new count.
  • Finish successfully after two consecutive clean snapshots separated by the active interval. Continue without a fixed round cap while new findings or state changes lead to meaningful progress.
  • Treat pending CI or review automation as neither clean nor failed. Poll it at the active interval without repeating expensive local checks on an unchanged fingerprint. Reset its first-seen time whenever the pending-state fingerprint changes.
  • If no recurring mechanism is available, complete the current round and report that automatic re-entry could not be scheduled. Do not emulate it with sleep, while true, nohup, or an abandoned background process, and never claim a future pass was scheduled unless the mechanism actually accepted it.

Stop Safely

Stop the loop and report the exact state when any of these conditions holds:

  • two clean confirmation snapshots establish stability;
  • the user stops, replaces, or materially redirects the task;
  • the target PR is merged or closed, the target branch disappears, or the target changes incompatibly with the active worktree;
  • a finding needs authority or a decision that is not already available;
  • the same root finding remains after two fix attempts;
  • the same authentication, rate-limit, tool, or environment failure blocks three consecutive rounds;
  • only unchanged pending external state remains for at least one hour.

Do not call a blocked or interrupted result clean. Do not stop merely because one poll is a no-op while asynchronous state is still pending.

Communicate Each Round

  • At startup, state the target, base, review scope, and whether commit/push or external writes are authorized.
  • Report material findings, fixes, validation failures, pushes, and external-state transitions promptly. Keep no-op updates brief.
  • On success or stop, provide a self-contained summary of findings fixed, files changed, checks run, commits or pushes made, clean-count evidence, and any unresolved blocker.

© hyodotdev, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file in .codex/skills/review-self of hyodotdev/openiap.

  • SKILL.md
  • agents/openai.yaml

Open the folder on GitHubat commit 75aa01c

Compare with similar skills

Review Self next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Review Self compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Review Self this skillhyodotdev/openiap154—~2.8kAutomated safety check: PassMIT
Finishing a Development Branchobra/superpowers296k5 repos~1.9kAutomated safety check: PassMIT
PR Babysitteropeninterpreter/openinterpreter69k3 repos~4.2kAutomated safety check: PassApache-2.0
Check PRonyx-dot-app/onyx32k2 repos~2.3kAutomated safety check: PassMIT
Understand Diff AnalysisEgonex-AI/Understand-Anything86k1 repos~1.4kAutomated safety check: PassMIT
PR Design DocOpenHands/OpenHands90k—~2.4kAutomated safety check: PassMIT

Similar skills

  • Walks the last step of a branch: confirm tests pass, detect the git environment, ask how to integrate, carry out your choice and clean up the worktree.

    296k GitHub starsUsed in 5 repos~1.9k tokens
    DevelopmentAuto-check passed
  • PR Babysitter

    openinterpreter/openinterpreter

    Watches an open GitHub pull request until it merges, handling review comments, diagnosing CI failures and retrying flaky checks along the way.

    69k GitHub starsUsed in 3 repos~4.2k tokens
    DevelopmentAuto-check passed
  • Check PR

    onyx-dot-app/onyx

    Checks a GitHub, GitLab, or Perforce (p4) pull request (or merge request, or shelved changelist) for unresolved review comments, failing status checks, and incomplete PR descriptions.

    32k GitHub starsUsed in 2 repos~2.3k tokens
    DevelopmentAuto-check passed
  • Understand Diff Analysis

    Egonex-AI/Understand-Anything

    Reads your git changes or a pull request against a prebuilt knowledge graph of the project to explain what changed, which components are affected and what is risky.

    86k GitHub starsUsed in 1 repo~1.4k tokens
    DevelopmentAuto-check passed
  • PR Design Doc

    OpenHands/OpenHands

    For a non-trivial pull request, write a self-contained HTML design doc under the temporary .pr/ directory and link a visibility-appropriate preview in the PR description, so maintainers grasp the…

    90k GitHub stars~2.4k tokensUpdated today
    DevelopmentAuto-check passed
  • WooCommerce Code Review

    woocommerce/woocommerce

    Reviews WooCommerce code changes against the project's standards, flagging backend PHP architecture, naming, documentation, data integrity and testing violations.

