Review Triage Phase
prisma/orm
Runs the triage step of the review-framework loop: reads fetched PR review state, builds `review-actions.json`, validates it and renders `review-actions.md`.
Review code changes for bugs, regressions, convention violations, and high-value cleanup opportunities.
$ npx skills add kairyou/agent-tools --skill at-review -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install kairyou/agent-tools at-review --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/kairyou/agent-tools.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/workflow/at-review .claude/skills/at-review && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "at-review" agent skill from https://github.com/kairyou/agent-tools/tree/main/skills/workflow/at-review into .claude/skills/at-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "at-review", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/kairyou/agent-tools/tree/main/skills/workflow/at-reviewType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add kairyou/agent-tools --skill at-review -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install kairyou/agent-tools at-review --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/kairyou/agent-tools.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/workflow/at-review .agents/skills/at-review && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "at-review" agent skill from https://github.com/kairyou/agent-tools/tree/main/skills/workflow/at-review into .agents/skills/at-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "at-review", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add kairyou/agent-tools --skill at-review -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install kairyou/agent-tools at-review --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/kairyou/agent-tools.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/workflow/at-review .cursor/skills/at-review && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "at-review" agent skill from https://github.com/kairyou/agent-tools/tree/main/skills/workflow/at-review into .cursor/skills/at-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "at-review", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/kairyou/agent-tools.git --path skills/workflow/at-review--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add kairyou/agent-tools --skill at-review -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install kairyou/agent-tools at-review --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/kairyou/agent-tools.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/workflow/at-review .gemini/skills/at-review && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "at-review" agent skill from https://github.com/kairyou/agent-tools/tree/main/skills/workflow/at-review into .gemini/skills/at-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "at-review", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install kairyou/agent-tools at-reviewInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add kairyou/agent-tools --skill at-review -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/kairyou/agent-tools.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/workflow/at-review .github/skills/at-review && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "at-review" agent skill from https://github.com/kairyou/agent-tools/tree/main/skills/workflow/at-review into .github/skills/at-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "at-review", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add kairyou/agent-tools --skill at-review -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install kairyou/agent-tools at-review --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/kairyou/agent-tools.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/workflow/at-review .opencode/skills/at-review && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "at-review" agent skill from https://github.com/kairyou/agent-tools/tree/main/skills/workflow/at-review into .opencode/skills/at-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "at-review", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
at-reviewReview code changes for bugs, regressions, convention violations, and high-value cleanup opportunities.
At Review is an agent skill from kairyou/agent-tools. Review code changes for bugs, regressions, convention violations, and high-value cleanup opportunities. Use for diffs, commit ranges, hosted PR/MR URLs, branches, paths, staged changes, or working-tree changes.
Its SKILL.md is about 2.1k tokens, which your agent loads only when the skill is triggered. The skill folder holds 4 other files, including reference files (for example `agents/openai.yaml` and `references/review-targets.md`).
It sits in Development, covering Code review. It works with Git. The repository describes itself as: Reusable Agent Skills, plus integrations (statusline, provider usage, vision) that install into Codex, Claude Code, and opencode. The licence is MIT.
3 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit acc2563. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
gitFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use git, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
At Review loads about 2.1k tokens when it runs, and up to ~3k if it reads all its reference files. Until then it costs about 55 tokens; SKILL.md has 1,210 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from kairyou/agent-tools at commit acc2563, republished under its MIT licence (© kairyou). 1,210 words, ~2,136 tokens.
.claude/skills/at-review/SKILL.md (or your agent's skills folder). This skill also uses 2 other files; get the full folder from GitHub.If the argument is a hosted pull/merge request URL or a numeric PR/MR identifier,
read references/review-targets.md from this skill directory before running
commands. Follow its read-only resolution and authentication fallback rules;
do not switch the user's working tree or write to the hosting service.
high effort → 3+5 angles × 6 candidates → 1-vote verify (recall-biased) → ≤10 findings
You are reviewing for recall at high effort: catch every real bug a careful reviewer would catch in one sitting. At this level, catching real bugs matters more than avoiding false positives. Err on the side of surfacing.
Run git diff "@{upstream}...HEAD" (or git diff main...HEAD / git diff HEAD~1 if there's no upstream) to get the unified diff under review. If there are uncommitted changes, or the range diff is empty, also run git diff HEAD and include the working-tree changes in scope — the review often runs before the commit. If a PR number, branch name, or file path was passed as an argument, review that target instead. Treat this diff as the review scope.
Run 8 independent finder angles using multi-agent capabilities. Each surfaces up to 6 candidate findings with file, line, a one-line summary, and a concrete failure_scenario. If multi-agent support is not available in your current tool set, do not error — perform each angle (and each verification) yourself, sequentially, in this context.
