Code Review Checklist
shareAI-lab/learn-claude-code
Reviews code against a five-part checklist covering security, correctness, performance, maintainability and testing, and reports findings in a fixed format.
Git-native issue tracking (beads), coding guidelines, knowledge injection, and spec-driven planning for AI agents.
$ npx skills add jlevy/strif --skill tbd -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install jlevy/strif tbd --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/jlevy/strif.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/tbd .claude/skills/tbd && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "tbd" agent skill from https://github.com/jlevy/strif/tree/master/.claude/skills/tbd into .claude/skills/tbd/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "tbd", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/jlevy/strif/tree/master/.claude/skills/tbdType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add jlevy/strif --skill tbd -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install jlevy/strif tbd --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/jlevy/strif.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.claude/skills/tbd .agents/skills/tbd && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "tbd" agent skill from https://github.com/jlevy/strif/tree/master/.claude/skills/tbd into .agents/skills/tbd/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "tbd", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add jlevy/strif --skill tbd -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install jlevy/strif tbd --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/jlevy/strif.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.claude/skills/tbd .cursor/skills/tbd && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "tbd" agent skill from https://github.com/jlevy/strif/tree/master/.claude/skills/tbd into .cursor/skills/tbd/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "tbd", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/jlevy/strif.git --path .claude/skills/tbd--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add jlevy/strif --skill tbd -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install jlevy/strif tbd --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/jlevy/strif.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.claude/skills/tbd .gemini/skills/tbd && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "tbd" agent skill from https://github.com/jlevy/strif/tree/master/.claude/skills/tbd into .gemini/skills/tbd/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "tbd", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install jlevy/strif tbdInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add jlevy/strif --skill tbd -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/jlevy/strif.git skills-src && mkdir -p .github/skills && cp -r skills-src/.claude/skills/tbd .github/skills/tbd && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "tbd" agent skill from https://github.com/jlevy/strif/tree/master/.claude/skills/tbd into .github/skills/tbd/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "tbd", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add jlevy/strif --skill tbd -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install jlevy/strif tbd --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/jlevy/strif.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.claude/skills/tbd .opencode/skills/tbd && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "tbd" agent skill from https://github.com/jlevy/strif/tree/master/.claude/skills/tbd into .opencode/skills/tbd/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "tbd", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
tbdGit-native issue tracking (beads), coding guidelines, knowledge injection, and spec-driven planning for AI agents.
Tbd is an agent skill from jlevy/strif. Git-native issue tracking (beads), coding guidelines, knowledge injection, and spec-driven planning for AI agents. Drop-in replacement for bd/Beads with simpler architecture. Use for: tracking issues/beads with dependencies, creating bugs/features/tasks, planning specs, implementing features from specs, code reviews, committing code, creating PRs, loading coding guidelines (TypeScript, Python, TDD, golden testing, Convex, monorepo patterns), code cleanup, research briefs, architecture docs, agent handoffs, and…
Its SKILL.md is about 3.5k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Development, covering Test-driven development, Code review and Task management. It works with Python, TypeScript and Git. The repository describes itself as: A tiny, useful Python lib of string, file, and object utilities. The licence is MIT.
4 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit f66ba7e. It shows what the files ask for, not the result of running them.
Pre-approves these tools, so the agent can use them without asking each time:
Bash(tbd:*)ReadWriteFrom allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
npmFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use npm, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Tbd loads about 3.5k tokens when it runs. Until then it costs about 256 tokens; SKILL.md has 1,349 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from jlevy/strif at commit f66ba7e, republished under its MIT licence (© jlevy). 1,349 words, ~3,470 tokens.
.claude/skills/tbd/SKILL.md (or your agent's skills folder).<!-- DO NOT EDIT: Generated by tbd setup.
Run 'tbd setup' to update.
-->
tbd helps humans and agents ship code with greater speed, quality, and discipline.
bd.npm install -g get-tbd@latest
tbd setup --auto --prefix=<name> # Fresh project (--prefix is REQUIRED: 2-8 alphabetic chars recommended. ALWAYS ASK THE USER FOR THE PREFIX; do not guess it)
tbd setup --auto # Existing tbd project (prefix already set)
tbd setup --from-beads # Migration from .beads/ if `bd` has been usedtbd --help # Command reference
tbd status # Status
tbd doctor # If there are problems
tbd setup --auto # Run any time to refresh setup
tbd prime # Restore full context on tbd after compactionYou are the tbd operator: Users talk naturally; you translate their requests to tbd actions. DO NOT tell users to run tbd commands. That’s your job.
