Agent skill

Choruz Code Review

by inclusionAI in inclusionAI/Choruz

A skill your agent uses when reviewing a pull request in this repository; orients the reviewer to Choruz's standards (AGENTS.md conventions, the PR test policy, Agent Notes, the CI gates) and the…

Apache-2.0Auto-check passedDevelopment

Install Choruz Code Review

skills CLI
$ npx skills add inclusionAI/Choruz --skill choruz-code-review -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install inclusionAI/Choruz choruz-code-review --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/inclusionAI/Choruz.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/choruz-code-review .claude/skills/choruz-code-review && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
choruz-code-review
GitHub stars
1k
Token cost
~1.7k tokens
SKILL.md length
836 words
Files
1
Skills in repo
11
Repo updated
First seen
Licence
Apache-2.0

At a glance

A skill your agent uses when reviewing a pull request in this repository; orients the reviewer to Choruz's standards (AGENTS.md conventions, the PR test policy, Agent Notes, the CI gates) and the…

  • Works in 8 steps: The Agent Note exists. A non-trivial… → Tests match the declared type. A bugfix… → Workspace scoping. Every new query or… → …
  • Reviewing a pull request in this repository
  • SKILL.md covers Sources of truth, Blocking requirements, Manual checks and Reporting findings
  • Calls bash

What it does

Choruz Code Review is an agent skill from inclusionAI/Choruz. Use when reviewing a pull request in this repository; orients the reviewer to Choruz's standards (AGENTS.md conventions, the PR test policy, Agent Notes, the CI gates) and the review-specific checks that a green CI cannot show.

Its SKILL.md is about 1.7k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Development, covering Code review, Agent instruction files and Pull requests. The licence is Apache-2.0.

When your agent uses it

  • Reviewing a pull request in this repository
  • Orients the reviewer to Choruzs standards (AGENTS.md conventions
  • The PR test policy
  • The CI gates) and the review-specific checks that a green CI cannot show

Example prompts

  • “/choruz-code-review”

Workflow steps

8 steps, taken from the first numbered list in SKILL.md.

  1. The Agent Note exists. A non-trivial change (behaviour, architecture, shared contract, process, format) links a note it adds or updates…
  2. Tests match the declared type. A bugfix has a regression test that fails without the fix; a feature has unit or integration coverage and…
  3. Workspace scoping. Every new query or command in crates/choruz-application filters by workspace_id; a new table carrying user data has the…
  4. Migrations are append-only. No edit to a file listed in scripts/historical-migrations.sha256; a new V0NN__name.sql with a matching…
  5. Contracts first. A wire, database or configuration change updates openapi/ or the migration in the same diff.
  6. Docs match the code. A moved file, renamed key, changed default or new command updates the document that names it (docs/, README, the web…
  7. Model-visible text is tested. A change to what agents receive (the [choruz-incoming] envelope, instruction templates in…
  8. Required evidence exists. The template's "Ran locally" names the commands the diff needed (see choruz-pre-push-checks); CI (linux)…

What it can do on your machine

Read from SKILL.md and the folder at commit 7509c40. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • bash

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Choruz Code Review loads about 1.7k tokens when it runs. Until then it costs about 62 tokens; SKILL.md has 836 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~62
When it runs · the whole SKILL.md, loaded when a task matches
~1.7k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from inclusionAI/Choruz at commit 7509c40, republished under its Apache-2.0 licence (© inclusionAI). 836 words, ~1,683 tokens.

Download SKILL.mdSave it as .claude/skills/choruz-code-review/SKILL.md (or your agent's skills folder).
name
choruz-code-review
description
Use when reviewing a pull request in this repository; orients the reviewer to Choruz's standards (AGENTS.md conventions, the PR test policy, Agent Notes, the CI gates) and the review-specific checks that a green CI cannot show.

Reviewing a Choruz PR

When loaded from a personal skills directory, resolve repository links from this skill's canonical .agents/skills/choruz-code-review/ location in the active Choruz checkout, not from the installed copy.