Read every hunk in the diff, line by line. Then Read the enclosing function for each hunk — bugs in unchanged lines of a touched function are in scope (the PR re-exposes or fails to fix them). For every line ask: what input, state, timing, or platform makes this line wrong? Look for inverted/wrong conditions, off-by-one, null/undefined deref, missing await, falsy-zero checks, wrong-variable copy-paste, error swallowed in catch, unescaped regex metachars.
For every line the diff DELETES or replaces, name the invariant or behavior it enforced, then search the new code for where that invariant is re-established. If you can't find it, that's a candidate: a removed guard, a dropped error path, a narrowed validation, a deleted test that was covering a real case.
For each function the diff changes, find its callers (Grep for the symbol) and check whether the change breaks any call site: a new precondition, a changed return shape, a new exception, a timing/ordering dependency. Also check callees: does a parallel change in the same PR make a call unsafe?
The angles above hunt for bugs; this one and the next two hunt for cleanup in the changed code. Flag new code that re-implements something the codebase already has — Grep shared/utility modules and files adjacent to the change, and name the existing helper to call instead.
Flag unnecessary complexity the diff adds: redundant or derivable state, copy-paste with slight variation, deep nesting, dead code left behind. Name the simpler form that does the same job.
Flag wasted work the diff introduces: redundant computation or repeated I/O, independent operations run sequentially, blocking work added to startup or hot paths. Also flag long-lived objects built from closures or captured environments — they keep the entire enclosing scope alive for the object's lifetime (a memory leak when that scope holds large values); prefer a class/struct that copies only the fields it needs. Name the cheaper alternative.
Check that each change fixes the root cause at the right depth rather than patching a symptom with a fragile bandaid. Special cases layered on shared infrastructure are a sign the fix isn't deep enough — prefer the simpler, more general change to the underlying mechanism over adding special cases, and name that change.
Find the instruction files that govern the changed code: the user-level instruction files for the current agent, the repo-root AGENTS.md or CLAUDE.md, plus any AGENTS.md or CLAUDE.md or CLAUDE.local.md in a directory that is an ancestor of a changed file (a directory's AGENTS.md or CLAUDE.md only applies to files at or below it). Read each one that exists, then check the diff for clear violations of the rules they state.
Only flag a violation when you can quote the exact rule and the exact line that breaks it — no style preferences, no vague "spirit of the doc" inferences. In the finding, name the instruction file path and quote the rule so the report can cite it. If no instruction file applies, return nothing for this angle.
Cleanup, altitude, and conventions candidates use the same file/line/summary shape; in failure_scenario, state the concrete cost (what is duplicated, wasted, harder to maintain, or which project instruction is broken) instead of a crash. Correctness bugs always outrank cleanup, altitude, and conventions findings when the output cap forces a cut.
Pass every candidate with a nameable failure scenario through — finders that silently drop half-believed candidates bypass the verify step and are the dominant cause of misses.
Dedup near-duplicates (same defect, same location, same reason → keep one). For each remaining candidate, run one verifier using multi-agent capabilities: give it the diff, the relevant file(s), and the candidate; it returns exactly one of CONFIRMED / PLAUSIBLE / REFUTED.
PLAUSIBLE by default — do not refute a candidate for being "speculative" or "depends on runtime state" when the state is realistic: concurrency races, nil/undefined on a rare-but-reachable path (error handler, cold cache, missing optional field), falsy-zero treated as missing, off-by-one on a boundary the code does not exclude, retry storms / partial failures, regex/allowlist that lost an anchor. These are PLAUSIBLE.
REFUTED only when constructible from the code: factually wrong (quote the actual line); provably impossible (type/constant/invariant — show it); already handled in this diff (cite the guard); or pure style with no observable effect.
Keep CONFIRMED and PLAUSIBLE. Drop REFUTED.
Unless --json was explicitly passed, the main agent's final answer is a Markdown report, nothing else. Structure it exactly:
Summary - 1-2 sentences on the review scope and what was found. If the diff was empty, write exactly "No changes to review." and stop. If nothing survived verification, write exactly "No findings survived verification." and stop.
Findings - one numbered block per finding, most-severe first, at most 10. Assign each finding High, Medium, or Low from its concrete impact and likelihood:
1. High|Medium|Low: summary
file:line
Failure: <failure_scenario>Only when --json was explicitly passed, follow this output contract:
Return findings as a JSON array of at most 10 objects:
[
{
"file": "path/to/file.ext",
"line": 123,
"summary": "one-sentence statement of the bug",
"failure_scenario": "concrete inputs/state → wrong output/crash"
}
]Ranked most-severe first. If more than 10 survive, keep the 10 most severe. If nothing survives verification, return []. Do not call the host-specific findings-reporting tool even if it is available - this review's output contract is the JSON block above.
