Agent skill

Malloy Review

by malloydata in malloydata/publisher

Malloy semantic-model code review. An agent skill from malloydata/publisher.

MITAuto-check passedEducation

Install Malloy Review

skills CLI
$ npx skills add malloydata/publisher --skill malloy-review -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install malloydata/publisher malloy-review --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/malloydata/publisher.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/malloy-review .claude/skills/malloy-review && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
malloy-review
GitHub stars
116
Token cost
~2.5k tokens
SKILL.md length
1,187 words
Files
11
Skills in repo
29
Repo updated
First seen
Licence
MIT

At a glance

Malloy semantic-model code review. An agent skill from malloydata/publisher.

  • Works in 7 steps: Resolve scope → Read files → PK data verification (if execute_query… → …
  • Critique a .malloy file
  • SKILL.md covers Before you start, Inputs, Workflow and Scaling notes, plus 2 more sections
  • Calls gh

What it does

Malloy Review is an agent skill from malloydata/publisher. Malloy semantic-model code review. Invoke when the user asks to review, audit, or critique a .malloy file, a folder of Malloy models, or a GitHub PR that touches Malloy. Enforces project modeling standards and emits a navigable review file.

Its SKILL.md is about 2.5k tokens, which your agent loads only when the skill is triggered. The skill folder holds 11 other files (for example `reference/output-template.md`, `reference/rubric-correctness.md` and `reference/rubric-documentation.md`).

It sits in Education, covering Code review and Quizzes and assessments. It works with GitHub. The repository describes itself as: Publisher is the open-source analytics engine for Malloy. It lets you define data models once — and use them everywhere. The licence is MIT.

When your agent uses it

  • Critique a .malloy file
  • A folder of Malloy models
  • A GitHub PR that touches Malloy

Example prompts

  • “/malloy-review”

Workflow steps

7 steps, taken from the step headings in SKILL.md.

  1. Resolve scope
  2. Read files
  3. PK data verification (if execute_query is available)
  4. Apply rubrics
  5. Look for cross-cutting themes
  6. Assemble output
  7. Write the file

What it can do on your machine

Read from SKILL.md and the folder at commit c43a052. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • gh

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use gh, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Malloy Review loads about 2.5k tokens when it runs. Until then it costs about 64 tokens; SKILL.md has 1,187 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~64
When it runs · the whole SKILL.md, loaded when a task matches
~2.5k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from malloydata/publisher at commit c43a052, republished under its MIT licence (© malloydata). 1,187 words, ~2,471 tokens.

Download SKILL.mdSave it as .claude/skills/malloy-review/SKILL.md (or your agent's skills folder). This skill also uses 10 other files; get the full folder from GitHub.
name
malloy-review
description
Malloy semantic-model code review. Invoke when the user asks to review, audit, or critique a `.malloy` file, a folder of Malloy models, or a GitHub PR that touches Malloy. Enforces project modeling standards and emits a navigable review file.
<!--
Copyright (c) Credible Data Inc.
SPDX-License-Identifier: MIT
-->

Malloy Code Review

Single-pass code reviewer for .malloy files. The deliverable is one Markdown file in the canonical shape (see reference/output-template.md). Findings cite the project's standards file (e.g., CLAUDE.md) where it applies; otherwise they cite rubric IDs (reference/rubric-*.md).

Tool names are written bare here - get_context, execute_query, search_malloy_docs. The exact prefixed name depends on the host surface; match each against the tools you actually have.

Before you start

Read these in order:

  1. Project standards: whatever conventions exist in your host environment (CLAUDE.md, AGENTS.md, etc.). Treat as the higher-priority source of truth; rubric rules defer to it where they overlap.
  2. reference/severity-taxonomy.md: the vocabulary every finding uses.
  3. reference/rubric-*.md: the seven dimension rubrics. Don't re-read for every review; load them on demand based on what's in scope.
  4. reference/output-template.md: the shape of the review file you produce.
  5. .malloy-review.local.md in the scope folder, if present, project-specific severity overrides or extra rules.

Make sure the Malloy MCP tools are configured before running: this skill uses execute_query for data checks and search_malloy_docs for verifying Malloy capabilities. Both are optional; the review degrades gracefully if either is unavailable.

Inputs

/malloy-review [<path>] [--pr <n>] [--out <file>] [--comment]
ArgumentEffect
(no arg)Auto-detect scope per reference/scope-resolution.md
<path>Review that file or directory
--pr <n>Review the .malloy files changed in GitHub PR <n> (see PR mode below)
--out <file>Write review to this path. Default is ./malloy-review-<YYYYMMDD-HHMMSS>.md
--commentPR mode only: post the review as a PR comment via gh pr comment

If scope is ambiguous (multiple packages, wrong file type, empty result), stop and ask: don't guess. See reference/scope-resolution.md for the rules.

