Agent skill

Code Reviewer

by MageByte-Zero in MageByte-Zero/spec-superflow

Review completed implementation batches for spec compliance and code quality.

MITAuto-check passedDevelopment

Install Code Reviewer

skills CLI
$ npx skills add MageByte-Zero/spec-superflow --skill code-reviewer -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install MageByte-Zero/spec-superflow code-reviewer --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/MageByte-Zero/spec-superflow.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/code-reviewer .claude/skills/code-reviewer && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
code-reviewer
GitHub stars
839
Used in
1 other repo
Token cost
~1.5k tokens
SKILL.md length
741 words
Files
2
Skills in repo
9
Repo updated
First seen
Licence
MIT

At a glance

Review completed implementation batches for spec compliance and code quality.

  • Works in 4 steps: Get the review range from recorded… → For Native final, the current executor… → When dispatching, fill only… → …
  • Tasks that involve Code review
  • SKILL.md covers Bundled runtime, Part 1: Requesting Review, Part 2: Receiving Review… and Common Mistakes, plus 1 more section
  • Calls git and node

What it does

Code Reviewer is an agent skill from MageByte-Zero/spec-superflow. Review completed implementation batches for spec compliance and code quality. Invoke after execution batches complete, before merging, or when a review gate is reached in the workflow.

Its SKILL.md is about 1.5k tokens, which your agent loads only when the skill is triggered. The skill folder holds 1 other file (for example `code-reviewer-prompt.md`).

It sits in Development, covering Code review, Human-in-the-loop approvals and Code quality. It works with Git. The repository describes itself as: 源码级融合 OpenSpec 规划引擎 + Superpowers 执行纪律的 AI 编程工作流插件。17 平台支持,9 skills,Spec-first,契约驱动。 The licence is MIT.

When your agent uses it

  • Tasks that involve Code review
  • Tasks that involve Human-in-the-loop approvals
  • Tasks that involve Code quality

Example prompts

  • “/code-reviewer”

Workflow steps

4 steps, taken from the first numbered list in SKILL.md.

  1. Get the review range from recorded execution evidence. For final review resolve the base in order: the recorded state.review_base start…
  2. For Native final, the current executor reviews the complete diff locally and writes the report; do not dispatch a reviewer subagent. For…
  3. When dispatching, fill only [DESCRIPTION], [PLAN_OR_REQUIREMENTS], [BASE_SHA], [HEAD_SHA], [WAVE_ID], and [REVIEW_REPORT_FILE]. Do not…
  4. Write a non-empty report at .superpowers/sdd/reviews/.md, then record that path with SSF execution review --wave --base --head --report…

What it can do on your machine

Read from SKILL.md and the folder at commit 25d9b0c. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • git
    • node

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use git, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Code Reviewer loads about 1.5k tokens when it runs. Until then it costs about 50 tokens; SKILL.md has 741 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~50
When it runs · the whole SKILL.md, loaded when a task matches
~1.5k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from MageByte-Zero/spec-superflow at commit 25d9b0c, republished under its MIT licence (© MageByte-Zero). 741 words, ~1,504 tokens.

Download SKILL.mdSave it as .claude/skills/code-reviewer/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
code-reviewer
description
Review completed implementation batches for spec compliance and code quality. Invoke after execution batches complete, before merging, or when a review gate is reached in the workflow.

Code Reviewer

Bundled runtime

Before executing a CLI line below, replace its leading SSF with node "<plugin-root>/scripts/spec-superflow.mjs"; <plugin-root> is the absolute directory two levels above this file. Never run SSF literally or call an ssf from PATH.

Two responsibilities: reviewing the recorded Git range and acting on findings with technical rigor. Review according to the persisted policy; verify feedback before implementing it.

Part 1: Requesting Review

Mandatory: one whole-range review for Native final; one review per planned wave for wave and legacy plans. Avoid redundant per-task or final reviews of unchanged evidence. Optional: when stuck, before refactoring, after fixing complex bugs.

Procedure
  1. Get the review range from recorded execution evidence. For final review resolve the base in order: the recorded state.review_base start anchor, then the review_base in the recorded isolation context, then git merge-base <target-branch> HEAD for a legacy/manual branch with an unambiguous target; head is git rev-parse HEAD. The CLI verifies this complete range. A failed final review retains the same base across fixes; wave repairs use the prior wave head. For a wave review use the recorded wave-start base. Never substitute HEAD~1; it misses earlier commits in multi-commit work.

  2. For Native final, the current executor reviews the complete diff locally and writes the report; do not dispatch a reviewer subagent. For user-authorized SDD with wave review, dispatch at most one reviewer for that wave using skills/code-reviewer/code-reviewer-prompt.md. If dispatch is unavailable, review locally.

  3. When dispatching, fill only [DESCRIPTION], [PLAN_OR_REQUIREMENTS], [BASE_SHA], [HEAD_SHA], [WAVE_ID], and [REVIEW_REPORT_FILE]. Do not send the whole planning bundle.