This skill is guidance, not a complete checklist. Fetch the PR's live base and exact head, run bash .agents/skills/choruz-pr/pr-plan.sh <base> on the head to see which surfaces the diff reaches, then read the diff and enough surrounding code to understand the design. Prioritise correctness, data isolation, lifecycle, security and broken required behaviour over style; a short review with one substantiated blocker is better than a list of nits.

Sources of truth

Blocking requirements

  1. The Agent Note exists. A non-trivial change (behaviour, architecture, shared contract, process, format) links a note it adds or updates, in the same PR; a proposed note being implemented is moved to implemented/ and rewritten in the present tense in the same diff. "none: mechanical" must be true.
  2. Tests match the declared type. A bugfix has a regression test that fails without the fix; a feature has unit or integration coverage and an e2e spec for a new user-facing flow; a database change has a new migration and a smoke run. Reject a type chosen to avoid tests.
  3. Workspace scoping. Every new query or command in crates/choruz-application filters by workspace_id; a new table carrying user data has the column and the index.
  4. Migrations are append-only. No edit to a file listed in scripts/historical-migrations.sha256; a new V0NN__name.sql with a matching docs/data-model.md update.
  5. Contracts first. A wire, database or configuration change updates openapi/ or the migration in the same diff.
  6. Docs match the code. A moved file, renamed key, changed default or new command updates the document that names it (docs/, README, the web docs pages under apps/web/app/docs) in the same diff. Comments state non-obvious contracts; flag narration, review history and duplicated rationale.
  7. Model-visible text is tested. A change to what agents receive (the [choruz-incoming] envelope, instruction templates in services/choruz-pipeline/src/instructions.rs and crates/choruz-host-runtime/assets/agent-templates, bootstrap fixtures) updates the instruction tests and fixtures, and states the agent-behaviour risk.
  8. Required evidence exists. The template's "Ran locally" names the commands the diff needed (see choruz-pre-push-checks); CI (linux) required is green on the exact head.
Show full SKILL.md (398 more words)Show less

Manual checks

  • Intent and interface contracts: trace both sides of every changed interface (gateway handler and web client, pipeline stage and store, connector and bridge). Confirm errors, cancellation, idempotency and ownership match the PR and any note.
  • Message path: for anything on the send, outbox, sync-feed or fanout path, check idempotency keys, server_seq ordering, optimistic-message reconciliation in the web client, and that every visible message is reconstructable from the store.
  • Lifecycle and concurrency: for spawned agents, terminals, the outbox watcher, cron and the supervisor, check races before publication, cancellation during awaits, independent error reporting, callback containment, and disposal to quiescence.
  • Enforcement: follow every permission denial and workspace check to the operation that executes it; exercise direct and alternate callers (API, connector, CLI, bridge) that could bypass the UI.
  • Scope and necessity: map each abstraction, option, compatibility path and defensive copy to a current consumer. Challenge speculative generality and unrelated features.
  • Real entry path: e2e tests exercise the shipped web app against the real API and pipeline through infra/host/web_e2e.sh, not a mocked route where the behaviour under test lives server-side.
  • Test strength: apply the policy's behaviour acceptance evidence to the actual assertions and fixtures. Ask whether the test remains green with the claimed behaviour removed; inspect the negative-control outcome for a bugfix or guard. Verify the real entry and result owner, affected device/account differences and ordinary state transitions. Flag missing evidence even when CI is green, without treating every theoretical scenario as required. Apply choruz-ci-test-reliability to owned-resource risks.
  • Selector rules: a new e2e spec for a new feature area gets a rule in .github/scripts/select_e2e_specs.py, or CI will never select it.
  • Seams touched match the diff: for a feature, api / database or security / auth PR, read the template's "Seams touched" section against docs/adding-a-feature.md. A new route without a require_* helper, a new table without workspace_id, a new spec without a selector rule, or a ticked seam the diff does not contain is a finding.
  • Implemented notes match shipped reality: paths, names and mechanisms in the note agree with the implementation.