Workflow

resolve scope → read files → verify PKs → apply rubrics → write output
1. Resolve scope

Per reference/scope-resolution.md. Echo the resolved scope to the user before doing anything expensive. Multi-package repos → present packages as A/B/C and let the user pick. Never auto-fan-out across packages: different packages may target different database connections.

2. Read files

For each in-scope .malloy file, read the full content. As you read, track each source's primary_key: and its join_one/join_many/join_cross targets, you'll use this for the PK uniqueness check (C-12) and join-style consistency (Y-03).

If mcp__ide__getDiagnostics is available, call it on the in-scope files and promote each diagnostic to a finding: errors → blocker (confidence 95), warnings → major (confidence 85), info/hint → minor (confidence 75), all with source: "diagnostic". Skip rubric rules these already cover. If unavailable, skip, the LLM rubric pass still runs.

3. PK data verification (if execute_query is available)

For every source with a declared primary_key:, run a uniqueness check and store the result on source_index.<src>.pk_verified:

malloy
run: <source> -> {
  aggregate:
    rows is count()
    distinct_pk is count(<pk_col>)
}
Resultpk_verified
rows == distinct_pktrue
rows != distinct_pkfalse
execute_query is unavailable for the scope"skipped"
The query fails (source unreachable, connection error, etc.)"error"

This step only collects evidence, the emit decision and fix template live in reference/rubric-correctness.md § C-12. When any source is "skipped" or "error", note the coverage gap in the output's Scope section.

4. Apply rubrics

Score the in-scope files against each applicable rubric. You don't need to read all seven: pick by content:

RubricRead when
rubric-correctness.mdAlways
rubric-documentation.mdAlways (every source/measure/dimension should be documented)
rubric-style.mdAlways
rubric-structure.mdAlways
rubric-queries.mdAny in-scope file has view: or run:
rubric-rendering.mdAny in-scope file has a # rendering tag
rubric-governance.mdAny in-scope file has ##! experimental.access_modifiers or include {} blocks

Findings use the canonical shape from reference/severity-taxonomy.md:

json
{
  "id": "C1",
  "severity": "critical",
  "category": "correctness-join",
  "file": "packages/x/customers.malloy",
  "line_range": [12, 12],
  "rule": "C-12 declared primary_key is not unique in the data",
  "current": "primary_key: customer_id (customer_id has duplicates per execute_query check)",
  "expected": "customer_id is unique per row, or the source carries a where: that scopes to a uniquely-keyed subset",
  "suggested_fix": "...",
  "confidence": 95,
  "source": "rule"
}

Drop findings with confidence < 80. The output should feel curated, not exhaustive.

5. Look for cross-cutting themes

After per-file findings, scan for systemic patterns. This is the highest-value output. Examples that emerged from real reviews:

  • N base sources all missing include {} curation
  • M files use raw conn.sql() where Malloy-native patterns exist
  • Canonical naming violations across N files (total_revenue vs net_revenue, etc.)
  • "Junk-drawer" files with multiple unrelated sources

Promote these to a Cross-Cutting Themes section in the output. They are usually more actionable than per-line findings, collapse 3+ findings of the same rule into one theme with the file list, and emit individual findings only for the top 2–3 worst offenders.

6. Assemble output

Apply reference/output-template.md. Section order is fixed (skip if empty):

  1. Header (scope, file count, LOC, timestamp)
  2. Scope (paths reviewed)
  3. Executive Summary (recommendation + top 1–3 risks)
  4. Coverage & Risk Map (file table; skip if scope is one file)
  5. Cross-Cutting Themes
  6. Top Issues (blockers + criticals)
  7. Detailed Findings (collapsed <details> per file)
  8. Questions for the Author (≤5 bullets)
  9. Positive Notes (only if real)
  10. Suggested Follow-ups (aggregated minor/nit findings)
  11. Suggested Split (only when scope is >2000 LOC or >30 files)
Show full SKILL.md (459 more words)Show less
7. Write the file

Default ./malloy-review-<YYYYMMDD-HHMMSS>.md. Tell the user the path and the top 1–3 issues inline. End with an offer to start fixing, most reviews are the start of iterative work, not a static report.

