Agent skill

Review Gate

by majiayu000 in majiayu000/spellbook

Use before an agent-produced diff is committed, pushed, opened as a PR, merged, landed, or applied to user files when explicit implementation approval is missing.

MITAuto-check passedAgent Workflows

Install Review Gate

skills CLI
$ npx skills add majiayu000/spellbook --skill review-gate -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install majiayu000/spellbook review-gate --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/majiayu000/spellbook.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/review-gate .claude/skills/review-gate && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
review-gate
GitHub stars
287
Token cost
~1.1k tokens
SKILL.md length
506 words
Files
2 (incl. assets)
Skills in repo
97
Repo updated
First seen
Licence
MIT

At a glance

Use before an agent-produced diff is committed, pushed, opened as a PR, merged, landed, or applied to user files when explicit implementation approval is missing.

  • Approve before landing
  • SKILL.md covers When To Run, Operating Contract, Gate States and Gotchas, plus 4 more sections
  • Calls python3 and git
  • Diff first then land

What it does

Review Gate is an agent skill from majiayu000/spellbook. Use before an agent-produced diff is committed, pushed, opened as a PR, merged, landed, or applied to user files when explicit implementation approval is missing. Trigger for review gate, review pack, approve before landing, diff first then land, human approval, merge gate, commit gate, push gate, or PR readiness. Produces a concise review pack, records risks and verification, and blocks landing until a human explicitly approves or approves with required fixes.

Its SKILL.md is about 1.1k tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files, including assets (for example `assets/review-pack-template.md`).

It sits in Agent Workflows, covering Human-in-the-loop approvals. The repository describes itself as: Cross-runtime skills for Claude Code, Codex, and multi-agent workflows. The licence is MIT.

When your agent uses it

  • Approve before landing
  • Diff first then land

Example prompts

  • “/review-gate”

Requirements

  • Python 3

What it can do on your machine

Read from SKILL.md and the folder at commit ed52af7. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • python3
    • git

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use git, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Review Gate loads about 1.1k tokens when it runs. Until then it costs about 119 tokens; SKILL.md has 506 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~119
When it runs · the whole SKILL.md, loaded when a task matches
~1.1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from majiayu000/spellbook at commit ed52af7, republished under its MIT licence (© majiayu000). 506 words, ~1,101 tokens.

Download SKILL.mdSave it as .claude/skills/review-gate/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
review-gate
description
Use before an agent-produced diff is committed, pushed, opened as a PR, merged, landed, or applied to user files when explicit implementation approval is missing. Trigger for review gate, review pack, approve before landing, diff first then land, human approval, merge gate, commit gate, push gate, or PR readiness. Produces a concise review pack, records risks and verification, and blocks landing until a human explicitly approves or approves with required fixes.

Review Gate

Use this skill as the last-mile safety checkpoint for agent-generated changes. It complements PR review tools; it does not replace code review, CI, or human approval.

Use assets/review-pack-template.md when the user needs a reusable review pack shape.

When To Run

Run before any of these actions when an agent-generated diff is involved:

  • commit
  • push
  • open or update a PR
  • merge or land
  • apply a generated patch to user files when the user has not already approved that exact implementation path

Read-only review, planning, issue triage, and local exploration do not require this gate unless the next step would land or publish changes.

Operating Contract

  • Direct actions: inspect diffs, collect verification evidence, and draft the review pack.
  • Escalate before: commit, push, PR creation, merge, branch deletion, or applying a generated patch when the user has not approved that exact action.
  • Evidence-backed pushback: block landing when verification is stale, sensitive surfaces lack review, or approval is ambiguous.
  • Feedback loop: convert repeated review findings into new checklist items, verification commands, or Review Pack risk prompts.

Gate States

StateMeaningAllowed next action
draft_packReview pack is being assembled.Inspect diff and verification only.
needs_fixesBlocking risks or missing evidence exist.Patch and rerun the gate.
awaiting_humanPack is complete but no human approval exists.Stop before commit, push, PR, merge, or apply.
approvedHuman explicitly approved the pack in the current thread.Proceed with the named action only.
approved_with_fixesHuman approved after specific fixes.Apply fixes, verify, and record evidence before landing.