Only apply anything when --fix was passed. Otherwise skip this entire section.
After producing the findings list, apply the findings to the working tree instead of stopping at the report: fix each one directly — correctness bugs and reuse/simplification/efficiency cleanups alike. Skip any finding whose fix would change intended behavior, require changes well outside the reviewed diff, or that you judge to be a false positive — note the skip rather than arguing with it. Finish with a brief summary of what was fixed and what was skipped.
© kairyou, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 2 other files (references) in skills/workflow/at-review of kairyou/agent-tools.
Open the folder on GitHubat commit acc2563
At Review next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| At Review this skillkairyou/agent-tools | 178 | — | ~2.1k | Automated safety check: Pass | MIT | |
| Review Triage Phaseprisma/orm | 48k | — | ~995 | Automated safety check: Pass | Apache-2.0 | |
| Cursor Composer Task DelegateChachamaru127/claude-code-harness | 3.2k | — | ~4.4k | Automated safety check: Notes | MIT | |
| Adopt PR Branch Contextpydantic/pydantic-ai-harness | 952 | — | ~1.8k | Automated safety check: Pass | MIT | |
| Coding Protocollencx/skills | 196 | — | ~2.4k | Automated safety check: Pass | MIT | |
| Code Reviewjustxor/claude-code-pro-course | 276 | — | ~293 | Automated safety check: Pass | MIT |
prisma/orm
Runs the triage step of the review-framework loop: reads fetched PR review state, builds `review-actions.json`, validates it and renders `review-actions.md`.
Chachamaru127/claude-code-harness
Hands one implementation task to Cursor Composer in an isolated git worktree, then reviews its diff and cherry-picks the result into the main branch.
pydantic/pydantic-ai-harness
Fills in issue-brief.md and pr-decisions.md for an existing pull request, so you can pick up a PR mid-flight with its linked issue and past review decisions summarized.
lencx/skills
Risk-scaled repo execution and code-evidence protocol. An agent skill from lencx/skills.
justxor/claude-code-pro-course
Ревью изменений в текущей ветке относительно main. An agent skill from justxor/claude-code-pro-course.
VeryGoodOpenSource/vgv-wingspan
Applies a minimal fix to an emergency bug through triage, root-cause location, a hotfix branch and a blast-radius check, with tests and review still required.
kairyou/agent-tools
Handle ZenTao (禅道) Bugs and Tasks end to end, including updating or writing back an item after code changes, managing Task status and hours, and reading linked Stories.
kairyou/agent-tools
Generate a Conventional Commits message from staged changes and wait for confirmation before committing.
kairyou/agent-tools
Inspect screenshots, photos, diagrams, image paths, and image URLs when the task depends on visible content.
kairyou/agent-tools
Summarize each day's Git activity into a concise daily work log, for a single date or a range.
kairyou/agent-tools
Summarize a contributor's Git history, a provided work log, or both into a concise, review-friendly self-evaluation for quarterly, semi-annual, or promotion cycles.
kairyou/agent-tools
Refactor changed code to reduce duplication, complexity, and wasted work.
Works with
Categories
Review code changes for bugs, regressions, convention violations, and high-value cleanup opportunities. At Review is an agent skill from kairyou/agent-tools. Review code changes for bugs, regressions, convention violations, and high-value cleanup opportunities.
At Review fits situations like: hosted PR/MR URLs; working-tree changes.
Run `npx skills add kairyou/agent-tools --skill at-review -a claude-code`. Or copy the skill folder (skills/workflow/at-review in kairyou/agent-tools) into .claude/skills/at-review in your project. Claude Code loads it when a task matches its description.
Run `npx skills add kairyou/agent-tools --skill at-review -a codex`. Or copy the skill folder (skills/workflow/at-review in kairyou/agent-tools) into .agents/skills/at-review in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add kairyou/agent-tools --skill at-review -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/at-review, .gemini/skills/at-review, .github/skills/at-review and .opencode/skills/at-review in your project.
Going by SKILL.md and its folder, At Review needs the command-line tools its instructions call (git).
SKILL.md contains no URLs. Its commands use git, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
At Review is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 2.1k tokens (SKILL.md is roughly 8.5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 876 tokens, read only when the agent opens those files.
Skills that share tags, products or a category with At Review: Review Triage Phase (prisma/orm, 48k stars), Cursor Composer Task Delegate (Chachamaru127/claude-code-harness, 3.2k stars), Adopt PR Branch Context (pydantic/pydantic-ai-harness, 952 stars) and Coding Protocol (lencx/skills, 196 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
kairyou (a GitHub user) maintains it in kairyou/agent-tools, which has 178 GitHub stars. The repository holds 8 skills in this directory. The repository was last updated on October 8, 2026.
Source: kairyou/agent-tools on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.