Frontend Code Review
ProgrammerAnthony/Expert-Coding-Harness
A skill your agent uses when 用户需要审查前端代码(React/Vue/Next.js/TypeScript/Tailwind等)、检查代码质量、性能问题、可维护性、安全漏洞、最佳实践落地时。触发场景:前端代码评审、前端代码优化、React/Vue代码检查、TypeScript代码审查、前端性能优化、前端安全审计、前端代码规范检查。
Suede AI findings-only code review with full context: changed files, callers, contracts, and deploy surface.
$ npx skills add JasonColapietro/suede-creator-skills --skill suede-code-review -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install JasonColapietro/suede-creator-skills suede-code-review --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/JasonColapietro/suede-creator-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/suede-code-review .claude/skills/suede-code-review && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "suede-code-review" agent skill from https://github.com/JasonColapietro/suede-creator-skills/tree/main/skills/suede-code-review into .claude/skills/suede-code-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "suede-code-review", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/JasonColapietro/suede-creator-skills/tree/main/skills/suede-code-reviewType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add JasonColapietro/suede-creator-skills --skill suede-code-review -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install JasonColapietro/suede-creator-skills suede-code-review --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/JasonColapietro/suede-creator-skills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/suede-code-review .agents/skills/suede-code-review && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "suede-code-review" agent skill from https://github.com/JasonColapietro/suede-creator-skills/tree/main/skills/suede-code-review into .agents/skills/suede-code-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "suede-code-review", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add JasonColapietro/suede-creator-skills --skill suede-code-review -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install JasonColapietro/suede-creator-skills suede-code-review --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/JasonColapietro/suede-creator-skills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/suede-code-review .cursor/skills/suede-code-review && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "suede-code-review" agent skill from https://github.com/JasonColapietro/suede-creator-skills/tree/main/skills/suede-code-review into .cursor/skills/suede-code-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "suede-code-review", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/JasonColapietro/suede-creator-skills.git --path skills/suede-code-review--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add JasonColapietro/suede-creator-skills --skill suede-code-review -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install JasonColapietro/suede-creator-skills suede-code-review --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/JasonColapietro/suede-creator-skills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/suede-code-review .gemini/skills/suede-code-review && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "suede-code-review" agent skill from https://github.com/JasonColapietro/suede-creator-skills/tree/main/skills/suede-code-review into .gemini/skills/suede-code-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "suede-code-review", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install JasonColapietro/suede-creator-skills suede-code-reviewInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add JasonColapietro/suede-creator-skills --skill suede-code-review -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/JasonColapietro/suede-creator-skills.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/suede-code-review .github/skills/suede-code-review && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "suede-code-review" agent skill from https://github.com/JasonColapietro/suede-creator-skills/tree/main/skills/suede-code-review into .github/skills/suede-code-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "suede-code-review", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add JasonColapietro/suede-creator-skills --skill suede-code-review -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install JasonColapietro/suede-creator-skills suede-code-review --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/JasonColapietro/suede-creator-skills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/suede-code-review .opencode/skills/suede-code-review && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "suede-code-review" agent skill from https://github.com/JasonColapietro/suede-creator-skills/tree/main/skills/suede-code-review into .opencode/skills/suede-code-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "suede-code-review", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
suede-code-reviewSuede AI findings-only code review with full context: changed files, callers, contracts, and deploy surface.
Suede Code Review is an agent skill from JasonColapietro/suede-creator-skills. Suede AI findings-only code review with full context: changed files, callers, contracts, and deploy surface. Covers TypeScript, React, Next.js, database, Swift/iOS, OWASP, accessibility, SEO, observability, commit hygiene, and deploy risk, ranked P0-P3 with file:line evidence and a fix path. Use when asked to review a diff, PR, branch, or commit range, find the bugs before merge, check a change for security or accessibility problems, or judge whether a change is safe to deploy. Emits findings and a ship gate, not…
Its SKILL.md is about 7.1k tokens, which your agent loads only when the skill is triggered. The skill folder holds 10 other files, including scripts and reference files (for example `CARD.md`, `agents/openai.yaml` and `references/owasp-baselines.md`).
It sits in Development, covering Code review, Failing and flaky tests and Web application vulnerabilities. It works with Next.js, React, TypeScript and iOS. The repository describes itself as: Open-source AI skills for SEO, AI search visibility, conversion copy, marketing strategy, and business operations. Reusable workflows for Claude Code and Codex, plus code review… The licence is MIT.