Reporting findings

State the defect, location, impact and evidence. Place a localised defect inline on the tightest relevant diff range; use a PR-level comment for cross-cutting architecture, scope, or review-wide synthesis. Separate blockers from suggestions and omit issues a green gate already enforces. When receiving review, verify each claim and fix or rebut it on technical grounds without performative agreement.

© inclusionAI, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .agents/skills/choruz-code-review of inclusionAI/Choruz.

Open the folder on GitHubat commit 7509c40

Compare with similar skills

Choruz Code Review next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Choruz Code Review compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Choruz Code Review this skillinclusionAI/Choruz1k—~1.7kAutomated safety check: PassApache-2.0
Code Reviewimbenrabi/Financial-Modeling-Prep-MCP-Server150—~2.6kAutomated safety check: PassApache-2.0
Code Reviewsortie-ai/sortie197—~2.9kAutomated safety check: PassMIT
Shipmillionco/react-doctor15k—~716Automated safety check: PassCustom licence
Dsh Code ReviewZhou-Yujing114514/deepseek-harness-linux119—~2.1kAutomated safety check: PassMIT
Dotnet Copfmflurry/settings-opencode171—~2kAutomated safety check: PassMIT

Similar skills

  • Code Review

    imbenrabi/Financial-Modeling-Prep-MCP-Server

    Review a PR or working diff against this repo's intent layer (the AGENTS.md hierarchy), toolception pitfalls, and core invariants.

    150 GitHub stars~2.6k tokensUpdated 3 mo ago
    DevelopmentAuto-check passed
  • Code Review

    sortie-ai/sortie

    Reviews pull requests in this repository for the defect classes a mechanical checklist misses: documentation that outlived the code it describes, reaction and retry state that leaks or clobbers a…

    197 GitHub stars~2.9k tokensUpdated yesterday
    DevelopmentAuto-check passed
  • Ship

    millionco/react-doctor

    Take the current branch from done-coding to merge-ready in one pass — review the diff against AGENTS.md, deslop, commit and push, open a PR using rule-validate's PR copy, then babysit until mergeable.

    15k GitHub stars~716 tokensUpdated today
    DevelopmentAuto-check passed
  • Dsh Code Review

    Zhou-Yujing114514/deepseek-harness-linux

    A skill your agent uses when reviewing a pull request in the deepseek-harness repo — orients the reviewer to this codebase's standards (AGENTS.md conventions, defensive patterns, ADRs, quality…

    119 GitHub stars~2.1k tokensUpdated 3 days ago
    DevelopmentAuto-check passed
  • Dotnet Cop

    fmflurry/settings-opencode

    Pre-merge code review for .NET 10 pull requests. An agent skill from fmflurry/settings-opencode.

    171 GitHub stars~2k tokensUpdated 2 days ago
    DevelopmentAuto-check passed
  • Alego Code Review

    singula-ai/alego

    A skill your agent uses when reviewing a pull request in the alego repo — orients the reviewer to this codebase's standards (AGENTS.md conventions, defensive patterns, ADRs, quality gates) and the…

    109 GitHub stars~2.4k tokensUpdated 11 days ago
    DevelopmentAuto-check passed

More from inclusionAI/Choruz

All 11 skills in this repo
  • Choruz Archive Agent Notes

    inclusionAI/Choruz

    A skill your agent uses when adding, auditing, pruning, archiving, restoring, or reviewing Agent Notes in this repository; checks every new note for superseded active records, classifies implemented…

    1k GitHub stars~1.2k tokensUpdated 2 days ago
    Auto-check passed
  • Choruz Merging Stacked PRs

    inclusionAI/Choruz

    A skill your agent uses when landing a chain of dependent pull requests (A ← B ← C, each based on the one below) onto main, merging a PR whose base is another open PR's branch, or whenever a request…