Scaling notes

ScopeBehavior
≤5 files / ≤500 LOCTrim Coverage Map and Cross-Cutting sections, likely nothing to surface. Skip the Suggested Split section.
6–20 files / 500–2000 LOCThe canonical workflow above. Include all sections that have content.
>20 files / >2000 LOCAdd a mandatory Suggested Split section. Risk-tier files into DEEP / SAMPLE / SKIM (DEEP = top ~25% by content signals: joins, access modifiers, source-level where:, public surface). Cap per-file finding count at ~12 per dimension; promote overflow into Cross-Cutting Themes. Blocker, critical, and diagnostic findings never count against the cap.

Mode notes

Single-file mode (user passes one .malloy file): trim the template hard. Drop the Coverage Map, Cross-Cutting Themes, and Suggested Split sections. Lean conversational; write the file AND print the Summary + Findings inline so the user doesn't need to open the file for a small review. End with a fix offer ("Want me to fix B1?").

Audit mode (user passes a directory or invokes inside a publisher.json package): every file is in play. Coverage Map matters more, the user needs to know what was deep-reviewed vs. skimmed. For unfamiliar packages, consider running just the source-level summary first, presenting it, and asking whether to proceed with full review.

PR mode (--pr <n>):

  1. gh pr view <n> --json state,isDraft,title,baseRefName,headRefName,url,author and gh pr diff <n> --name-only. Stop if the PR is closed or has no .malloy changes.
  2. Filter changed files to .malloy and intersect with any path argument, that's the scope.
  3. Fetch full file contents on the PR's head (via gh pr checkout <n> if the working tree is clean, otherwise via gh api repos/<owner>/<repo>/contents/<path>?ref=<headRef>). Don't clobber working state without asking.
  4. Run the workflow above. PR header: # Malloy Model Review, PR #<n>: <title> with branch/package/LOC/url metadata.
  5. With --comment, post via gh pr comment <n> -F <file> (cap at GitHub's 65,536-char limit; if larger, post the exec summary + top issues and reference the local file). Lead the comment body with <!-- malloy-review: <timestamp> --> so re-runs can detect prior reviews. Never post without --comment.

What this skill does NOT do

  • Does not modify any .malloy files. Output is the Markdown review only.
  • Does not post PR comments without --comment.
  • Does not walk above the resolved scope. Even if a finding would benefit from cross-scope context, scope is fixed once resolved.
  • Does not guess at multi-package disambiguation. Always asks.
  • Does not flag modeling features as hazards. Source-level where: clauses and deliberate private: choices are part of how Malloy models work. If something looks unusual, surface it as a "Question for the Author," not a finding.

© malloydata, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 10 other files in skills/malloy-review of malloydata/publisher.

  • SKILL.md
  • reference/output-template.md
  • reference/rubric-correctness.md
  • reference/rubric-documentation.md
  • reference/rubric-governance.md
  • reference/rubric-queries.md
  • reference/rubric-rendering.md
  • reference/rubric-structure.md
  • reference/rubric-style.md
  • reference/scope-resolution.md
  • reference/severity-taxonomy.md

Open the folder on GitHubat commit c43a052

Compare with similar skills

Malloy Review next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Malloy Review compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Malloy Review this skillmalloydata/publisher116—~2.5kAutomated safety check: PassMIT
Copilot PR Autopilotgithub/awesome-copilot40k—~3.4kAutomated safety check: PassMIT
Comment Judgefmflurry/settings-opencode171—~2.5kAutomated safety check: PassMIT
Codebase to Coursezarazhangrui/codebase-to-course5.7k—~4.4kAutomated safety check: PassNone
TendrillableIvy-Interactive/Ivy-Tendril202—~2.3kAutomated safety check: PassCustom licence
GitHub Review Iterationprisma/orm48k—~2.2kAutomated safety check: PassApache-2.0

Similar skills

  • Copilot PR Autopilot

    github/awesome-copilot

    Official

    Copilot left 14 review comments on your PR — half are nits. An agent skill from github/awesome-copilot.

    40k GitHub stars~3.4k tokensUpdated yesterday
    Backend & APIsAuto-check passed
  • Comment Judge

    fmflurry/settings-opencode

    LLM-as-a-judge rubric for code comments (forbidden, false, stale, narration, noise, keep).

    171 GitHub stars~2.5k tokensUpdated 3 days ago
    EducationAuto-check passed
  • Codebase to Course

    zarazhangrui/codebase-to-course

    Turns a codebase into an interactive single-page HTML course for non-technical learners, with scroll modules, animated diagrams, quizzes and plain-English code translations.