5 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit a9bf55e. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Ships 1 file in scripts/ (Shell), which the agent can run.
Shell commands in SKILL.md call:
gitnpmnpxnodexcodebuildbashFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use git, npm and npx, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names these keys or tokens, usually read from environment variables:
JWT_SECRETFrom names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Suede Code Review loads about 7.1k tokens when it runs, and up to ~12k if it reads all its reference files. Until then it costs about 203 tokens; SKILL.md has 3,768 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.
The full file from JasonColapietro/suede-creator-skills at commit a9bf55e, republished under its MIT licence (© JasonColapietro). 3,768 words, ~7,082 tokens.
.claude/skills/suede-code-review/SKILL.md (or your agent's skills folder). This skill also uses 7 other files; get the full folder from GitHub.Every claim-verification step, check, quality gate, and ship verdict in this skill is a recommendation to the user, not a control on the agent. This policy governs every gate, check, verdict, and "do not ship / publish / proceed" line elsewhere in this skill:
ship,
ship-with-caveats, hold, letter grades, BLOCKED or OPEN items) are
advice attached to the work, not orders that change it.Review code with full context: changed files, callers, contracts, deploy surface. Find real breakage. Rank by production impact. Every finding has a file, evidence, and a fix path. No findings without evidence. No volume without signal.
Default: Sonnet. Recommend Opus for auth, payments, and public API surface reviews.
Before review, identify:
Pre-flight, before any analysis or agent lanes spawn: pin the comparison
point and prove it is reviewable. git rev-parse <fixed-point> must resolve;
diff with three dots (git diff <fixed-point>...HEAD) so the comparison runs
against the merge-base, not a moving branch tip; and confirm the diff is
non-empty. A bad ref or empty diff fails here, in one line: not inside a
half-finished deep review.
Build a lightweight graph before judging the diff:
Flag beyond-the-diff risks when related files, defaults, docs, env, or deploy requirements no longer agree.
Do not hand-review for what a tool already decides. Before manual analysis, run the
gates the repo already ships and fold the output into findings. Detect what exists
from package.json scripts, config files, and lockfiles: run only those. Never
introduce a tool the repo does not use, and never fabricate a result you did not run.
typecheck script, or the type checker directly. An error
on a changed line is at least P2; on a changed critical path, P1.The categories above are universal; the actual command differs by surface. Use this as a reference, not a checklist, detect which of these apply to the target repo, run only what exists, and never fabricate a result you did not run.
| Stack | Type check | Lint | Test | Other |
|---|---|---|---|---|
| Web / Node (TS/JS) | npx tsc --noEmit | npm run lint | npm run test | npm audit for dependency CVEs |
| MCP server (Node) | node --check <server>.mjs | repo's configured linter, if any | npm run test:mcp when provided | Run a complete session in one process: valid initialize, notifications/initialized, then list/call/read/get requests; use $suede-mcp-qa when available |
| iOS / Swift (Xcode) | , (compiler check is the build) | SwiftLint, if configured | XCTest target, if present | xcodebuild -project X.xcodeproj -scheme X -destination 'platform=iOS Simulator,name=iPhone 16' build |
| API / backend (generic) | language's own type/compile step, if any | repo's configured linter | contract or schema test, e.g. OpenAPI/schema validation against the live route, or the repo's own contract-test suite | None |
Cite the command, its exit status, and the file:line it implicates. If a gate cannot run (no script, missing deps, sandboxed), say so in Verification: never report a gate as passed that you did not execute.
A review that fights the house style produces noise, not signal. Honor what the repo already encodes.
CLAUDE.md, AGENTS.md,
CONTRIBUTING.md, .editorconfig, formatter/linter config, and any review-config
file at the repo root or in the changed directories. A documented convention is
binding: do not flag what a rule permits; do flag what it forbids.AGENTS.md overrides a repo-root rule for files under that path.Add a --depth modifier to any review:
--quick (~2 min): Pattern-based scan. Flag obvious bugs, hardcoded
secrets, missing null checks, SQL/command injection patterns, broken error
handling. No cross-file analysis. Use for PRs with narrow blast radius.--standard (default, ~10 min): Per-file analysis: correctness on changed paths, language-specific traps (see checklists below), state handling, test coverage on changed behavior, call graph within changed files. Default for all PRs unless the user says otherwise.--deep (~25 min): Cross-file analysis including full import graph and
call chain tracing. Finds semantic bugs that only appear when you follow data
across module boundaries. Use for auth changes, payment flows, data
migrations, and public API changes.State depth level at the top of every review output.