  4. Write a non-empty report at .superpowers/sdd/reviews/<wave-id>.md, then record that path with SSF execution review <change-dir> --wave <wave-id> --base <base-sha> --head <head-sha> --report .superpowers/sdd/reviews/<wave-id>.md --verdict <pass|fail>. For schema-2 plans, failed receipts also require --issue <stable-finding-id> for the blocking defect being repaired; reuse its ID across retries. Other findings keep their own IDs in the report. Identical failed input cannot consume another attempt.

  5. Critical/Important findings require a fail receipt, focused repair, one focused re-review, and replacement pass. Note Minor for later.

  6. At adjudication-required, wait for human authorization before another review.

Minimality And Scope

For unrequested complexity, cite the missing task requirement and diff line. Use Important for merge-blocking complexity and Minor for safe, behavior-neutral redundancy; never score by line count.

Part 2: Receiving Review Feedback

The Response Pattern
  1. READ feedback without reacting
  2. UNDERSTAND and restate requirement
  3. VERIFY against codebase reality
  4. EVALUATE: technically sound for THIS codebase?
  5. RESPOND: technical acknowledgment or reasoned pushback
  6. IMPLEMENT: one item at a time, test each
Severity Levels
LevelMeaningAction
CriticalBugs, security, data loss, broken functionalityFix immediately
ImportantArchitecture problems, missing features, poor error handling, test gapsFix before next batch
MinorCode style, optimization, documentation polishNote for later
Show full SKILL.md (282 more words)Show less
Forbidden Responses

Never: performative agreement ("You're right!", "Great point!"), blind implementation before verification, thanking the reviewer. Instead: restate the requirement, ask clarifying questions, push back with reasoning, or just fix it (actions > words).

Handling Unclear Feedback

Ask only about unclear findings that change a material decision; continue independent, already-understood repairs within scope. Do not turn an unclear optional comment into a global stop.

Source-Specific Rules

From user: Trusted — implement after understanding. Still ask if scope unclear. No performative agreement.

From external reviewer: Before implementing, check: technically correct for this codebase? breaks existing functionality? reason for current implementation? works on all platforms? reviewer understands full context? If suggestion seems wrong, push back with technical reasoning.

When to Push Back

Suggestion breaks existing functionality, reviewer lacks context, violates YAGNI, technically incorrect for this stack, legacy/compatibility reasons, conflicts with user's architectural decisions. Push back with technical reasoning, not defensiveness.

Implementation Order
  1. Clarify only the material uncertainty that blocks a repair
  2. Fix blocking issues (breaks, security)
  3. Fix simple issues (typos, imports)
  4. Fix complex issues (refactoring, logic)
  5. Test each fix individually, verify no regressions

Common Mistakes

MistakeFix
Performative agreementState requirement or just act
Blind implementationVerify against codebase first
Batch without testingOne at a time, test each
Proceeding without a wave receiptRecord pass/fail via SSF execution review before the next dependent wave
Assuming reviewer is rightCheck if breaks things
Avoiding pushbackTechnical correctness > comfort
Unclear feedbackClarify the blocked finding while continuing independent repairs

Exception Handling

  • Parse failures: Report specific file, request regenerated review package
  • Missing files: Regenerate via scripts/review-package. Empty diff = nothing to review
  • User interruption: Re-read review report on resume, continue from next unreviewed batch

© MageByte-Zero, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file in skills/code-reviewer of MageByte-Zero/spec-superflow.

  • SKILL.md
  • code-reviewer-prompt.md

Open the folder on GitHubat commit 25d9b0c

Used in 1 other repository

We found 1 copy of this SKILL.md (exact, near-identical or edited) in other folders, from 1 other GitHub owner. This page covers the copy in MageByte-Zero/spec-superflow, which our catalogue first saw on October 7, 2026.

Compare with similar skills

Code Reviewer next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Code Reviewer compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Code Reviewer this skillMageByte-Zero/spec-superflow8391 repos~1.5kAutomated safety check: PassMIT
Qt C++ Code Reviewx-tools-author/x-tools1.1k2 repos~4.3kAutomated safety check: PassBSD-3-Clause
Adversarial Reviewer302ai/302-AI-Studio1321 repos~3kAutomated safety check: PassMIT
Feature-Level Code Reviewdataelement/bisheng12k—~1kAutomated safety check: PassApache-2.0
Code ReviewerCaoMeiYouRen/caomei-auth220—~1.5kAutomated safety check: PassMIT
Two-Axis Code Reviewrengwu/wayfinder-maps134—~1.8kAutomated safety check: PassMIT

Similar skills

  • Qt C++ Code Review

    x-tools-author/x-tools

    Read-only review of Qt6 C++ code that combines a deterministic lint script with six parallel analysis agents and reports only high-confidence issues.

    1.1k GitHub starsUsed in 2 repos~4.3k tokens
    DevelopmentAuto-check passed
  • Adversarial Reviewer

    302ai/302-AI-Studio

    Adversarial code review that breaks the self-review monoculture.

    132 GitHub starsUsed in 1 repo~3k tokens
    DevelopmentAuto-check passed
  • Feature-Level Code Review

    dataelement/bisheng

    Runs a seven-dimension code review on a finished feature, comparing the diff against a base branch and the feature's spec, design and task files.