WRONG: “Run tbd create to track this bug”
RIGHT: (you run tbd create yourself and tell the user it’s tracked)
Welcoming a user: When users ask “what is tbd?”
or want help → run tbd shortcut welcome-user
| User Says | You (the Agent) Run |
|---|---|
| Issues/Beads | |
| “There’s a bug where …” | tbd create "..." --type=bug |
| “Create a task/feature for …” | tbd create "..." --type=task or --type=feature |
| “Let’s work on issues/beads” | tbd ready |
| “Show me issue X” | tbd show <id> |
| “Close this issue” | tbd close <id> |
| “Search issues for X” | tbd search "X" |
| “Add label X to issue” | tbd label add <id> <label> |
| “What issues are stale?” | tbd stale |
| Planning & Specs | |
| “Plan a new feature” / “Create a spec” | tbd shortcut new-plan-spec |
| “Break spec into beads” | tbd shortcut plan-implementation-with-beads |
| “Implement these beads” | tbd shortcut implement-beads |
| Code Review & Commits | |
| “Review this code” / “Code review” | tbd shortcut review-code |
| “Review this PR” | tbd shortcut review-github-pr |
| “Commit this” / “Use the commit shortcut” | tbd shortcut code-review-and-commit |
| “Create a PR” / “File a PR” | tbd shortcut create-or-update-pr-simple |
| “Merge main into my branch” | tbd shortcut merge-upstream |
| Guidelines & Knowledge | |
| “Use TypeScript best practices” | tbd guidelines typescript-rules |
| “Use Python best practices” | tbd guidelines python-rules |
| “Build a TypeScript CLI” | tbd guidelines typescript-cli-tool-rules |
| “Improve monorepo setup” | tbd guidelines pnpm-monorepo-patterns or bun-monorepo-patterns |
| “Add golden/e2e testing” | tbd guidelines golden-testing-guidelines |
| “Use TDD” / “Test-driven development” | tbd guidelines general-tdd-guidelines |
| “Convex best practices” | tbd guidelines convex-rules |
| Documentation | |
| “Research this topic” | tbd shortcut new-research-brief |
| “Document architecture” | tbd shortcut new-architecture-doc |
| Cleanup & Maintenance | |
| “Clean up this code” / “Remove dead code” | tbd shortcut code-cleanup-all |
| “Fix repository problems” | tbd doctor --fix |
| Sessions & Handoffs | |
| “Hand off to another agent” | tbd shortcut agent-handoff |
| “Check out this library’s source” | tbd shortcut checkout-third-party-repo |
| (your choice whenever appropriate) | tbd list, tbd dep add, tbd close, tbd sync, etc. |
Note: Never gitignore .tbd/workspaces/ — the outbox must be committed to your
working branch. See tbd guidelines tbd-sync-troubleshooting for details.
Before saying “done”, you MUST complete this checklist:
[ ] 1. git add + git commit
[ ] 2. git push
[ ] 3. gh pr checks <PR> --watch 2>&1 (IMPORTANT: WAIT for final summary, do NOT tell user it is done until you confirm it passes CI!)
[ ] 4. tbd close/update <id> for all beads worked on
[ ] 5. tbd sync
[ ] 6. CONFIRM CI passed (if failed: fix, run tests, re-push, restart from step 3)Work is not done until pushed, CI passes, and tbd is synced.