TypeScript, React, accessibility, Next.js, SEO, database, and performance trap
catalogs are in references/traps-web.md. Load it when the diff touches any of
those stacks, and read only the sections that match: a Swift-only change needs
none of it.
For --deep reviews on auth changes, payment flows, data migrations, or public API changes, run as separate lanes:
Collect consensus first. If high-severity concerns persist after a fix cycle, keep status at hold and name the smallest next check or patch.
The changed-file import graph is the floor. The bugs that ship hide outside the diff. On --deep, widen past the immediate callers:
git log -L or git blame the changed region. If this area was fixed before, a change that reintroduces the old shape is a regression, cite the prior commit. If it churns repeatedly, flag it as fragile.State what you traced. A whole-repo claim with no symbols named is not evidence.
Check on any new route handler, API endpoint, background job, cron, queue consumer, or service function:
try/catch blocks that catch without logging or Sentry capture. Flag catch (e) {} and catch (e) { console.error(e) }: a caught error that only console.errors is invisible in production. Require Sentry.captureException(e) or equivalent on unexpected errors.Run this automatically at the end of every review. No exceptions. It answers one question: is this safe to deploy right now?
Grade each dimension. Each is pass / conditional / block:
git revert fully undo this? Red flags: schema migrations, irreversible external API calls (email sent, payment charged, data permanently deleted), S3/storage mutations, message queue publishes. Recommend blocking if rollback requires manual data repair.~0% (new feature, flagged), ~partial (specific flow), ~100% (shared middleware, auth, DB query in hot path). Higher blast radius requires more evidence before deploy..github/workflows/ (or equivalent CI) exist and cover the changed surface (build, types, tests)? Are required status checks enforced on main? Recommend blocking if the changed surface has no automated gate and the repo is production-connected.Output block, required at the end of every review:
DEPLOY SAFETY
Breaking changes: pass | conditional | block, [evidence]
Rollback safety: pass | conditional | block, [evidence or red flag]
Blast radius: ~X%, [which path or user segment]
Environment readiness: pass | conditional | block, [missing vars if any]
Dependency changes: pass | conditional | block, [new deps and CVE status]
Data mutations: pass | conditional | block, [irreversible operations if any]
Security delta: improved | neutral | block, [surface changed]
Verdict: SAFE TO DEPLOY | DEPLOY WITH CONDITIONS | DO NOT DEPLOY
Conditions (if any):This skill emits no letter grade. When the caller wants lane grades too, run $suede-code (findings + grade) or $suede-code-grader (grade only): those two carry the canonical Instant-F trigger list, grade caps, and A-F scale. Instant-F patterns found here (hardcoded secrets, injection, auth bypass, unverified payment webhooks, destructive migrations with no rollback, plaintext sensitive data) are P0 findings and set the Ship Gate to hold.
Run automatically on every review. Scan the raw diff for content that should never reach git history. No exception for "it's just a branch", dirty commits propagate.
Execute it, do not eyeball it. This skill's scripts/commit-dirt-scan.sh carries the literal pattern set: run it with the target repo as the working directory (bash <skill-dir>/scripts/commit-dirt-scan.sh main...HEAD, or pipe a diff to it with -). It and prints a verdict per category. It is read-only and always exits 0, confirm each hit against the diff before reporting it. When the script cannot run, check every added (+) line by hand for the same seven categories: secrets and credentials · debug artifacts · conflict markers · accidentally staged build output · WIP breadcrumbs · oversized or binary blobs · exposed internal references.
Score:
COMMIT DIRT SCORE
Secrets / credentials: clean | suspicious | dirty, [pattern found or "none"]
Debug artifacts: clean | suspicious | dirty, [symbol or line or "none"]
Conflict markers: clean | dirty, ["none" or file:line]
Accidentally staged: clean | dirty, [path or "none"]
WIP breadcrumbs: clean | suspicious | dirty, [marker or "none"]
Oversized / binary: clean | dirty, [file and size or "none"]
Exposed internals: clean | suspicious | dirty, [pattern or "none"]
Overall dirt rating: CLEAN | SUSPICIOUS | DIRTYA DIRTY overall rating automatically sets the Ship Gate to hold.
Lead with findings, ordered by severity. Group repeated patterns once: "This pattern appears in 4 files: [list]. Fix described once below." The structural problem is the review: when a design or structural defect is present, report it first and alone, hold the line-level findings inside the code that defect governs, name them as deferred until the structure is settled, and do not enumerate them. A broken design buried under twelve P2 nits reads as twelve small problems.