    12k GitHub stars~1k tokensUpdated 7 days ago
    DevelopmentAuto-check passed
  • Code Reviewer

    CaoMeiYouRen/caomei-auth

    审查当前 git 变更、PR、提交范围、技能定义文件、架构调整或安全敏感代码时使用。输出结构化 Review Gate 结论(Pass/Reject)、问题分级(blocker/warning/suggest)、最低验证矩阵、证据链与复查基线。覆盖正确性、安全、架构、SOLID、可删除代码、性能、异常处理与测试风险;默认只输出 review,不直接修改代码。用户提到 review、code…

    220 GitHub stars~1.5k tokensUpdated 6 days ago
    DevelopmentAuto-check passed
  • Two-Axis Code Review

    rengwu/wayfinder-maps

    Reviews the changes since a commit, branch or tag along two separate axes: the repo's documented coding standards and fidelity to the originating spec or PRD.

    134 GitHub stars~1.8k tokensUpdated yesterday
    DevelopmentAuto-check passed
  • Code Reviewer

    alirezarezvani/claude-code-tresor

    Automatic code quality and best practices analysis. An agent skill from alirezarezvani/claude-code-tresor.

    777 GitHub stars~1.8k tokensUpdated 3 mo ago
    DevelopmentAuto-check passed

More from MageByte-Zero/spec-superflow

All 9 skills in this repo
  • Bug Investigator

    MageByte-Zero/spec-superflow

    A skill your agent uses when encountering any bug, test failure, or unexpected behavior during spec-superflow execution, before proposing fixes.

    839 GitHub starsUsed in 1 repo~1.6k tokens
    Auto-check passed
  • Need Explorer

    MageByte-Zero/spec-superflow

    Clarify intent, scope, constraints, and success criteria before artifact creation.

    839 GitHub starsUsed in 1 repo~805 tokens
    Auto-check passed
  • Spec Writer

    MageByte-Zero/spec-superflow

    Create or refine spec-superflow planning artifacts. An agent skill from MageByte-Zero/spec-superflow.

    839 GitHub starsUsed in 1 repo~1.6k tokens
    Auto-check passed
  • Build Executor

    MageByte-Zero/spec-superflow

    Execute an active direct request or approved planned change.

    839 GitHub starsUsed in 1 repo~2.3k tokens
    Auto-check passed
  • Contract Builder

    MageByte-Zero/spec-superflow

    Maintain an execution contract only for an existing legacy change that requires one.

    839 GitHub starsUsed in 1 repo~1.3k tokens
    Auto-check passed
  • Release Archivist

    MageByte-Zero/spec-superflow

    Close out a spec-superflow change with verification, summary, and archive readiness.

    839 GitHub starsUsed in 1 repo~1.3k tokens
    Auto-check passed

Works with

Categories

Questions about Code Reviewer

What does Code Reviewer do?

Review completed implementation batches for spec compliance and code quality. Code Reviewer is an agent skill from MageByte-Zero/spec-superflow. Review completed implementation batches for spec compliance and code quality.

When should I use Code Reviewer?

Code Reviewer fits situations like: tasks that involve Code review; tasks that involve Human-in-the-loop approvals; tasks that involve Code quality.

How do I install Code Reviewer in Claude Code?

Run `npx skills add MageByte-Zero/spec-superflow --skill code-reviewer -a claude-code`. Or copy the skill folder (skills/code-reviewer in MageByte-Zero/spec-superflow) into .claude/skills/code-reviewer in your project. Claude Code loads it when a task matches its description.

How do I install Code Reviewer in Codex?

Run `npx skills add MageByte-Zero/spec-superflow --skill code-reviewer -a codex`. Or copy the skill folder (skills/code-reviewer in MageByte-Zero/spec-superflow) into .agents/skills/code-reviewer in your project. Codex loads it when a task matches its description.

Can I use Code Reviewer in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add MageByte-Zero/spec-superflow --skill code-reviewer -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/code-reviewer, .gemini/skills/code-reviewer, .github/skills/code-reviewer and .opencode/skills/code-reviewer in your project.

What does Code Reviewer need to run?

Going by SKILL.md and its folder, Code Reviewer needs the command-line tools its instructions call (git and node).

Does Code Reviewer access the network?

SKILL.md contains no URLs. Its commands use git, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Code Reviewer safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Code Reviewer use?

Code Reviewer is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Code Reviewer use?

About 1.5k tokens (SKILL.md is roughly 6k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Code Reviewer?

Skills that share tags, products or a category with Code Reviewer: Qt C++ Code Review (x-tools-author/x-tools, 1.1k stars), Adversarial Reviewer (302ai/302-AI-Studio, 132 stars), Feature-Level Code Review (dataelement/bisheng, 12k stars) and Code Reviewer (CaoMeiYouRen/caomei-auth, 220 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Code Reviewer?

MageByte-Zero (a GitHub user) maintains it in MageByte-Zero/spec-superflow, which has 839 GitHub stars. The repository holds 9 skills in this directory. The repository was last updated on October 1, 2026.

Source: MageByte-Zero/spec-superflow on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.