tbd ready when not given specific directionstbd sync at session end| Command | Purpose |
|---|---|
tbd ready | Beads ready to work (no blockers) |
tbd list --status open | All open beads |
tbd list --status in_progress | Your active work |
tbd show <id> | Bead details with dependencies |
| Command | Purpose |
|---|---|
tbd create "title" --type task|bug|feature --priority=P2 | New bead (P0-P4, not “high/medium/low”) |
tbd update <id> --status in_progress | Claim work |
tbd close <id> [--reason "..."] | Mark complete |
| Command | Purpose |
|---|---|
tbd dep add <bead> <depends-on> | Add dependency |
tbd blocked | Show blocked beads |
tbd sync | Sync with git remote (run at session end) |
tbd stats | Project statistics |
tbd doctor | Check for problems |
tbd doctor --fix | Auto-fix repository problems |
| Command | Purpose |
|---|---|
tbd search <query> | Search issues by text |
tbd label add <id> <label> | Add label to issue |
tbd label remove <id> <label> | Remove label from issue |
tbd label list | List all labels in use |
tbd stale | List issues not updated recently |
| Command | Purpose |
|---|---|
tbd shortcut <name> | Run a shortcut |
tbd shortcut --list | List shortcuts |
tbd guidelines <name> | Load coding guidelines |
tbd guidelines --list | List guidelines |
tbd template <name> | Output a template |
--json to any command<!-- BEGIN SHORTCUT DIRECTORY -->
Run tbd shortcut <name> to use any of these shortcuts:
| Name | Description |
|---|---|
| agent-handoff | Generate a concise handoff prompt for another coding agent to continue work |
| checkout-third-party-repo | Get source code for libraries and third-party repos using git. Essential for reliable source code review. Prefer this to web searches or fetching of web pages from github.com as it is far more effective (github.com blocks web scraping from main website). |
| code-cleanup-all | Full cleanup cycle including duplicate removal, dead code, and code quality improvements |
| code-cleanup-docstrings | Review and add concise docstrings to major functions and types |
| code-cleanup-tests | Review and remove tests that do not add meaningful coverage |
| code-review-and-commit | Run pre-commit checks, review changes, and commit code |
| coding-spike | Prototype to validate a spec through hands-on implementation |
| create-or-update-pr-simple | Create or update a pull request with a concise summary |
| create-or-update-pr-with-validation-plan | Create or update a pull request with a detailed test/validation plan |
| implement-beads | Implement beads from a spec, following TDD and project rules |
| merge-upstream | Merge origin/main into current branch with conflict resolution |
| new-architecture-doc | Create an architecture document for a system or component design |
| new-guideline | Create a new coding guideline document for tbd |
| new-plan-spec | Create a new feature planning specification document |
| new-qa-playbook | Create a QA test playbook for manual validation workflows |
| new-research-brief | Create a research document for investigating a topic or technology |
| new-shortcut | Create a new shortcut (reusable instruction template) for tbd |
| new-validation-plan | Create a validation/test plan showing what's tested and what remains |
| plan-implementation-with-beads | Create implementation beads from a feature planning spec |
| precommit-process | Full pre-commit checklist including spec sync, code review, and testing |
| review-code | Comprehensive code review for uncommitted changes, branch work, or GitHub PRs |
| review-code-python | Python-focused code review (language-specific rules only) |
| review-code-typescript | TypeScript-focused code review (language-specific rules only) |
| review-github-pr | Review a GitHub pull request with follow-up actions (comment, fix, CI check) |
| revise-all-architecture-docs | Comprehensive revision of all current architecture documents |
| revise-architecture-doc | Update an architecture document to reflect current codebase state |
| setup-github-cli | Ensure GitHub CLI (gh) is installed and working |
| sync-failure-recovery | Handle tbd sync failures by saving to workspace and recovering later |
| update-specs-status | Review active specs and sync their status with tbd issues |
| welcome-user | Welcome message for users after tbd installation or setup |
Run tbd guidelines <name> to apply any of these guidelines:
| Name | Description |
|---|---|
| backward-compatibility-rules | Guidelines for maintaining backward compatibility across code, APIs, file formats, and database schemas |
| bun-monorepo-patterns | Modern patterns for Bun-based TypeScript monorepo architecture |
| cli-agent-skill-patterns | Best practices for building TypeScript CLIs that function as agent skills in Claude Code and other AI coding agents |
| commit-conventions | Conventional Commits format with extensions for agentic workflows |
| convex-limits-best-practices | Comprehensive reference for Convex platform limits, workarounds, and performance best practices |
| convex-rules | Guidelines and best practices for building Convex projects, including database schema design, queries, mutations, and real-world examples |
| electron-app-development-patterns | Guidelines for Electron development ecosystems including npm, pnpm, and Bun, with security baselines and framework comparisons |
| error-handling-rules | Rules for handling errors, failures, and exceptional conditions |
| general-coding-rules | Rules for constants, magic numbers, and general coding practices |
| general-comment-rules | Language-agnostic rules for writing clean, maintainable comments |
| general-eng-assistant-rules | Rules for AI assistants acting as senior engineers, including objectivity and communication guidelines |
| general-style-rules | Style guidelines for auto-formatting, emoji usage, and output formatting |
| general-tdd-guidelines | Test-Driven Development methodology and best practices |
| general-testing-rules | Rules for writing minimal, effective tests with maximum coverage |
| golden-testing-guidelines | Guidelines for implementing golden/snapshot testing for complex systems |
| pnpm-monorepo-patterns | Modern patterns for pnpm-based TypeScript monorepo architecture |
| python-cli-patterns | Modern patterns for Python CLI application architecture |
| python-modern-guidelines | Guidelines for modern Python projects using uv, with a few more opinionated practices |
| python-rules | General Python coding rules and best practices |
| release-notes-guidelines | Guidelines for writing clear, accurate release notes |
| tbd-sync-troubleshooting | Common issues and solutions for tbd sync and workspace operations |
| typescript-cli-tool-rules | Rules for building CLI tools with Commander.js, picocolors, and TypeScript |
| typescript-code-coverage | Best practices for code coverage in TypeScript with Vitest and v8 provider |
| typescript-rules | TypeScript coding rules and best practices |
| typescript-sorting-patterns | Deterministic sorting patterns and comparison chains for TypeScript |
| typescript-yaml-handling-rules | Best practices for parsing and serializing YAML in TypeScript |
| writing-style-guidelines | Guidelines for clear, concise, and reader-friendly writing in documentation and code |
<!-- END SHORTCUT DIRECTORY -->
© jlevy, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in .claude/skills/tbd of jlevy/strif.