P0 / P1: use the full block:
[P0] path/to/file.ts:142
Issue: JWT secret falls back to empty string; any token is valid when SECRET is unset.
Fix: `process.env.JWT_SECRET ?? (() => { throw new Error('JWT_SECRET required') })()`
Verify: set JWT_SECRET="" and curl /api/me, expect 401, currently 200.
OWASP: A02 Cryptographic Failures
Confidence: highP2 / P3: one line each:
[P2] components/Feed.tsx:88, missing key prop on .map() return; use item.id not index. TS will catch post-fix.
[P3] utils/format.ts:12, magic number 86400; extract as SECONDS_PER_DAY.Severity:
If the issue cannot be tied to a file, route, command, state, or user-visible behavior, mark it as an open question instead.
When asked to fix, convert each accepted finding into an agent-ready brief:
Fix one risk cluster at a time. After fixing, rerun the relevant review mode and do not close the finding until evidence confirms it.
When the user asks to apply fixes (--fix flag or equivalent instruction):
The per-category security baselines are in references/owasp-baselines.md. Load it
when the diff touches auth, sessions, crypto, payments, file upload, or any
request-handling boundary.
Always check these when relevant:
The Swift and SwiftUI trap catalog and the native contract-drift checks are in
references/traps-swift-ios.md. Load it when the diff touches Swift, SwiftUI, or
an API contract an iOS client consumes.
Flag tech debt patterns as P3, group by file, don't block ship. Do not block a ship on P3 tech debt unless it directly obscures a P0/P1 bug. File as follow-up.
Beyond what the repo documents, the review carries a fixed twelve-smell
maintainability baseline (Fowler, Refactoring ch. 3) in
references/smell-baseline.md. Load it on --standard and --deep reviews and
match it against the diff only. Its binding rules travel with it: a documented
repo rule overrides the baseline, every smell finding is a labeled judgment
call ("possible Feature Envy", P3 by default, confidence medium at best), and
anything tooling already enforces is skipped. Smell findings feed this
Technical Debt lane: they never outrank correctness findings and never move
the Ship Gate on their own.
Code that works but does not do what it claimed is still a defect.
#123,
Closes #45); a path the caller passed; a spec file under docs/, specs/,
or a scratch directory matching the branch or feature name. If none exists,
say "no spec available" in the output and review intent from the PR
description alone: never invent requirements to review against.For a PR summary or any review spanning four or more files, lead with a walkthrough so the reader sees the shape before the findings:
sequenceDiagram (request → handler → service → data) or flowchart when the change moves data across three or more boundaries or alters an async, auth, or payment path. Skip it for a localized edit: a diagram of a one-file change is noise.The walkthrough orients; it never replaces findings, and stays above the Findings block.
False positives are why reviewers get muted. Self-check the draft findings before emitting:
For a review:
Findings
Deploy Safety
Commit Dirt Score
Open Questions
Verification Checked
Ship GateFor no findings, say that clearly and name any residual risk or unrun checks.
For a PR summary:
Summary
Change Map
Risk Map
Verification
Ship GateThe ship gate is always the last line of a review output:
SHIP GATE: hold | ship-with-caveats | ship
Reason: [one sentence, naming the blocking finding ID or named caveat]hold: a blocker or high-risk unknown remains.ship-with-caveats: no blocker remains, but named non-critical caveats exist.ship: no known blocker remains and required verification passed.--fix or an explicit instruction.© JasonColapietro, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 7 other files (scripts, references) in skills/suede-code-review of JasonColapietro/suede-creator-skills.
Open the folder on GitHubat commit a9bf55e
Suede Code Review next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Suede Code Review this skillJasonColapietro/suede-creator-skills | 127 | — | ~7.1k | Automated safety check: Pass | MIT | |
| Frontend Code ReviewProgrammerAnthony/Expert-Coding-Harness | 235 | — | ~614 | Automated safety check: Pass | MIT | |
| Ultraciteagustinusnathaniel/nextarter-tailwind | 125 | 2 repos | ~1.2k | Automated safety check: Pass | MIT | |
| Code Reviewerjewbetcha/opentrace | 116 | 2 repos | ~1.1k | Automated safety check: Notes | MIT | |
| Dbgtheodo-group/debug-that | 158 | — | ~2.5k | Automated safety check: Pass | MIT | |
| Code Reviewnteract/semiotic | 2.7k | — | ~1.5k | Automated safety check: Pass | Apache-2.0 |
ProgrammerAnthony/Expert-Coding-Harness
A skill your agent uses when 用户需要审查前端代码(React/Vue/Next.js/TypeScript/Tailwind等)、检查代码质量、性能问题、可维护性、安全漏洞、最佳实践落地时。触发场景:前端代码评审、前端代码优化、React/Vue代码检查、TypeScript代码审查、前端性能优化、前端安全审计、前端代码规范检查。
agustinusnathaniel/nextarter-tailwind
Ultracite is a zero-config linting and formatting preset for JavaScript/TypeScript projects.
