Agent skill

Code Review

by initializ in initializ/forge

AI-powered code review for diffs and individual files using LLM analysis

Apache-2.0Auto-check passedDevelopment

Install Code Review

skills CLI
$ npx skills add initializ/forge --skill code-review -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install initializ/forge code-review --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/initializ/forge.git skills-src && mkdir -p .claude/skills && cp -r skills-src/forge-skills/local/embedded/code-review .claude/skills/code-review && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
code-review
GitHub stars
223
Token cost
~3k tokens
SKILL.md length
1,291 words
Files
3 (incl. scripts)
Skills in repo
15
Repo updated
First seen
Licence
Apache-2.0

At a glance

AI-powered code review for diffs and individual files using LLM analysis

  • Works in 4 steps: If REVIEW_PROVIDER is set, it wins. → Else if REVIEW_MODEL starts with claude-… → Else if only one API key is set, use… → …
  • Tasks that involve Code review
  • SKILL.md covers Authentication, Environment Variables, Tool: code_review_diff and Tool: code_review_file, plus 1 more section
  • Runs Shell scripts from its folder; calls git; reaches github.com and api.openai.com; needs ANTHROPIC_API_KEY and OPENAI_API_KEY

What it does

Code Review is an agent skill from initializ/forge. AI-powered code review for diffs and individual files using LLM analysis

Its SKILL.md is about 3k tokens, which your agent loads only when the skill is triggered. The skill folder holds 3 other files, including scripts (for example `scripts/code-review-diff.sh` and `scripts/code-review-file.sh`).

It sits in Development, covering Code review. It works with OpenAI, GitHub and Anthropic API. The repository describes itself as: Forge is the open-source runtime for Anthropic's Agent Skills standard — built for the agent that runs next to a service, in your environment, on infrastructure you already… The licence is Apache-2.0.

When your agent uses it

  • Tasks that involve Code review

Example prompts

  • “/code-review”

Requirements

  • A Bash shell
  • A credential in ANTHROPIC_API_KEY
  • A credential in OPENAI_API_KEY

Workflow steps

4 steps, taken from the first numbered list in SKILL.md.

  1. If REVIEW_PROVIDER is set, it wins.
  2. Else if REVIEW_MODEL starts with claude- or anthropic/, use Anthropic.
  3. Else if only one API key is set, use that provider.
  4. Else (both keys, no model hint): use OpenAI.

What it can do on your machine

Read from SKILL.md and the folder at commit 3c608d8. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 2 files in scripts/ (Shell), which the agent can run.

    Shell commands in SKILL.md call:

    • git

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • github.com
    • api.openai.com
    • api.together.ai

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • ANTHROPIC_API_KEY
    • OPENAI_API_KEY
    • GH_TOKEN

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Code Review loads about 3k tokens when it runs. Until then it costs about 21 tokens; SKILL.md has 1,291 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~21
When it runs · the whole SKILL.md, loaded when a task matches
~3k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from initializ/forge at commit 3c608d8, republished under its Apache-2.0 licence (© initializ). 1,291 words, ~3,003 tokens.

Download SKILL.mdSave it as .claude/skills/code-review/SKILL.md (or your agent's skills folder). This skill also uses 2 other files; get the full folder from GitHub.
name
code-review
description
AI-powered code review for diffs and individual files using LLM analysis
icon
🔎
category
developer
tags
code-review, diff, pull-request, quality, security

Code Review Skill

AI-powered code review that analyzes diffs and individual files for bugs, security issues, style violations, and improvement opportunities. Supports both local git diffs and GitHub pull requests.

Authentication

Set at least one LLM API key:

bash
# Option A: Anthropic
export ANTHROPIC_API_KEY="sk-ant-..."