    1k GitHub stars~866 tokensUpdated 2 days ago
    Auto-check passed
  • Choruz CI Test Reliability

    inclusionAI/Choruz

    Design, review, and diagnose Choruz tests and fixtures that can fail nondeterministically under CI concurrency: parallel Playwright workers sharing one PostgreSQL and one API, vitest workers, cargo…

    1k GitHub stars~1.8k tokensUpdated 2 days ago
    Auto-check passed
  • Choruz Doc

    inclusionAI/Choruz

    Create, restructure, review, audit, or migrate Choruz Markdown documentation (docs/, README, AGENTS.md, the in-app docs pages) using one owner per fact, tier placement, executed-operation…

    1k GitHub stars~1.6k tokensUpdated 2 days ago
    Auto-check passed
  • Choruz Find Simplifications

    inclusionAI/Choruz

    A skill your agent uses when working in this repository to find non-obvious simplification candidates, remove redundant comments or implementation-heavy documentation, write proposed Agent Notes or…

    1k GitHub stars~1.6k tokensUpdated 2 days ago
    Auto-check passed
  • Choruz PR

    inclusionAI/Choruz

    Use before opening or completing a pull request in this repository — classify the change, add the tests its type requires, run exactly what CI will run, label it, merge only on a green "CI (linux)…

    1k GitHub stars~2.6k tokensUpdated 2 days ago
    Auto-check passed

Categories

Questions about Choruz Code Review

What does Choruz Code Review do?

A skill your agent uses when reviewing a pull request in this repository; orients the reviewer to Choruz's standards (AGENTS.md conventions, the PR test policy, Agent Notes, the CI gates) and the…. Choruz Code Review is an agent skill from inclusionAI/Choruz.md conventions, the PR test policy, Agent Notes, the CI gates) and the review-specific checks that a green CI cannot show.

When should I use Choruz Code Review?

Choruz Code Review fits situations like: reviewing a pull request in this repository; orients the reviewer to Choruzs standards (AGENTS.md conventions; the PR test policy; the CI gates) and the review-specific checks that a green CI cannot show.

How do I install Choruz Code Review in Claude Code?

Run `npx skills add inclusionAI/Choruz --skill choruz-code-review -a claude-code`. Or copy the skill folder (.agents/skills/choruz-code-review in inclusionAI/Choruz) into .claude/skills/choruz-code-review in your project. Claude Code loads it when a task matches its description.

How do I install Choruz Code Review in Codex?

Run `npx skills add inclusionAI/Choruz --skill choruz-code-review -a codex`. Or copy the skill folder (.agents/skills/choruz-code-review in inclusionAI/Choruz) into .agents/skills/choruz-code-review in your project. Codex loads it when a task matches its description.

Can I use Choruz Code Review in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add inclusionAI/Choruz --skill choruz-code-review -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/choruz-code-review, .gemini/skills/choruz-code-review, .github/skills/choruz-code-review and .opencode/skills/choruz-code-review in your project.

What does Choruz Code Review need to run?

Going by SKILL.md and its folder, Choruz Code Review needs the command-line tools its instructions call (bash).

Does Choruz Code Review access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Choruz Code Review safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Choruz Code Review use?

Choruz Code Review is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Choruz Code Review use?

About 1.7k tokens (SKILL.md is roughly 6.7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Choruz Code Review?

Skills that share tags, products or a category with Choruz Code Review: Code Review (imbenrabi/Financial-Modeling-Prep-MCP-Server, 150 stars), Code Review (sortie-ai/sortie, 197 stars), Ship (millionco/react-doctor, 15k stars) and Dsh Code Review (Zhou-Yujing114514/deepseek-harness-linux, 119 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Choruz Code Review?

inclusionAI (a GitHub organization) maintains it in inclusionAI/Choruz, which has 1,002 GitHub stars. The repository holds 11 skills in this directory. The repository was last updated on October 7, 2026.

Source: inclusionAI/Choruz on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.