jewbetcha/opentrace
Comprehensive code review skill for TypeScript, JavaScript, Python, Swift, Kotlin, Go.
theodo-group/debug-that
Debug applications using the dbg CLI debugger. An agent skill from theodo-group/debug-that.
nteract/semiotic
Review Semiotic pull requests for behavioral bugs, regressions, contract drift, and missing evidence.
Rain-kl/OpenFlare
Provides comprehensive code review guidance for React 19, Vue 3, Angular 17+, Svelte 5, Rust, TypeScript, Java, PHP, Python, Django, Go, C/.NET, Kotlin, Swift, NestJS, C/C++, and more.
JasonColapietro/suede-creator-skills
Lints a local music or media release folder and scores its readiness, flagging missing files, weak metadata, artwork and stem problems, split gaps and rights blockers.
JasonColapietro/suede-creator-skills
Turns messy creator materials into an offline rights-and-provenance transfer package: hashed asset inventory, intake manifest, credits, license notes and a missing-information report.
JasonColapietro/suede-creator-skills
Turns a video clip, interview moment or transcript into a package that bridges viewers to a long-form guide, with rights, claim and approval gates along the way.
JasonColapietro/suede-creator-skills
Checks a Suede AI MCP server release against a live process: the full JSON-RPC lifecycle, schemas, annotations, malformed input, catalog agreement and install docs.
JasonColapietro/suede-creator-skills
Takes a native Android app from product idea to Google Play release, covering Compose architecture, policy checks, privacy, billing, testing, signing and rollout.
JasonColapietro/suede-creator-skills
Suede-owned paid-media creative system for hooks, headlines, primary text, static and motion concepts, platform specs, review pages, and test-ready variant batches.
Works with
Categories
Suede AI findings-only code review with full context: changed files, callers, contracts, and deploy surface. Suede Code Review is an agent skill from JasonColapietro/suede-creator-skills. Suede AI findings-only code review with full context: changed files, callers, contracts, and deploy surface.
Suede Code Review fits situations like: asked to review a diff; find the bugs before merge; check a change for security; accessibility problems.
Run `npx skills add JasonColapietro/suede-creator-skills --skill suede-code-review -a claude-code`. Or copy the skill folder (skills/suede-code-review in JasonColapietro/suede-creator-skills) into .claude/skills/suede-code-review in your project. Claude Code loads it when a task matches its description.
Run `npx skills add JasonColapietro/suede-creator-skills --skill suede-code-review -a codex`. Or copy the skill folder (skills/suede-code-review in JasonColapietro/suede-creator-skills) into .agents/skills/suede-code-review in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add JasonColapietro/suede-creator-skills --skill suede-code-review -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/suede-code-review, .gemini/skills/suede-code-review, .github/skills/suede-code-review and .opencode/skills/suede-code-review in your project.
Going by SKILL.md and its folder, Suede Code Review needs a shell for the scripts in its folder, the command-line tools its instructions call (git, npm, npx, node, xcodebuild and bash) and credentials named JWT_SECRET. Our summary lists: Node.js; A Bash shell.
SKILL.md contains no URLs. Its commands use git, npm and npx, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.
Suede Code Review is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 7.1k tokens (SKILL.md is roughly 28k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 5.3k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Suede Code Review: Frontend Code Review (ProgrammerAnthony/Expert-Coding-Harness, 235 stars), Ultracite (agustinusnathaniel/nextarter-tailwind, 125 stars), Code Reviewer (jewbetcha/opentrace, 116 stars) and Dbg (theodo-group/debug-that, 158 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
JasonColapietro (a GitHub user) maintains it in JasonColapietro/suede-creator-skills, which has 127 GitHub stars. The repository holds 78 skills in this directory. The repository was last updated on October 9, 2026.
Source: JasonColapietro/suede-creator-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.