# Option B: OpenAI or any OpenAI-compatible provider (Together, OpenRouter, Groq, ...)
export OPENAI_API_KEY="sk-..."
export OPENAI_BASE_URL="https://api.together.ai/v1"   # only when not using openai.com

# Optional: override the model (defaults: claude-sonnet-4-20250514 / gpt-4o)
export REVIEW_MODEL="moonshotai/Kimi-K2.6"

# Optional: force a specific provider when both keys are set
export REVIEW_PROVIDER="openai"   # or "anthropic"

Provider selection (auto-detected when REVIEW_PROVIDER is unset):

  1. If REVIEW_PROVIDER is set, it wins.
  2. Else if REVIEW_MODEL starts with claude- or anthropic/, use Anthropic.
  3. Else if only one API key is set, use that provider.
  4. Else (both keys, no model hint): use OpenAI.

This precedence fixes the common deployment where both ANTHROPIC_API_KEY and OPENAI_API_KEY live in .forge/secrets.enc (one is stale or for a different skill). Pre-fix the skill always preferred Anthropic and returned 401 against the stale key.

For GitHub PR review, also set:

bash
export GH_TOKEN="ghp_..."

The token needs read-only access:

Scope (classic PAT)Fine-grained permissionWhy
repo (or public_repo for public repos)Contents: ReadFetch PR diff and file contents

This skill only reads diffs — it never posts comments, applies labels, or merges. For write operations, see the code-review-github skill.

Environment Variables

VariableRequiredDescription
ANTHROPIC_API_KEYone-ofAnthropic API key
OPENAI_API_KEYone-ofOpenAI or OpenAI-compatible (Together, OpenRouter, Groq, ...) API key
REVIEW_PROVIDERnoExplicit provider override: anthropic or openai. When unset, auto-detected from REVIEW_MODEL prefix, then by which key is set. Prefers openai when both keys exist and no model hint disambiguates
REVIEW_MODELnoOverride LLM model name. Default: claude-sonnet-4-20250514 (anthropic) / gpt-5.4 (openai)
REVIEW_MAX_DIFF_BYTESnoMax diff size before truncation (default: 100000)
GH_TOKENnoGitHub token for PR diffs — read-only access is sufficient
FORGE_REVIEW_STANDARDS_DIRnoPath to .forge-review/standards/ directory for custom rules
OPENAI_BASE_URLnoBase URL for OpenAI-compatible providers (default: https://api.openai.com/v1). Always uses /chat/completions — see OPENAI_USE_RESPONSES_API for the proprietary Responses API
OPENAI_USE_RESPONSES_APInoSet to 1 to use OpenAI's proprietary /responses endpoint (Codex/OAuth flow). Default off. Only relevant when OPENAI_BASE_URL points at api.openai.com

Tool: code_review_diff

Review a code diff for bugs, security issues, and improvements. Accepts either a GitHub PR URL or a local git base ref.

Default behavior: When the user says "review my local changes" or "review changes in <path>" WITHOUT specifying a base branch, default to base_ref: "HEAD". This reviews uncommitted and untracked files — the user's work-in-progress. Do NOT ask the user for a base ref in this case. Only use main/develop as base_ref when the user explicitly says "against main" or "against develop".

Input:

ParameterTypeRequiredDescription
pr_urlstringnoGitHub PR URL (e.g., https://github.com/owner/repo/pull/123)
base_refstringnoGit ref to compare from. Default: HEAD (uncommitted changes). Use main only if user says "against main"
repo_pathstringnoAbsolute path to the local git repository. Required when using base_ref
focusstringnoReview focus: bugs, security, style, all. Default: all
extra_contextstringnoAdditional context or instructions for the reviewer

One of pr_url or base_ref is required. When using base_ref, repo_path must point to the user's local repository (scripts run in the agent's directory, not the user's project).

Output: JSON object with structured review findings.