Agents must not self-approve. Prior CI success, a reviewer lane, or a green local test is evidence for the pack, not approval.

Gotchas

  • Approval is action-specific. "Commit it" does not mean "merge it."
  • A reviewer lane is independent evidence, not human approval.
  • If a fix changes the diff after approval, refresh verification and update the pack before landing.
Show full SKILL.md (197 more words)Show less

Review Pack

Produce this compact pack:

text
review_gate:
- intent:
- diff_summary:
- files_changed:
- driving_skill_or_issue:
- risks:
- missing_tests_or_verification:
- commands_run:
- evidence:
- open_questions:
- approval_needed_for:
- decision:

Keep findings ranked by severity. Include exact file paths, PR numbers, issue numbers, command names, and current head SHA when available.

Decision Rules

  • If verification is stale, missing, or tied to a different head SHA, set needs_fixes.
  • If the diff touches auth, payments, secrets, permissions, innerHTML, eval, shell execution, generated registry, hooks, or high-context files, call that out explicitly.
  • If user approval is ambiguous, set awaiting_human and ask for the named action only.
  • If the user approves, do exactly the approved action. A commit approval is not automatically a merge approval.
  • If a required fix changes the diff, rerun the relevant verification and update the pack before landing.

Integration Points

flowguard should call this gate at landing checkpoints. Queue skills may use a reviewer lane for independent findings, but the Review Gate still records the human-facing pack and approval state.

For GitHub PRs, combine this gate with current remote truth:

  • PR head SHA
  • check rollup
  • merge state
  • GraphQL reviewThreads
  • linked issue intent

Verification

For Spellbook changes, the pack usually cites:

bash
git diff --check
python3 ./scripts/validate_skills.py --check
python3 ./scripts/audit_skill_quality.py skill-name

Use project-specific tests for code changes. If a command cannot run, report the precondition and keep the decision out of approved.

© majiayu000, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file (assets) in skills/review-gate of majiayu000/spellbook.

  • SKILL.md
  • assets/review-pack-template.md

Open the folder on GitHubat commit ed52af7

Compare with similar skills

Review Gate next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Review Gate compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Review Gate this skillmajiayu000/spellbook287—~1.1kAutomated safety check: PassMIT
Show Me Your Work Decision Logcursor/plugins11k8 repos~1.6kAutomated safety check: PassNone
Darwin Skill Optimizeralchaincyf/darwin-skill6.2k1 repos~4.7kAutomated safety check: PassMIT
Loop Constraints Enforcercobusgreyling/loop-engineering11k1 repos~475Automated safety check: NotesMIT
Ask User QuestionMemTensor/MemOS12k—~1kAutomated safety check: PassApache-2.0
PUA High-Agency Governancetanweai/pua20k—~502Automated safety check: PassMIT

Similar skills

  • Official

    Keeps a TSV decision log for long or unattended agent runs, one row per decision with what, why, evidence and result, so a reviewer can check the work later.

    11k GitHub starsUsed in 8 repos~1.6k tokens
    Agent WorkflowsAuto-check passed
  • Darwin Skill Optimizer

    alchaincyf/darwin-skill

    Scores SKILL.md files on a nine-dimension rubric, then improves them in a keep-or-revert loop with independent judge agents, test prompts, git history and human checkpoints.

    6.2k GitHub starsUsed in 1 repo~4.7k tokens
    Agent WorkflowsAuto-check passed
  • Loop Constraints Enforcer

    cobusgreyling/loop-engineering

    Loads a project's loop-constraints.md before any other action and blocks pushes, edits or merges that violate the rules it defines.

    11k GitHub starsUsed in 1 repo~475 tokens
    Agent WorkflowsAuto-check: notes
  • Ask User Question

    MemTensor/MemOS

    Shows a question as a modal in the interface to clarify a task, collect a preference or get approval, since the user cannot see terminal output.

    12k GitHub stars~1k tokensUpdated 2 days ago
    Agent WorkflowsAuto-check passed
  • Pushes an agent to keep verifying and changing approach after repeated failures, using a diagnosis line, evidence-based completion and confirmation before risky edits.

    20k GitHub stars~502 tokensUpdated 1 mo ago
    Agent WorkflowsAuto-check passed
  • Agentmemory Forget

    rohitg00/agentmemory

    Deletes chosen memories from agentmemory only after showing the matches and getting an explicit yes, for privacy requests and cleanup of outdated notes.

