Agent skill

At Review

by kairyou in kairyou/agent-tools

Review code changes for bugs, regressions, convention violations, and high-value cleanup opportunities.

MITAuto-check passedDevelopment

Install At Review

skills CLI
$ npx skills add kairyou/agent-tools --skill at-review -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install kairyou/agent-tools at-review --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/kairyou/agent-tools.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/workflow/at-review .claude/skills/at-review && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
at-review
GitHub stars
178
Token cost
~2.1k tokens
SKILL.md length
1,210 words
Files
3 (incl. references)
Skills in repo
8
Repo updated
First seen
Licence
MIT

At a glance

Review code changes for bugs, regressions, convention violations, and high-value cleanup opportunities.

  • Works in 3 steps: Gather the diff → Find candidates (3 correctness angles +… → Verify (1-vote, recall-biased)
  • Hosted PR/MR URLs
  • SKILL.md covers Phase 0 — Gather the diff, Phase 1 — Find candidates (3…, Phase 2 — Verify (1-vote,… and Output, plus 1 more section
  • Calls git

What it does

At Review is an agent skill from kairyou/agent-tools. Review code changes for bugs, regressions, convention violations, and high-value cleanup opportunities. Use for diffs, commit ranges, hosted PR/MR URLs, branches, paths, staged changes, or working-tree changes.

Its SKILL.md is about 2.1k tokens, which your agent loads only when the skill is triggered. The skill folder holds 4 other files, including reference files (for example `agents/openai.yaml` and `references/review-targets.md`).

It sits in Development, covering Code review. It works with Git. The repository describes itself as: Reusable Agent Skills, plus integrations (statusline, provider usage, vision) that install into Codex, Claude Code, and opencode. The licence is MIT.

When your agent uses it

  • Hosted PR/MR URLs
  • Working-tree changes

Example prompts

  • “/at-review”

Workflow steps

3 steps, taken from the step headings in SKILL.md.

  1. Gather the diff
  2. Find candidates (3 correctness angles + 3 cleanup angles + 1 altitude angle + 1 conventions angle, up to 6 each)
  3. Verify (1-vote, recall-biased)

What it can do on your machine

Read from SKILL.md and the folder at commit acc2563. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • git

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use git, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

At Review loads about 2.1k tokens when it runs, and up to ~3k if it reads all its reference files. Until then it costs about 55 tokens; SKILL.md has 1,210 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~55
When it runs · the whole SKILL.md, loaded when a task matches
~2.1k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~3k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from kairyou/agent-tools at commit acc2563, republished under its MIT licence (© kairyou). 1,210 words, ~2,136 tokens.

Download SKILL.mdSave it as .claude/skills/at-review/SKILL.md (or your agent's skills folder). This skill also uses 2 other files; get the full folder from GitHub.
name
at-review
description
Review code changes for bugs, regressions, convention violations, and high-value cleanup opportunities. Use for diffs, commit ranges, hosted PR/MR URLs, branches, paths, staged changes, or working-tree changes.
argument-hint
[--fix] [<pr-or-mr-url|branch|path>]

Code Review

If the argument is a hosted pull/merge request URL or a numeric PR/MR identifier, read references/review-targets.md from this skill directory before running commands. Follow its read-only resolution and authentication fallback rules; do not switch the user's working tree or write to the hosting service.

high effort → 3+5 angles × 6 candidates → 1-vote verify (recall-biased) → ≤10 findings

You are reviewing for recall at high effort: catch every real bug a careful reviewer would catch in one sitting. At this level, catching real bugs matters more than avoiding false positives. Err on the side of surfacing.

Phase 0 — Gather the diff

Run git diff "@{upstream}...HEAD" (or git diff main...HEAD / git diff HEAD~1 if there's no upstream) to get the unified diff under review. If there are uncommitted changes, or the range diff is empty, also run git diff HEAD and include the working-tree changes in scope — the review often runs before the commit. If a PR number, branch name, or file path was passed as an argument, review that target instead. Treat this diff as the review scope.