Examples

User says → tool input mapping:

User requestTool input
"Review code changes against main in ~/myproject"{"base_ref": "main", "repo_path": "~/myproject"}
"Review my changes since develop in /opt/app"{"base_ref": "develop", "repo_path": "/opt/app"}
"Review the last 3 commits in ~/myproject for security issues"{"base_ref": "HEAD~3", "repo_path": "~/myproject", "focus": "security"}
"Review changes on the feature/auth branch in ~/myproject"{"base_ref": "main", "repo_path": "~/myproject"}
"Review my local changes in ~/myproject"{"base_ref": "HEAD", "repo_path": "~/myproject"}
"Review my uncommitted changes in ~/myproject"{"base_ref": "HEAD", "repo_path": "~/myproject"}
"Review this PR https://github.com/org/repo/pull/42"{"pr_url": "https://github.com/org/repo/pull/42"}
"Security audit on PR 99 in org/repo"{"pr_url": "https://github.com/org/repo/pull/99", "focus": "security"}

Important:

  • Pass repo_path exactly as the user provides it. The script handles ~ expansion internally — do NOT try to resolve ~ yourself (you do not know the user's home directory). For example, if the user says ~/myproject, pass "repo_path": "~/myproject".
  • For local reviews, repo_path is required because the script runs in the agent's working directory, not the user's project directory.
  • base_ref is the starting point to compare FROM. It is NOT the branch being reviewed — it is the base that changes are measured against. The diff includes both committed and uncommitted (working tree) changes relative to base_ref.
  • base_ref can be a branch name (main, develop), a commit SHA, or a relative ref (HEAD~3). The script uses git merge-base to find the fork point, so only changes on the current branch are reviewed.
  • When a branch has many commits (e.g., merged PRs), use HEAD~N to narrow the review scope to the most recent N commits. For example, HEAD~5 reviews only the last 5 commits.
  • When the user says "review changes on branch X" or "review branch X", they mean: review the changes that branch X introduces. Use main (or the repo's default branch) as base_ref — NOT the branch name itself.
  • When the user says "review my uncommitted changes" or "review my local changes", use HEAD as base_ref to show only unstaged/staged changes.
Show full SKILL.md (486 more words)Show less
Pre-Flight Scope Check (IMPORTANT)

Before calling code_review_diff with a base_ref, the agent MUST run cli_execute to check the diff scope:

bash
cd <repo_path> && git log --oneline <base_ref>..HEAD | head -20

This shows how many commits will be reviewed. If there are more than ~5 commits:

  1. Tell the user: "There are N commits between <base_ref> and HEAD. This includes: [list first few commit subjects]."
  2. Ask: "Would you like me to review all N commits, or narrow the scope? For example, I can review just the last 3 commits with HEAD~3."
  3. Only call code_review_diff after the user confirms the scope.

This prevents reviewing unrelated changes from older commits or merged PRs on long-lived branches.

Detection Heuristics

The agent selects this tool when it detects:

  • Requests mentioning "review", "diff", "PR", "pull request", "changes"
  • A directory path or repository path in the user's message
  • GitHub PR URLs pasted in conversation
  • Requests to check code quality, find bugs, or audit changes
Response Format
json
{
  "summary": "Brief overall assessment",
  "risk_level": "low|medium|high|critical",
  "findings": [
    {
      "file": "path/to/file.go",
      "line": 42,
      "severity": "error|warning|info|nitpick",
      "category": "bug|security|style|performance|maintainability",
      "title": "Short finding title",
      "description": "Detailed explanation of the issue",
      "suggestion": "Suggested fix or improvement"
    }
  ],
  "stats": {
    "files_reviewed": 5,
    "total_findings": 3,
    "by_severity": {"error": 1, "warning": 1, "nitpick": 1}
  }
}
Tips
  • Use focus: security for security-focused audits
  • Use base_ref: main to review all uncommitted changes against main
  • Large diffs are automatically truncated at REVIEW_MAX_DIFF_BYTES (default 100KB)
  • Set FORGE_REVIEW_STANDARDS_DIR to apply org-specific coding standards

Tool: code_review_file

Deep review of a single file with full context (not just diff). Useful for thorough analysis of critical files.