    11k GitHub starsUsed in 3 repos~1.1k tokens
    DevelopmentAuto-check passed

More from hyodotdev/openiap

All 19 skills in this repo
  • E2E Matrix Runner

    hyodotdev/openiap

    Run the full OpenIAP device matrix — six frameworks across iOS, Google Play, Amazon Appstore, Meta Horizon, and VegaOS — driving real hardware over adb and xcrun, and report one row per cell with…

    154 GitHub stars~3.4k tokensUpdated yesterday
    Auto-check: notes
  • Generate Doc

    hyodotdev/openiap

    A skill your agent uses for OpenIAP documentation generation work, especially the release-note card each PR carries in packages/docs/src/pages/docs/updates/releases.tsx, written as already published…

    154 GitHub stars~2.7k tokensUpdated yesterday
    Auto-check passed
  • Opencollective Steward

    hyodotdev/openiap

    Manage OpenIAP's OpenCollective presence, including profile copy, slug/link migrations, sponsor/backer recognition, update posts, and README/docs sponsor assets.

    154 GitHub stars~1.5k tokensUpdated yesterday
    Auto-check passed
  • Iapkit E2E Martie

    hyodotdev/openiap

    Run IAPKit local receipt-validation E2E with the dev.hyo.martie React Native or Expo examples, the compiled packages/kit server, real Convex, and Apple or Google sandbox purchases.

    154 GitHub stars~5.4k tokensUpdated yesterday
    Auto-check: notes
  • E2E Matrix Runner Apple

    hyodotdev/openiap

    Run the Apple half of the OpenIAP device matrix — six frameworks plus the native package on iOS — on a physical iPhone and report one row per cell with evidence.

    154 GitHub stars~501 tokensUpdated yesterday
    Auto-check passed
  • E2E Matrix Runner Google

    hyodotdev/openiap

    Run the Android half of the OpenIAP device matrix — six frameworks across Google Play, Amazon Appstore, and Meta Horizon, plus VegaOS — on real hardware and report one row per cell with evidence.

    154 GitHub stars~574 tokensUpdated yesterday
    Auto-check passed

Categories

Questions about Review Self

What does Review Self do?

Independently review and simplify the agent's current implementation, working-tree changes, or pull request; enforce KISS and repository SSOT rules, fix actionable in-scope gaps, rerun relevant…. Review Self is an agent skill from hyodotdev/openiap. Independently review and simplify the agent's current implementation, working-tree changes, or pull request; enforce KISS and repository SSOT rules, fix actionable in-scope gaps, rerun relevant verification, and recheck at the user-requested interval (five minutes by default) until stable or genuinely blocked.

When should I use Review Self?

Review Self fits situations like: the user says review-self; asks the agent to review the current changes; requests a self-review loop; wants current work monitored for new issues after implementation.

How do I install Review Self in Claude Code?

Run `npx skills add hyodotdev/openiap --skill review-self -a claude-code`. Or copy the skill folder (.codex/skills/review-self in hyodotdev/openiap) into .claude/skills/review-self in your project. Claude Code loads it when a task matches its description.

How do I install Review Self in Codex?

Run `npx skills add hyodotdev/openiap --skill review-self -a codex`. Or copy the skill folder (.codex/skills/review-self in hyodotdev/openiap) into .agents/skills/review-self in your project. Codex loads it when a task matches its description.

Can I use Review Self in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add hyodotdev/openiap --skill review-self -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/review-self, .gemini/skills/review-self, .github/skills/review-self and .opencode/skills/review-self in your project.

What does Review Self need to run?

Going by SKILL.md and its folder, Review Self needs the command-line tools its instructions call (git).

Does Review Self access the network?

SKILL.md contains no URLs. Its commands use git, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Review Self safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Review Self use?

Review Self is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Review Self use?

About 2.8k tokens (SKILL.md is roughly 11k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Review Self?

Skills that share tags, products or a category with Review Self: Finishing a Development Branch (obra/superpowers, 296k stars), PR Babysitter (openinterpreter/openinterpreter, 69k stars), Check PR (onyx-dot-app/onyx, 32k stars) and Understand Diff Analysis (Egonex-AI/Understand-Anything, 86k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Review Self?

hyodotdev (a GitHub organization) maintains it in hyodotdev/openiap, which has 154 GitHub stars. The repository holds 19 skills in this directory. The repository was last updated on October 7, 2026.

Source: hyodotdev/openiap on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.