Phase 1 — Find candidates (3 correctness angles + 3 cleanup angles + 1 altitude angle + 1 conventions angle, up to 6 each)

Run 8 independent finder angles using multi-agent capabilities. Each surfaces up to 6 candidate findings with file, line, a one-line summary, and a concrete failure_scenario. If multi-agent support is not available in your current tool set, do not error — perform each angle (and each verification) yourself, sequentially, in this context.

Angle A — line-by-line diff scan

Read every hunk in the diff, line by line. Then Read the enclosing function for each hunk — bugs in unchanged lines of a touched function are in scope (the PR re-exposes or fails to fix them). For every line ask: what input, state, timing, or platform makes this line wrong? Look for inverted/wrong conditions, off-by-one, null/undefined deref, missing await, falsy-zero checks, wrong-variable copy-paste, error swallowed in catch, unescaped regex metachars.

Angle B — removed-behavior auditor

For every line the diff DELETES or replaces, name the invariant or behavior it enforced, then search the new code for where that invariant is re-established. If you can't find it, that's a candidate: a removed guard, a dropped error path, a narrowed validation, a deleted test that was covering a real case.

Angle C — cross-file tracer

For each function the diff changes, find its callers (Grep for the symbol) and check whether the change breaks any call site: a new precondition, a changed return shape, a new exception, a timing/ordering dependency. Also check callees: does a parallel change in the same PR make a call unsafe?

Reuse

The angles above hunt for bugs; this one and the next two hunt for cleanup in the changed code. Flag new code that re-implements something the codebase already has — Grep shared/utility modules and files adjacent to the change, and name the existing helper to call instead.

Simplification

Flag unnecessary complexity the diff adds: redundant or derivable state, copy-paste with slight variation, deep nesting, dead code left behind. Name the simpler form that does the same job.

Efficiency

Flag wasted work the diff introduces: redundant computation or repeated I/O, independent operations run sequentially, blocking work added to startup or hot paths. Also flag long-lived objects built from closures or captured environments — they keep the entire enclosing scope alive for the object's lifetime (a memory leak when that scope holds large values); prefer a class/struct that copies only the fields it needs. Name the cheaper alternative.

Altitude

Check that each change fixes the root cause at the right depth rather than patching a symptom with a fragile bandaid. Special cases layered on shared infrastructure are a sign the fix isn't deep enough — prefer the simpler, more general change to the underlying mechanism over adding special cases, and name that change.

Show full SKILL.md (578 more words)Show less
Conventions (AGENTS.md or CLAUDE.md)

Find the instruction files that govern the changed code: the user-level instruction files for the current agent, the repo-root AGENTS.md or CLAUDE.md, plus any AGENTS.md or CLAUDE.md or CLAUDE.local.md in a directory that is an ancestor of a changed file (a directory's AGENTS.md or CLAUDE.md only applies to files at or below it). Read each one that exists, then check the diff for clear violations of the rules they state.

Only flag a violation when you can quote the exact rule and the exact line that breaks it — no style preferences, no vague "spirit of the doc" inferences. In the finding, name the instruction file path and quote the rule so the report can cite it. If no instruction file applies, return nothing for this angle.

Cleanup, altitude, and conventions candidates use the same file/line/summary shape; in failure_scenario, state the concrete cost (what is duplicated, wasted, harder to maintain, or which project instruction is broken) instead of a crash. Correctness bugs always outrank cleanup, altitude, and conventions findings when the output cap forces a cut.

Pass every candidate with a nameable failure scenario through — finders that silently drop half-believed candidates bypass the verify step and are the dominant cause of misses.

Phase 2 — Verify (1-vote, recall-biased)

Dedup near-duplicates (same defect, same location, same reason → keep one). For each remaining candidate, run one verifier using multi-agent capabilities: give it the diff, the relevant file(s), and the candidate; it returns exactly one of CONFIRMED / PLAUSIBLE / REFUTED.

PLAUSIBLE by default — do not refute a candidate for being "speculative" or "depends on runtime state" when the state is realistic: concurrency races, nil/undefined on a rare-but-reachable path (error handler, cold cache, missing optional field), falsy-zero treated as missing, off-by-one on a boundary the code does not exclude, retry storms / partial failures, regex/allowlist that lost an anchor. These are PLAUSIBLE.