Input:

ParameterTypeRequiredDescription
file_pathstringyesPath to the file to review (relative to repo root, or absolute path)
repo_pathstringnoAbsolute path to the local repository. Required for local file review (scripts run in the agent's directory, not the user's project)
pr_urlstringnoIf set, fetches the file from the PR head branch
focusstringnoReview focus: bugs, security, style, all. Default: all
extra_contextstringnoAdditional context or instructions for the reviewer

Output: Same JSON structure as code_review_diff.

Examples

User says → tool input mapping:

User requestTool input
"Review the file src/server.go in ~/myproject"{"file_path": "src/server.go", "repo_path": "~/myproject"}
"Security audit on cmd/main.go in /opt/app"{"file_path": "cmd/main.go", "repo_path": "/opt/app", "focus": "security"}
"Review auth.py from PR #42 in org/repo"{"file_path": "auth.py", "pr_url": "https://github.com/org/repo/pull/42"}

Important: For local file review, repo_path is required. file_path is relative to the repo root. Resolve ~ to the absolute home directory path.

Detection Heuristics

The agent selects this tool when it detects:

  • Requests to "review this file", "audit file", "check file for issues"
  • A specific file path mentioned with a repository/directory path
  • Single-file deep review requests (as opposed to diff-level review)
Tips
  • Use this for critical files that need thorough review beyond just changes
  • Combine with code_review_diff for comprehensive PR review: diff-level first, then deep-dive on flagged files
  • Works with any text file: source code, configs, scripts, IaC templates

Safety Constraints

  • Never executes code from the diff or reviewed files
  • API keys are passed via environment variables, never logged or included in output
  • Diff content is sent to the configured LLM API for analysis (respects egress_domains)
  • Large diffs are truncated, not streamed, to prevent excessive API costs
  • No filesystem modifications: read-only analysis only

© initializ, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 2 other files (scripts) in forge-skills/local/embedded/code-review of initializ/forge.

  • SKILL.md
  • scripts/code-review-diff.sh
  • scripts/code-review-file.sh

Open the folder on GitHubat commit 3c608d8

Compare with similar skills

Code Review next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Code Review compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Code Review this skillinitializ/forge223—~3kAutomated safety check: PassApache-2.0
Codex Reviewalinaqi/maggy707—~3kAutomated safety check: PassMIT
PR Babysitteropeninterpreter/openinterpreter69k3 repos~4.2kAutomated safety check: PassApache-2.0
Get API Docs with chubandrewyng/context-hub14k2 repos~775Automated safety check: PassMIT
Open Code Review CLIalibaba/open-code-review44k—~3.1kAutomated safety check: PassApache-2.0
GitHub Review Iterationprisma/orm48k—~2.2kAutomated safety check: PassApache-2.0

Similar skills

  • Codex Review

    alinaqi/maggy

    OpenAI Codex CLI code review with GPT-5.2-Codex, CI/CD integration

    707 GitHub stars~3k tokensUpdated 13 days ago
    DevOps & CloudAuto-check passed
  • PR Babysitter

    openinterpreter/openinterpreter

    Watches an open GitHub pull request until it merges, handling review comments, diagnosing CI failures and retrying flaky checks along the way.

    69k GitHub starsUsed in 3 repos~4.2k tokens
    DevelopmentAuto-check passed
  • Get API Docs with chub

    andrewyng/context-hub

    Fetches current documentation for third-party APIs and SDKs with the chub CLI before the agent writes code against them, instead of relying on remembered API shapes.

    14k GitHub starsUsed in 2 repos~775 tokens
    DevelopmentAuto-check passed
  • Open Code Review CLI

    alibaba/open-code-review

    Runs the ocr command-line tool to review Git changes, a commit or a branch comparison with an AI model, returning line-level comments and optionally applying fixes.

    44k GitHub stars~3.1k tokensUpdated 2 days ago
    DevelopmentAuto-check passed
  • Official

    Runs a loop on a GitHub pull request: fetch review state, triage comments into actions, implement them and resolve threads, repeating until nothing actionable is left.