    5.7k GitHub stars~4.4k tokensUpdated 6 mo ago
    EducationAuto-check passed
  • Tendrillable

    Ivy-Interactive/Ivy-Tendril

    Find "Tendrillable" GitHub issues - open, recent, code-requiring issues that an agent can plan and one-shot WITHOUT asking clarifying questions, with high probability of success.

    202 GitHub stars~2.3k tokensUpdated 25 days ago
    EducationAuto-check passed
  • Official

    Runs a loop on a GitHub pull request: fetch review state, triage comments into actions, implement them and resolve threads, repeating until nothing actionable is left.

    48k GitHub stars~2.2k tokensUpdated yesterday
    DevelopmentAuto-check passed
  • Cherry Studio PR Review

    CherryHQ/cherry-studio

    Reviews Cherry Studio branches, pull requests, commits, files and docs against the project's own architecture, naming, API-boundary and UI rules, report-only by default.

    53k GitHub stars~3.9k tokensUpdated today
    DevelopmentAuto-check passed

More from malloydata/publisher

All 29 skills in this repo
  • Eval Answer

    malloydata/publisher

    Score one analytical answer against a verified golden, and score which of the entities the golden depends on retrieval delivered to the answerer.

    116 GitHub stars~4.3k tokensUpdated today
    Auto-check passed
  • Fix Scan Finding

    malloydata/publisher

    Fix a CRITICAL Trivy finding that is failing CI in this repo (a vulnerability, misconfiguration, or secret from security-scan.yml or image-scan.yml), or add, review, or retire an entry in…

    116 GitHub stars~5.1k tokensUpdated today
    Auto-check passed
  • Eval Import

    malloydata/publisher

    Turn a list of questions into an eval set, whatever shape it arrived in: a JSONL a customer sent, a CSV, a spreadsheet export, a markdown doc, an email thread, or a pull from production logs.

    116 GitHub stars~5.9k tokensUpdated today
    Auto-check passed
  • Eval Loop

    malloydata/publisher

    Conduct a local Publisher evaluation loop in five steps: scrape/run, eval, diagnose, improve, checkpoint.

    116 GitHub stars~7.8k tokensUpdated today
    Auto-check passed
  • Eval Improve

    malloydata/publisher

    Make the smallest safe Malloy model edit that closes a diagnosed model-owned gap, with a probe receipt for every factual claim.

    116 GitHub stars~2.8k tokensUpdated today
    Auto-check passed
  • Eval Judge

    malloydata/publisher

    Decide whether ONE answer matches its golden, and say whether you believe the golden.

    116 GitHub stars~3.4k tokensUpdated today
    Auto-check passed

Works with

Questions about Malloy Review

What does Malloy Review do?

Malloy semantic-model code review. An agent skill from malloydata/publisher. Malloy Review is an agent skill from malloydata/publisher. Malloy semantic-model code review.

When should I use Malloy Review?

Malloy Review fits situations like: critique a .malloy file; A folder of Malloy models; A GitHub PR that touches Malloy.

How do I install Malloy Review in Claude Code?

Run `npx skills add malloydata/publisher --skill malloy-review -a claude-code`. Or copy the skill folder (skills/malloy-review in malloydata/publisher) into .claude/skills/malloy-review in your project. Claude Code loads it when a task matches its description.

How do I install Malloy Review in Codex?

Run `npx skills add malloydata/publisher --skill malloy-review -a codex`. Or copy the skill folder (skills/malloy-review in malloydata/publisher) into .agents/skills/malloy-review in your project. Codex loads it when a task matches its description.

Can I use Malloy Review in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add malloydata/publisher --skill malloy-review -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/malloy-review, .gemini/skills/malloy-review, .github/skills/malloy-review and .opencode/skills/malloy-review in your project.

What does Malloy Review need to run?

Going by SKILL.md and its folder, Malloy Review needs the command-line tools its instructions call (gh).

Does Malloy Review access the network?

SKILL.md contains no URLs. Its commands use gh, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Malloy Review safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Malloy Review use?

Malloy Review is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Malloy Review use?

About 2.5k tokens (SKILL.md is roughly 9.9k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Malloy Review?

Skills that share tags, products or a category with Malloy Review: Copilot PR Autopilot (github/awesome-copilot, 40k stars), Comment Judge (fmflurry/settings-opencode, 171 stars), Codebase to Course (zarazhangrui/codebase-to-course, 5.7k stars) and Tendrillable (Ivy-Interactive/Ivy-Tendril, 202 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Malloy Review?

malloydata (a GitHub organization) maintains it in malloydata/publisher, which has 116 GitHub stars. The repository holds 29 skills in this directory. The repository was last updated on October 10, 2026.

Source: malloydata/publisher on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.