    29k GitHub stars~612 tokensUpdated yesterday
    Agent WorkflowsAuto-check passed

More from majiayu000/spellbook

All 97 skills in this repo
  • Skill Ecosystem Doctor

    majiayu000/spellbook

    Audits and repairs how coding-agent Skills are owned, copied and exposed across runtimes, from canonical sources to quarantine and retirement.

    287 GitHub stars~3k tokensUpdated 2 days ago
    Auto-check passed
  • AGENTS.md Scaffold

    majiayu000/spellbook

    Scans a repository for real evidence and proposes, or on request writes, a small stack of root and scoped AGENTS.md files with validation commands and generated-file boundaries.

    287 GitHub stars~1.5k tokensUpdated 2 days ago
    Auto-check passed
  • Product Demo Builder

    majiayu000/spellbook

    Plans, produces or diagnoses evidence-backed product demo videos: script, capture plan, pacing checks and verified final media built on real product behavior.

    287 GitHub stars~3.3k tokensUpdated 2 days ago
    Auto-check passed
  • Flowguard Task Guard

    majiayu000/spellbook

    Single entry point that routes long or ambiguous agent tasks, checks live state, bounds autonomous loops and leaves a resumable handoff.

    287 GitHub stars~2.1k tokensUpdated 2 days ago
    Auto-check passed
  • npm Supply Chain Check

    majiayu000/spellbook

    Scans a repository, its lockfiles and node_modules for known malicious npm package versions and install-time indicators, using a read-only Python scanner.

    287 GitHub stars~1.5k tokensUpdated 2 days ago
    Auto-check passed
  • Product Manager Toolkit

    majiayu000/spellbook

    Product management helpers: a RICE scoring script, an interview transcript analyzer and PRD templates for prioritizing features, synthesizing research and writing requirements.

    287 GitHub stars~2.2k tokensUpdated 2 days ago
    Auto-check passed

Categories

Questions about Review Gate

What does Review Gate do?

Use before an agent-produced diff is committed, pushed, opened as a PR, merged, landed, or applied to user files when explicit implementation approval is missing. Review Gate is an agent skill from majiayu000/spellbook. Use before an agent-produced diff is committed, pushed, opened as a PR, merged, landed, or applied to user files when explicit implementation approval is missing.

When should I use Review Gate?

Review Gate fits situations like: approve before landing; diff first then land.

How do I install Review Gate in Claude Code?

Run `npx skills add majiayu000/spellbook --skill review-gate -a claude-code`. Or copy the skill folder (skills/review-gate in majiayu000/spellbook) into .claude/skills/review-gate in your project. Claude Code loads it when a task matches its description.

How do I install Review Gate in Codex?

Run `npx skills add majiayu000/spellbook --skill review-gate -a codex`. Or copy the skill folder (skills/review-gate in majiayu000/spellbook) into .agents/skills/review-gate in your project. Codex loads it when a task matches its description.

Can I use Review Gate in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add majiayu000/spellbook --skill review-gate -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/review-gate, .gemini/skills/review-gate, .github/skills/review-gate and .opencode/skills/review-gate in your project.

What does Review Gate need to run?

Going by SKILL.md and its folder, Review Gate needs the command-line tools its instructions call (python3 and git). Our summary lists: Python 3.

Does Review Gate access the network?

SKILL.md contains no URLs. Its commands use git, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Review Gate safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Review Gate use?

Review Gate is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Review Gate use?

About 1.1k tokens (SKILL.md is roughly 4.4k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Review Gate?

Skills that share tags, products or a category with Review Gate: Show Me Your Work Decision Log (cursor/plugins, 11k stars), Darwin Skill Optimizer (alchaincyf/darwin-skill, 6.2k stars), Loop Constraints Enforcer (cobusgreyling/loop-engineering, 11k stars) and Ask User Question (MemTensor/MemOS, 12k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Review Gate?

majiayu000 (a GitHub user) maintains it in majiayu000/spellbook, which has 287 GitHub stars. The repository holds 97 skills in this directory. The repository was last updated on October 8, 2026.

Source: majiayu000/spellbook on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.