REFUTED only when constructible from the code: factually wrong (quote the actual line); provably impossible (type/constant/invariant — show it); already handled in this diff (cite the guard); or pure style with no observable effect.

Keep CONFIRMED and PLAUSIBLE. Drop REFUTED.

Output

Unless --json was explicitly passed, the main agent's final answer is a Markdown report, nothing else. Structure it exactly:

Summary - 1-2 sentences on the review scope and what was found. If the diff was empty, write exactly "No changes to review." and stop. If nothing survived verification, write exactly "No findings survived verification." and stop.

Findings - one numbered block per finding, most-severe first, at most 10. Assign each finding High, Medium, or Low from its concrete impact and likelihood:

text
1. High|Medium|Low: summary
   file:line
   Failure: <failure_scenario>
JSON mode

Only when --json was explicitly passed, follow this output contract:

Return findings as a JSON array of at most 10 objects:

json
[
  {
    "file": "path/to/file.ext",
    "line": 123,
    "summary": "one-sentence statement of the bug",
    "failure_scenario": "concrete inputs/state → wrong output/crash"
  }
]

Ranked most-severe first. If more than 10 survive, keep the 10 most severe. If nothing survives verification, return []. Do not call the host-specific findings-reporting tool even if it is available - this review's output contract is the JSON block above.

Applying fixes (--fix)

Only apply anything when --fix was passed. Otherwise skip this entire section.

After producing the findings list, apply the findings to the working tree instead of stopping at the report: fix each one directly — correctness bugs and reuse/simplification/efficiency cleanups alike. Skip any finding whose fix would change intended behavior, require changes well outside the reviewed diff, or that you judge to be a false positive — note the skip rather than arguing with it. Finish with a brief summary of what was fixed and what was skipped.

© kairyou, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 2 other files (references) in skills/workflow/at-review of kairyou/agent-tools.

  • SKILL.md
  • agents/openai.yaml
  • references/review-targets.md

Open the folder on GitHubat commit acc2563

Compare with similar skills

At Review next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

At Review compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
At Review this skillkairyou/agent-tools178—~2.1kAutomated safety check: PassMIT
Review Triage Phaseprisma/orm48k—~995Automated safety check: PassApache-2.0
Cursor Composer Task DelegateChachamaru127/claude-code-harness3.2k—~4.4kAutomated safety check: NotesMIT
Adopt PR Branch Contextpydantic/pydantic-ai-harness952—~1.8kAutomated safety check: PassMIT
Coding Protocollencx/skills196—~2.4kAutomated safety check: PassMIT
Code Reviewjustxor/claude-code-pro-course276—~293Automated safety check: PassMIT

Similar skills

  • Official

    Runs the triage step of the review-framework loop: reads fetched PR review state, builds `review-actions.json`, validates it and renders `review-actions.md`.

    48k GitHub stars~995 tokensUpdated yesterday
    DevelopmentAuto-check passed
  • Cursor Composer Task Delegate

    Chachamaru127/claude-code-harness

    Hands one implementation task to Cursor Composer in an isolated git worktree, then reviews its diff and cherry-picks the result into the main branch.

    3.2k GitHub stars~4.4k tokensUpdated 6 days ago
    DevelopmentAuto-check: notes
  • Adopt PR Branch Context

    pydantic/pydantic-ai-harness

    Official

    Fills in issue-brief.md and pr-decisions.md for an existing pull request, so you can pick up a PR mid-flight with its linked issue and past review decisions summarized.

    952 GitHub stars~1.8k tokensUpdated 8 days ago
    DevelopmentAuto-check passed
  • Coding Protocol

    lencx/skills

    Risk-scaled repo execution and code-evidence protocol. An agent skill from lencx/skills.

    196 GitHub stars~2.4k tokensUpdated 1 mo ago
    DevelopmentAuto-check passed
  • Code Review

    justxor/claude-code-pro-course

    Ревью изменений в текущей ветке относительно main. An agent skill from justxor/claude-code-pro-course.