    48k GitHub stars~2.2k tokensUpdated today
    DevelopmentAuto-check passed
  • PR Finalize Review

    microsoft/garnet

    Official

    Checks that a pull request's title and description match its implementation and reviews the code for Garnet best practices, reporting findings without posting them.

    12k GitHub stars~3.1k tokensUpdated today
    DevelopmentAuto-check passed

More from initializ/forge

All 15 skills in this repo
  • Code Plan

    initializ/forge

    Turn a task description and repository into a structured implementation plan (files to create, files to modify, tests to add, risks).

    223 GitHub stars~1.9k tokensUpdated 6 days ago
    Auto-check passed
  • Codegen HTML

    initializ/forge

    Scaffold and iterate on standalone Preact + HTM applications with zero build dependencies

    223 GitHub stars~1.5k tokensUpdated 6 days ago
    Auto-check passed
  • Code Agent

    initializ/forge

    General-purpose coding agent that reads, writes, and edits code, and searches codebases.

    223 GitHub stars~2.5k tokensUpdated 6 days ago
    Auto-check: warnings
  • Codegen React

    initializ/forge

    Scaffold and iterate on Vite + React applications. An agent skill from initializ/forge.

    223 GitHub stars~1.8k tokensUpdated 6 days ago
    Auto-check passed
  • K8s Cost Visibility

    initializ/forge

    Estimate Kubernetes infrastructure costs by querying cluster node, pod, PVC/PV, and LoadBalancer data, applying cloud pricing models, and producing cost attribution reports with storage and…

    223 GitHub stars~2.7k tokensUpdated 6 days ago
    Auto-check passed
  • K8s Pod Rightsizer

    initializ/forge

    Analyze Kubernetes workload metrics and produce policy-constrained CPU/memory rightsizing recommendations with optional patch generation and rollback-safe apply.

    223 GitHub stars~4.3k tokensUpdated 6 days ago
    Auto-check passed

Categories

Questions about Code Review

What does Code Review do?

AI-powered code review for diffs and individual files using LLM analysis. Code Review is an agent skill from initializ/forge.

When should I use Code Review?

Code Review fits situations like: tasks that involve Code review.

How do I install Code Review in Claude Code?

Run `npx skills add initializ/forge --skill code-review -a claude-code`. Or copy the skill folder (forge-skills/local/embedded/code-review in initializ/forge) into .claude/skills/code-review in your project. Claude Code loads it when a task matches its description.

How do I install Code Review in Codex?

Run `npx skills add initializ/forge --skill code-review -a codex`. Or copy the skill folder (forge-skills/local/embedded/code-review in initializ/forge) into .agents/skills/code-review in your project. Codex loads it when a task matches its description.

Can I use Code Review in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add initializ/forge --skill code-review -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/code-review, .gemini/skills/code-review, .github/skills/code-review and .opencode/skills/code-review in your project.

What does Code Review need to run?

Going by SKILL.md and its folder, Code Review needs a shell for the scripts in its folder, the command-line tools its instructions call (git) and credentials named ANTHROPIC_API_KEY, OPENAI_API_KEY and GH_TOKEN. Our summary lists: A Bash shell; A credential in ANTHROPIC_API_KEY; A credential in OPENAI_API_KEY.

Does Code Review access the network?

SKILL.md names 3 domains. In commands or code: github.com, api.openai.com and api.together.ai; the agent is likely to contact these when it follows the instructions. This is read from the text; nothing was executed.

Is Code Review safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Code Review use?

Code Review is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Code Review use?

About 3k tokens (SKILL.md is roughly 12k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Code Review?

Skills that share tags, products or a category with Code Review: Codex Review (alinaqi/maggy, 707 stars), PR Babysitter (openinterpreter/openinterpreter, 69k stars), Get API Docs with chub (andrewyng/context-hub, 14k stars) and Open Code Review CLI (alibaba/open-code-review, 44k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Code Review?

initializ (a GitHub organization) maintains it in initializ/forge, which has 223 GitHub stars. The repository holds 15 skills in this directory. The repository was last updated on October 1, 2026.

Source: initializ/forge on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.