Open the folder on GitHubat commit f66ba7e
We found 2 copies of this SKILL.md (exact, near-identical or edited) in other folders. This page covers the copy in jlevy/strif, which our catalogue first saw on October 7, 2026.
Tbd next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Tbd this skilljlevy/strif | 131 | — | ~3.5k | Automated safety check: Pass | MIT | |
| Code Review ChecklistshareAI-lab/learn-claude-code | 78k | 5 repos | ~1.1k | Automated safety check: Pass | MIT | |
| Subagent-Driven DevelopmentHoangNguyen0403/agent-skills-standard | 571 | — | ~1.3k | Automated safety check: Pass | MIT | |
| Skyvern Version BumpSkyvern-AI/skyvern | 23k | — | ~1k | Automated safety check: Notes | AGPL-3.0 | |
| Git History Bug Auditben-manes/caffeine | 18k | — | ~3.3k | Automated safety check: Pass | Apache-2.0 | |
| Code Reviewerjewbetcha/opentrace | 116 | 2 repos | ~1.1k | Automated safety check: Notes | MIT |
shareAI-lab/learn-claude-code
Reviews code against a five-part checklist covering security, correctness, performance, maintainability and testing, and reports findings in a fixed format.
HoangNguyen0403/agent-skills-standard
Runs a multi-task implementation plan by sending each task to a fresh implementer subagent, reviewing it independently, then reviewing the whole branch.
Skyvern-AI/skyvern
Walks through a Skyvern open-source release bump: update the version, rebuild the Python and TypeScript SDKs with Fern, commit, and open a pull request.
ben-manes/caffeine
Audits a module by walking its git history commit by commit, tracking unresolved issues forward, and reporting the ones that survive to HEAD as findings.
jewbetcha/opentrace
Comprehensive code review skill for TypeScript, JavaScript, Python, Swift, Kotlin, Go.
x-tools-author/x-tools
Runs a 47-rule deterministic QML linter, then six parallel deep-analysis passes over bindings, layout, loaders, delegates, states, and performance.
Works with
Categories
Git-native issue tracking (beads), coding guidelines, knowledge injection, and spec-driven planning for AI agents. Tbd is an agent skill from jlevy/strif. Git-native issue tracking (beads), coding guidelines, knowledge injection, and spec-driven planning for AI agents.
Tbd fits situations like: : tracking issues/beads with dependencies; creating bugs/features/tasks; implementing features from specs; committing code.
Run `npx skills add jlevy/strif --skill tbd -a claude-code`. Or copy the skill folder (.claude/skills/tbd in jlevy/strif) into .claude/skills/tbd in your project. Claude Code loads it when a task matches its description.
Run `npx skills add jlevy/strif --skill tbd -a codex`. Or copy the skill folder (.claude/skills/tbd in jlevy/strif) into .agents/skills/tbd in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add jlevy/strif --skill tbd -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/tbd, .gemini/skills/tbd, .github/skills/tbd and .opencode/skills/tbd in your project.
Going by SKILL.md and its folder, Tbd needs the command-line tools its instructions call (npm). Our summary lists: Python 3; Node.js. Its frontmatter pre-approves these tools: Bash(tbd:*), Read, Write.
SKILL.md contains no URLs. Its commands use npm, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Tbd is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 3.5k tokens (SKILL.md is roughly 14k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Tbd: Code Review Checklist (shareAI-lab/learn-claude-code, 78k stars), Subagent-Driven Development (HoangNguyen0403/agent-skills-standard, 571 stars), Skyvern Version Bump (Skyvern-AI/skyvern, 23k stars) and Git History Bug Audit (ben-manes/caffeine, 18k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
jlevy (a GitHub user) maintains it in jlevy/strif, which has 131 GitHub stars. The repository was last updated on May 23, 2026.
Source: jlevy/strif on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.