    276 GitHub stars~293 tokensUpdated 10 days ago
    DevelopmentAuto-check passed
  • Targeted Emergency Bug Fix

    VeryGoodOpenSource/vgv-wingspan

    Applies a minimal fix to an emergency bug through triage, root-cause location, a hotfix branch and a blast-radius check, with tests and review still required.

    109 GitHub stars~1.9k tokensUpdated 4 days ago
    DevelopmentAuto-check passed

More from kairyou/agent-tools

All 8 skills in this repo
  • At Zentao

    kairyou/agent-tools

    Handle ZenTao (禅道) Bugs and Tasks end to end, including updating or writing back an item after code changes, managing Task status and hours, and reading linked Stories.

    178 GitHub stars~4k tokensUpdated 3 days ago
    Auto-check passed
  • At Commit

    kairyou/agent-tools

    Generate a Conventional Commits message from staged changes and wait for confirmation before committing.

    178 GitHub stars~1.5k tokensUpdated 3 days ago
    Auto-check passed
  • At Vision

    kairyou/agent-tools

    Inspect screenshots, photos, diagrams, image paths, and image URLs when the task depends on visible content.

    178 GitHub stars~1.5k tokensUpdated 3 days ago
    Auto-check passed
  • At Daily Log

    kairyou/agent-tools

    Summarize each day's Git activity into a concise daily work log, for a single date or a range.

    178 GitHub stars~2k tokensUpdated 3 days ago
    Auto-check passed
  • At Self Eval

    kairyou/agent-tools

    Summarize a contributor's Git history, a provided work log, or both into a concise, review-friendly self-evaluation for quarterly, semi-annual, or promotion cycles.

    178 GitHub stars~1.6k tokensUpdated 3 days ago
    Auto-check passed
  • At Simplify

    kairyou/agent-tools

    Refactor changed code to reduce duplication, complexity, and wasted work.

    178 GitHub stars~770 tokensUpdated 3 days ago
    Auto-check passed

Works with

Questions about At Review

What does At Review do?

Review code changes for bugs, regressions, convention violations, and high-value cleanup opportunities. At Review is an agent skill from kairyou/agent-tools. Review code changes for bugs, regressions, convention violations, and high-value cleanup opportunities.

When should I use At Review?

At Review fits situations like: hosted PR/MR URLs; working-tree changes.

How do I install At Review in Claude Code?

Run `npx skills add kairyou/agent-tools --skill at-review -a claude-code`. Or copy the skill folder (skills/workflow/at-review in kairyou/agent-tools) into .claude/skills/at-review in your project. Claude Code loads it when a task matches its description.

How do I install At Review in Codex?

Run `npx skills add kairyou/agent-tools --skill at-review -a codex`. Or copy the skill folder (skills/workflow/at-review in kairyou/agent-tools) into .agents/skills/at-review in your project. Codex loads it when a task matches its description.

Can I use At Review in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add kairyou/agent-tools --skill at-review -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/at-review, .gemini/skills/at-review, .github/skills/at-review and .opencode/skills/at-review in your project.

What does At Review need to run?

Going by SKILL.md and its folder, At Review needs the command-line tools its instructions call (git).

Does At Review access the network?

SKILL.md contains no URLs. Its commands use git, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is At Review safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does At Review use?

At Review is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does At Review use?

About 2.1k tokens (SKILL.md is roughly 8.5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 876 tokens, read only when the agent opens those files.

What are the alternatives to At Review?

Skills that share tags, products or a category with At Review: Review Triage Phase (prisma/orm, 48k stars), Cursor Composer Task Delegate (Chachamaru127/claude-code-harness, 3.2k stars), Adopt PR Branch Context (pydantic/pydantic-ai-harness, 952 stars) and Coding Protocol (lencx/skills, 196 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains At Review?

kairyou (a GitHub user) maintains it in kairyou/agent-tools, which has 178 GitHub stars. The repository holds 8 skills in this directory. The repository was last updated on October 8, 2026.

Source: kairyou/agent-tools on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.